HomeServicesPortfolioAboutContactBlogCareers
Book a call
Fintech

A Compliance Checklist for Voice AI: Consent, Disclosure, and Recording

August 2026 · ISTRALLEN Team

What this covers

A voice AI compliance review has more moving parts than a chat one, because recording a call and disclosing automation are both regulated acts before the agent says anything useful. This is a starting checklist for a risk or compliance team reviewing a voice agent in a regulated workflow like lending. It is not legal advice — your jurisdiction and product change what's mandatory, so run it past counsel.

1. Recording consent and disclosure

  • A recorded disclosure at the start of the call, and consent captured before recording begins.
  • Awareness of all-party (two-party) consent rules — several US states require every party to consent, not just one. Confirm this against your actual calling footprint with counsel, don't assume a single rule everywhere.
  • The consent itself stored as a record, not just implied by the disclosure playing.

2. AI disclosure

  • The caller is told, plainly, that they're speaking with an automated assistant. Some jurisdictions require it; none reward being coy about it.
  • The disclosure is near the start, not buried after the agent has already handled a request.

3. The human decision boundary

  • Anything that could constitute an adverse action — a credit denial, in lending — routes to a human. The model is not the final decision-maker.
  • Adverse-action notices carry specific, accurate principal reasons within the required timeframe. In the US, regulators have stated that the complexity of an algorithm is not a defence for failing to give specific reasons.
  • The escalation trigger fires before the conversation crosses that line, not after. On our voice AI engagement the warm handoff is triggered once the conversation moves into territory that could constitute an adverse action, with the loan officer's console pre-loaded.

4. Records and retention

  • The consent record and the full transcript are durably stored and queryable — during the call for a warm handoff, and after it for disputes and exams.
  • Decide whether the audio itself has to be retained, not just the transcript.
  • Retention matches the applicable window; the store is append-only.

5. Identity and authentication

  • Define what the agent can do before identity is verified versus after, and the verification bar on a phone channel.
  • Order-specific or application-specific actions sit behind verification.

6. Data handling and sub-processors

  • Where transcripts and audio live, and which sub-processors touch them — the speech API, the telephony provider.
  • Retention on their side, and whether audio or transcripts are used to train their models (opt out).

7. Scripted regulated statements

  • Any legally required language is reviewed and fixed, not generated fresh on each call where wording could drift.

8. Escalation path and human oversight

  • A defined, reliable route to a human exists and is tested — not just a promise in the design doc.
  • The human who picks up sees full context: transcript and structured data, so the caller doesn't restate anything.
  • There's a documented behaviour for the case where the model is uncertain right at a regulated boundary — it should escalate, not guess.

Common gaps this catches

  • A consent disclosure that plays but is never logged as a consent record.
  • AI disclosure missing, or placed after the agent has already acted.
  • No documented behaviour for when the model is unsure right at the adverse-action boundary.
  • A retention policy that covers the transcript but not the audio.

Where this stops being right

  • Scale the rigour to the consequence. A status-only information line carries lighter obligations than an agent that qualifies applicants.
  • Non-lending voice use has a different, often lighter set — this checklist is shaped by regulated lending.
  • Jurisdiction matters more than any checklist. Consent and disclosure rules differ by country and by US state; this is a prompt for the conversation with counsel, not a substitute for it.

FAQ

Do we need consent to record every call? A disclosed consent is the baseline. Some states require all-party consent — confirm your calling footprint with counsel.

Can the voice agent tell someone they're approved or declined? Status and next steps, grounded in your system, yes. The adverse-action communication for a decline goes through your compliance path, not an improvised sentence from the model.

Is the transcript enough for retention? Often you also need the consent record, and sometimes the audio. Check your specific obligations before setting the policy.

ISTRALLEN builds voice agents for regulated fintech workflows with consent, disclosure, and the human decision boundary designed in; see AI for Fintech.

See it in production
AI for Fintech → Fraud-scoring case study →
← All articles