5 considerations for FinServ enterprises worried about AI compliance
Why most voice AI vendors fail the FinServ compliance review — and the five checks that decide it.
PolyAI's deployment for a large UK high-street bank was built in about six weeks. Governance took six months. That ratio is what responsible AI deployment looks like inside a regulated financial institution, and understanding it is the most useful frame a CX leader can bring to the job of getting a voice AI past their CCO.
Contact center AI sales cycles run long in financial services for a concrete reason: the CCO, the Head of Regulatory Compliance, and the business heads carry legal accountability for what happens when a platform goes wrong. In a sector where a wrong answer can mean regulatory exposure, customer harm, or public failure, that caution is earned.
The compliance review is a filter, and most vendors don't clear it.
What compliance teams are checking, and why most vendors can't answer
PolyAI holds the certifications a financial services review asks for: ISO 27001, SOC 2 Type 2, PCI DSS, GDPR, FSQS, and CyberEssentials Plus.
The specific requirements vary by geography. The core of the review does not. Across every market, five considerations decide whether a deployment advances or stalls.
1. Does the model route customer audio through anyone else?
If the platform sends customer conversations through a commercial LLM, whether ChatGPT, Gemini, or any third-party model, the CCO's team will run a second review of that vendor's data policies. That review terminates most deployments. PolyAI's Raven model is proprietary and built in-house, so sensitive customer audio never touches an external model. For an institution under Consumer Duty or CFPB oversight, that single fact often separates a deployment that clears governance from one that doesn't.
2. Can every regulated interaction be reconstructed after the fact?
Consumer Duty compliance, CFPB oversight, and internal audit all require full call recording and interaction logs. A platform that doesn't produce them natively leaves a gap the compliance team has to close some other way, which usually means it doesn't get approved.
3. Where does the audio actually live?
Where is customer call audio processed, and does it cross a jurisdiction on the way? Institutions with residency requirements need in-region, VPC, or on-premise hosting rather than a standard cloud arrangement. A vendor without a configurable residency option is, at most major financial institutions, not a viable shortlist candidate.
4. Does the vendor map to your regime: DORA, the AI Act, Consumer Duty, CFPB?
In the EU, the Digital Operational Resilience Act (DORA) changes what a bank must demand of any supplier touching a critical function. A vendor handling identity verification, payments, or core customer interactions can expect to be assessed as an ICT third-party provider. That puts the institution under ongoing obligations for ICT risk management, incident reporting, resilience testing, and exit planning, and it obliges the bank to evidence the same controls from its vendor.
Under the EU AI Act, customer-service voice agents fall under Limited Risk: transparency obligations apply, high-risk classification does not. The practical test is whether a vendor can map its controls to DORA's requirements and produce what an operational-resilience review asks for. PolyAI runs a formal information security program with 48-hour incident notification, annual third-party penetration testing, a 24-hour recovery objective, and a maintained subprocessor register, the evidence base a DORA-governed institution needs.
In the UK, the FCA's Consumer Duty framework, in force since 2023, extends compliance obligations into AI-driven interactions. Firms must evidence good outcomes for retail customers. In a contact center, that means documented escalation paths for vulnerable callers, tone calibration in sensitive conversations, and full auditability of AI-driven decisions.
In the US, the Consumer Financial Protection Bureau (CFPB) has signaled growing scrutiny of AI in consumer-facing finance, with a focus on fairness, explainability, and the treatment of customers in financial distress. State-level rules add complexity, but the direction is consistent: more oversight, applied earlier in procurement.
5. Has it already cleared governance at a real institution?
This is the question references actually answer, and it's where a vendor either has production proof or doesn't.
| Customer | Industry | Outcome |
|---|---|---|
| Leading EU-based Commercial & Retail Bank | Retail banking | 80% CSAT; roughly 7x higher true resolution rate than the platform it was evaluated against; £2 per resolved call for the AI vs £4.48 for their agents |
| Allstate | Insurance | 160,000+ calls handled monthly; 42% containment with no backend API integrations; 20% SMS deflection |
| Liverpool Victoria | Insurance | About 50% webchat containment in production since February 2026, running embedded under an existing CCaaS stack, which shows the integration doesn't require replacing the incumbent |
| Leading UK-based Commercial & Retail Bank | Retail banking (collections) | Live deployment handling inbound Financial Health and Support calls under full FCA conduct and Consumer Duty obligations |
European deployments in regulated banking run under the bank's own DORA and outsourcing review, covering documented model architecture, data-handling controls, escalation paths, and customer-protection outcomes. PolyAI supports that review as the ICT provider. The approval sits with the institution.
NatWest's deployment in Financial Health and Support handles inbound collections: callers in financial distress, under FCA conduct obligations and Consumer Duty. A bank trusted with calls this sensitive has cleared the highest conduct bar there is, which is why it took strong confidence in the solution and full compliance adherence to automate them at all.
How to brief your CCO
The conversation goes better when the CX leader arrives with specifics. A CCO who hears "the vendor is compliant" has nothing to evaluate. A CCO who gets a certification summary, a data-residency options document, and three reference deployments in regulated institutions has something to work with.
Five questions worth putting to any AI vendor before that meeting:
- What are your current certifications: ISO 27001, SOC 2 Type 2, PCI DSS, GDPR, FSQS, CyberEssentials Plus?
- Are your speech recognition and language models proprietary, or does customer audio route through third-party commercial models?
- What data-residency options do you offer: standard cloud, VPC, on-premise?
- Do you provide full call recording and audit trails across all regulated interactions?
- Can you name a mainstream financial services deployment, not a small fintech, that has cleared enterprise governance, and offer a reference contact?
A vendor that answers all five directly is ready for your CCO. One that hedges on model architecture or data sovereignty won't survive the first fifteen minutes of a compliance review.
Frequently asked questions
Is PolyAI compliant with PCI DSS? Yes. PolyAI is certified to PCI DSS 4.0, covering secure handling of payment card data within customer service interactions.
Does PolyAI meet FCA Consumer Duty requirements? PolyAI deployments support Consumer Duty compliance through documented escalation paths for vulnerable customers, real-time tone calibration based on caller emotion, full call recording, and interaction audit trails. Metro Bank, an FCA-regulated institution, is a live PolyAI deployment in the UK.
Does PolyAI process customer data through third-party AI models? No. PolyAI's speech recognition (ASR) and language model are both proprietary, developed in-house as Raven. Customer audio is not routed through OpenAI, Anthropic, Google, or any third-party commercial model. VPC and on-premise deployment options are available for institutions with specific data-residency requirements.
Has PolyAI received approval from a financial regulator? PolyAI hasn't sought direct regulatory approval; that isn't how regulators engage with AI vendors. The approval sits with the bank. What PolyAI does is support its banking clients through it: in the EU, by supporting clients' DORA and material-outsourcing governance reviews as an ICT third-party provider; in the UK, through internal governance reviews covering model risk, AI ethics, data protection, and operational risk. The real question is whether a vendor can get your institution through its own process. PolyAI has, and can evidence it.
Does PolyAI comply with CFPB guidelines for AI in financial services? PolyAI's platform supports CFPB compliance requirements, including explainability of AI-driven decisions, appropriate handling of customers in financial distress, and full audit-trail documentation. Allstate, a regulated US insurer, handles 150,000 calls monthly on PolyAI.
Does PolyAI have specific guardrails for financial services? PolyAI's guardrail architecture is enterprise-grade by default — five layers of runtime controls active across 100% of production traffic, covering jailbreak prevention, content safety, PII redaction, and deterministic overrides that ensure authoritative data (balances, transaction amounts) always comes from your systems of record, never the LLM. We layer on top of that with finserv-specific controls drawn from our experience in the sector, including fraud escalation routing and vulnerable customer handling. And because every institution's risk profile is different, we work with your compliance and operational teams to configure and test the right rules for your specific environment before anything goes live.
What compliance certifications does PolyAI hold for financial services? ISO 27001, SOC 2 Type 2, PCI DSS, GDPR, FSQS (Financial Services Qualification System), and CyberEssentials Plus.
Build it yourself
The compliance architecture is already in place. What remains is configuring the experience your customers actually call about: the call flows, authentication steps, escalation logic, and routing rules specific to your institution's products and obligations.
Agent Studio gives CX and contact center teams direct control over that configuration without depending on IT for every change. Technical teams can go further with the Agent Development Kit.