Banking AI calling compliance: campaign rules
The difference between a shop's promotional call and a bank's credit campaign is not only the product: every sentence said about a financial product can create an expectation, and a wrong phrase has real consequences for the customer. This article builds the operational model for banking call campaigns: when the compliance function is brought in, what stays out of the script, consent and the limit on disclosure, preparing the list, the audit trail, escalation rules and compliance indicators.
Why a bank's calls run on different rules
The difference between a shop's promotional call and a bank's credit campaign call is not only the product. Every sentence said about a financial product can create an expectation, the conversation can be examined later, and a wrong phrase has real financial consequences for the customer.
So in banking the question of call automation is a process question before it is a technical one: who may be called, what may be said, what is recorded, and who approves all three. Writing a script before those are answered is wasted work.
This article is about building that process. It states no legal requirement and no regulatory rule — the actual rules depend on the country, the product and the institution's own documents. Its purpose is to shape the operational model so a compliance function can review and approve it.
Compliance is a process question
Many projects plan compliance as the last stage: write the script, build the system, then send it to legal. The outcome is almost always the same — the project comes back two months later.
- The compliance function joins before the script is written
- Which products can be called about at all — that is the first question
- Which phrasings may be used is confirmed in writing
- In which situations the conversation must move to a person — a list prepared in advance
- Which records are kept, and for how long, is agreed
Confirming those five in writing speeds the project up rather than slowing it. A team with an approved phrase list writes the script in a day; a team without one debates every sentence separately.
The practical form is simple: a one-page document with three columns — what can be said, what cannot, and what has to be handed to a person. That document becomes the source of the script, and when it changes the script changes.
What cannot be in the script
Several kinds of statement about a financial product are treated as risky, and most banks' internal rules cover them in one form or another.
What works instead is this formula: general information about availability, the list of documents an application needs, and setting the next step. Those three fully serve the purpose of the call and create no commitment.
One detail worth noting: when a customer asks for a specific figure, the script should not say «I do not know». The correct answer explains how the calculation is made and moves the conversation to whoever can make it.
Consent and disclosure
The question of who may be called sits at the very start of a campaign, and it belongs to preparing the list rather than to the call itself.
- On what basis the customer entered this campaign — that belongs as a column on the list
- Customers who opted out are removed from the list automatically
- Opting out must also be possible during the call, and recorded immediately
- The reason for the call is stated openly at the start
- Who the call is made on behalf of has to be clear
The second line is where this breaks most often in technical terms. The opt-out is recorded in one system while the campaign takes its list from another — and the customer is called again. That is the most serious operational risk here, and the fix is in the integration.
The third line needs a rule of its own: an opt-out given during a call should remove the customer from all applicable communication, not only from that campaign — otherwise they hear from the same bank next week under a different one.
Identity and the limit on disclosure
The most sensitive moment in a phone conversation is this: what may be said before it is certain who is on the other end.
The practical principle is that account details, balances, transaction history and personal terms are not disclosed to someone whose identity has not been verified. Those can only be opened after the bank's own verification procedure, and only on a channel able to carry that procedure.
For an automated call scenario the consequence is that a campaign call stays within general information. Any question that requires personal data becomes a condition for handing the conversation over — which makes it the principal decision point of the script.
Preparing the campaign list
From a compliance standpoint the list matters as much as the script, because a wrong list reaches more customers than a wrong sentence.
- Segment criteria are confirmed in writingWhich customer group is included and why. The criterion is stored in a form that can be checked afterwards.
- Exclusions are appliedCustomers who opted out, those in collections, those with an unresolved complaint and any other group named in internal rules come off the list.
- The list is approvedBefore the campaign runs, its size and composition are approved by the responsible person. Preview helps here: how many will be reached is visible in advance.
- A campaign log is keptWhich list, which scenario, which date. That log is the basis of any later review.
Records, retention and the audit trail
The question a compliance function will ask is simple: what was said to this customer, and how can you show it. The answer depends on how the operation was set up.
- Every call's result is stored as a code and as fields
- Which version of the scenario was in use is recorded — the version changes as the script does
- The moment a conversation was handed to a person, and why, is visible
- Opt-outs and complaints are flagged separately
- Retention periods and access rights follow a written rule
The second line is the most commonly missed. If the script changed five times in three months and nobody knows which call ran on which version, no later review is possible. Recording the version is solved with a single field.
Escalation and complaints
In automated calling the escalation rule is the most concrete part of compliance, and it belongs inside the script.
- The customer expresses dissatisfaction — hand over immediately
- The customer uses the word complaint — hand over and log it as a complaint
- Personal financial information is requested — hand over
- The customer asks something the script cannot answer — hand over, do not say «I do not know»
- A technical problem occurs — end the call and schedule a callback
Keeping this list short matters: a long list is not applied in practice. Five conditions can be remembered and can be tested.
Measurement: compliance indicators
Compliance measurement is separate from sales measurement and should be read in a separate report.
- Opt-out count, and how long an opt-out takes to propagate through the systems
- Escalation rate: what share of conversations moved to a person
- Complaint count and breakdown by subject
- Whether list exclusions were applied correctly — tested on a sample
- The share of calls with a recorded scenario version
Assessing call quality in general is a separate subject and is built in AI call quality assurance, which sets out how the scorecard is written.
Limits
This article is not legal advice and interprets no regulatory requirement. Rules for calling campaigns in financial services differ by country, by product and by each institution's own documents.
The second limit is in automation itself. Credit decisions, negotiating individual terms and contested cases are a person's work, and that is not a technical constraint but a question of responsibility. Automation here covers first contact and information only.
What the Vexvon side provides
These are the elements that build the operational part of this model.
- Knowledge base: the agent answers only from information the company approved — «what may be said» is constrained at system level
- Scenario: system prompt, inbound and outbound mode, fields to extract and the tools available are configured separately
- Handover: when the condition is met, the agent passes the conversation to a live operator
- Campaign: the target list is built from a CRM filter, preview shows its size in advance, and a campaign can be paused or cancelled
- CRM: outcome codes, close reasons and one timeline of every action
- Routing: time policies and prioritised rules, tested by simulation before they meet live calls
How the knowledge base is built is on the knowledge base page, and call handling on the call center page.
First step
Start with the one-page document rather than the script: three columns — what can be said, what cannot, what has to be handed over. Write and approve it with the compliance function. After that the script is a day's work.
To discuss how this would work in your own processes, get in touch.