Governance

Compliance & quality

Automated conduct checks on every call, plus human audit results.

Conduct compliance

99.7%

Automated checks across 1,246 calls

QA score

94 / 100

Rolling 30-day average

Consent coverage

98.2%

24 accounts pending consent refresh

Recordings retained

12 months

Encrypted at rest and in transit

Flagged calls

10

This week, all reviewed within 24h

DNC list size

184 accounts

Blocked from outbound dialling

Rules monitored

12

Applied in real time on every call

Audits completed

215

Sampled reviews this quarter

Automated conduct checks

Applied to every conversation in real time

RuleDetailCalls checkedPass rateLast breachStatus
Calling window respected
No dialling on Fridays or outside 09:00–19:00 GST1,246100%Compliant
Identity verified before disclosure
Two-factor verification on every connected call1,24699.8%22 MayCompliant
No sensitive data requested
PIN, OTP, full card number never requested1,246100%Compliant
Respectful language
No threatening or coercive phrasing detected1,246100%Compliant
Do-not-call honoured
Consent and DNC flags block dialling1,24699.4%09 JunMonitor
Call purpose disclosed
Bank name and reason stated in the opening1,246100%Compliant
Recording disclosure given
Customer informed the call may be recorded1,24699.9%14 MayCompliant
Frequency cap honoured
Max 1 outbound attempt per account per day1,24698.7%10 JunMonitor
Hardship pathway offered
Financial difficulty flag triggers human handoff312100%Compliant
Language preference honoured
Arabic/English switch on customer request1,24699.6%30 MayCompliant
Settlement terms accurate
Amounts and dates match the lending system1,246100%Compliant
Call closing script complete
Summary and next steps confirmed before hang-up1,24697.9%11 JunMonitor

QA score trend

Rolling weighted score over the last 12 weeks

Audit history

Sampled reviews by QA, compliance and risk

QA — Mouza A.94 / 100

11 Jun · 40 calls

Strong Arabic switching, two long silences flagged.

Compliance — Hamdan A.97 / 100

08 Jun · 60 calls

All disclosures present, no conduct issues.

QA — Mouza A.91 / 100

04 Jun · 35 calls

Two cases where the promise date was not repeated back.

Risk — Abdulla R.95 / 100

01 Jun · 80 calls

Hardship handling consistent with policy.

QA scorecard breakdown

Weighted components of the rolling QA score

AreaWeightScore
Greeting & disclosure15%98 / 100
Identity verification20%96 / 100
Regulatory disclosure20%99 / 100
Tone & empathy15%92 / 100
Resolution & next steps20%90 / 100
Call closing10%93 / 100

Flagged calls

Calls surfaced for human review this week

Call IDAccountReasonReviewerAction taken
CL-88231GB-6648Extended silence over 12 secondsMouza A.Coaching note logged
CL-88214GB-2205Promise date not repeated backMouza A.Script reinforcement
CL-88190GB-8890Customer requested Arabic, delayed switchHamdan A.Latency ticket raised
CL-88176GB-7731Closing summary incompleteAbdulla R.Model prompt updated
CL-88155GB-4432Possible DNC list mismatchHamdan A.Account suppressed, under review
CL-88140GB-9012Sentiment spike — customer frustrationMouza A.Escalated to human agent
CL-88121GB-3391Hardship keyword detectedAbdulla R.Routed to hardship desk
CL-88098GB-5567Call duration exceeded 9 minutesMouza A.Reviewed, no issue found
CL-88074GB-6210Repeat call within 24 hoursHamdan A.Frequency cap corrected
CL-88061GB-1187Customer disputed debt amountAbdulla R.Routed to disputes team

Consent & do-not-call register

How opt-outs and consent refreshes are tracked

  • 184 accounts currently on the do-not-call register, synced hourly from the lending system.
  • Verbal opt-outs during a call are logged and enforced within 5 minutes.
  • Consent is refreshed every 12 months or on any change of contact number.
  • 24 accounts are pending a consent refresh and are excluded from outbound dialling.
  • Register changes are reviewed weekly by the compliance team.

UAE Central Bank conduct rules mapping

How internal controls map to regulatory expectations

Consumer Protection Regulation — fair treatment

Respectful language & tone checks

Consumer Protection Regulation — debt collection conduct

Calling window, frequency cap, disclosure checks

Data protection standards

Masked references, encrypted storage, access logging

Complaint handling requirements

Auto-escalation to human agent on dispute or complaint

Vulnerable customer treatment

Hardship keyword detection and hardship desk routing

Data protection

How customer information is handled during collections calls

Masked references

Accounts are spoken only as the last four digits.

No card credentials

The agent never asks for PIN, OTP or full card numbers.

Encrypted transport

Call audio and account context move over encrypted channels.

Access logging

Every configuration change and export is attributed to a user.

Retention schedule

  • Call recordings — retained 12 months, then permanently deleted.
  • Call transcripts and QA scores — retained 24 months for audit trend analysis.
  • Consent and DNC register entries — retained for the life of the account plus 24 months.
  • Exported reports — retained 24 months in the secure reporting archive.

Access control

  • Role-based access: agents view masked data only, QA and compliance view full detail.
  • Recording playback requires a documented business reason and is logged.
  • Exports require manager approval for anything beyond aggregate metrics.
  • Access reviews are performed quarterly by the compliance team.