Loading
Loading
The FCA Consumer Duty, effective from July 2023, requires firms to deliver good outcomes for retail customers across four areas: products and services, price and value, consumer understanding, and consumer support. For contact centres handling financial services calls, this means ensuring that communication is clear and not misleading, that customers can access support without unreasonable barriers, and that outcomes are monitored across the full customer base. Firms should be able to demonstrate how they measure and evidence good outcomes from customer interactions.
Contact centres should have processes in place to assess whether scripts and communications meet Consumer Duty standards, and quality monitoring should include specific criteria related to the four outcome areas.
Call recording is a standard practice in contact centres but must comply with GDPR requirements. Customers must be informed that calls are being recorded and the lawful basis for recording must be documented. Common lawful bases include legitimate interest (for quality monitoring and training) and legal obligation (for regulatory compliance). Recorded calls constitute personal data and must be stored securely, retained only for as long as necessary, and made available to customers upon subject access request. Retention policies should be clearly defined and consistently applied.
Contact centres that process card payments by telephone must comply with PCI DSS (Payment Card Industry Data Security Standard). This requires that card data is not stored in call recordings: either by pausing recording during payment capture or by using DTMF masking technology. Agents should not read card numbers back to callers, and payment card data should not be written down or stored outside of PCI-compliant systems. Regular assessments and compliance certifications should be maintained.
The FCA expects firms to identify and respond appropriately to customers showing signs of vulnerability. Contact centres should train agents to recognise indicators of vulnerability, including references to health conditions, bereavement, financial difficulty, low literacy, or cognitive impairment. Clear escalation procedures should be in place, and interactions with vulnerable customers should be flagged, documented, and reviewed. Speech analytics can assist with automated vulnerability detection across all calls.
Outbound calling operations must comply with the Telephone Preference Service (TPS) and Corporate Telephone Preference Service (CTPS) regulations. Numbers registered on TPS/CTPS must not be called for marketing purposes unless the individual has given specific prior consent. Contact lists must be screened against the TPS register within 28 days of use. Failure to comply can result in significant fines from the Information Commissioner's Office (ICO).
FCA-regulated firms must have a documented complaints handling procedure that meets the requirements of DISP (Dispute Resolution: Complaints). All expressions of dissatisfaction that meet the FCA definition of a complaint must be captured, acknowledged, investigated, and resolved within prescribed timeframes. Contact centre agents should be trained to identify complaints, even when customers do not explicitly use the word, and to follow the correct logging and escalation procedures.
Regulated firms must maintain adequate records of customer interactions for audit and regulatory purposes. This includes call recordings, transaction records, complaint files, and quality monitoring documentation. Retention periods vary by regulation: MiFID II requires recording retention for five years, while general GDPR principles require that data is not kept longer than necessary. A clear retention schedule that reflects all applicable regulatory requirements should be documented and enforced.
Complete the form below to receive a PDF version of this guide by email.
Our team can provide tailored guidance and support to help you implement the recommendations in this guide.
Get in Touch