MaxContact explores how contact centre compliance is changing, what the latest research reveals, and why sampling may no longer be enough.
Compliance used to be something you could, quietly, budget for. A fine here, a sample there, a QA process that reviewed a small slice of calls and hoped the rest looked the same.
That maths no longer works.
In 2026 the cost of getting it wrong has changed by an order of magnitude, and regulators have moved from asking whether you’ve done the work to asking you to prove it.
In MaxContact’s recent webinar, Kayleigh Tait and Conor Bowler walked through what’s changed and shared new research from more than 300 UK contact centre leaders. Here’s the summary.
Two things have shifted at once.
First, the numbers. PECR – the regulation governing outbound calls, texts and marketing communications – used to cap fines at £500,000.
Since the Data (Use and Access) Act came into force in February 2026, that cap has risen to £17.5 million, or 4% of global turnover, whichever is higher.
That’s a 35x increase in maximum exposure. And for the first time, company directors can be held personally liable, up to £500,000 each.
Second, the FCA’s stance. Consumer Duty has been law since 2023, but the regulator has moved from “have you put this in place?” to “prove it with evidence.”
Of the 180 board reports the FCA reviewed last year, the most common failure wasn’t that firms hadn’t done the work – it was that they couldn’t evidence the outcomes for vulnerable customers.
At these levels, a fine isn’t a line item you plan for. It’s a risk you have to design out.
To ground this in reality rather than headline numbers, MaxContact commissioned independent research across 300+ UK contact centre leaders, 285 of them FCA-regulated. A few findings stood out.
Coverage has matured – but gaps remain. Asked how they review calls today:
That’s a more mature picture than the “2–3% sampled” figure often quoted in industry research. But it also confirms that a real share of organisations still aren’t solving the problem with technology.
Sampling leaves you exposed. More than half – 54% – said a compliance breach or harm had occurred outside their routine QA process. 16.5% said it had happened more than once. The point is simple: if you only look at a sample, the problems tend to live in the calls you didn’t look at.
And it costs real money. Across everyone surveyed – including firms that paid nothing – the average regulatory fine in the last 12 months was £81,000, with 31% paying £50,000 or more.
Fines weren’t the whole story either: the average lost revenue from non-compliant sales (refunds, cancellations, deals that fell through) was £22,000, and 50.2% said they’d lost a sale, contract or customer over a compliance issue.
One of the more revealing findings came from asking teams two questions. First: how confident are you that you could evidence fair treatment if the FCA came knocking? Confidence was high across the board.
Then we flipped it: have you actually found a breach outside your QA sample? The gap between the two is the interesting bit.
It’s less about how hard a team looks and more about what they’re looking at. Sales and collections calls tend to follow scripts and structured flows, so there are only so many ways a conversation can drift out of compliance.
Customer care and technical support calls are far less scripted – troubleshooting, escalations, one-off advice – so there’s more variance per call, and more chance of a breach hiding in the calls that never make it into the sample.
Even when issues are caught, they’re caught slowly. On average, it takes 3.08 days between a call happening and the person who took it getting feedback. Only 10.9% hear back within a day; over a third (37.2%) wait three days or more.
The blocker isn’t attitude. Time, cost and headcount accounted for 37.4% of the reasons given, while only 6% felt there was no genuine need for faster feedback.
That delay matters, because feedback has a shelf life. Third-party research shows employees are 3.6x more likely to say they’re motivated to do outstanding work when feedback comes daily rather than at a quarterly or annual review.
Put the two together and the risk is clear: if something’s going wrong on a call and nobody flags it for the best part of a working week, it’s probably happening again and again in the meantime.
This can be addressed with features inside Conversation Analytics. They’re easy to blur together, so it’s worth being precise.
AI-powered call scoring: Features such as MaxContact’s AI Call Scoring provide an AI scorecard builder within the Conversation Analytics base package.
Users can write a scorecard in plain English to score individual calls, with a human still selecting which calls to assess. The feature can reduce review time from 2–3 times the length of the call to around five minutes per call.
Auto QA at Scale takes those same scorecards and runs them on a schedule – historically and as new calls come in – so you get consistent coverage across 100% of eligible calls.
Every result is backed by evidence in the transcript, and calls are grouped by outcome (pass, fail, auto-fail, not applicable) so your team can focus human review where it’s needed.
In the demo, Conor built an FCA compliance scorecard and showed how it runs at scale. A few things worth knowing:
Isn’t AI scoring just swapping one compliance risk for another? No – because it isn’t a black box. Every score links straight back to the exact part of the transcript it came from, so a QA lead can check any result against the call in seconds. The AI decides what needs looking at; a human still decides what to do about it.
We already run Conversation Analytics with AI Call Scoring – is Auto-QA a big project? No. It sits on infrastructure you already have, so it’s a matter of turning the feature on.
Your existing scorecards carry straight over — you’re not rebuilding anything. What changes is that scoring runs on a schedule against every eligible call, rather than a person choosing which calls to score.
Can results be shown to agents, not just QA? This is in development, and it’s permissions-based – you control the level of detail.
The plan is three layers of feedback: calls scored in real time as they happen, a daily “top three to improve, top three strengths” summary, and the same across a rolling seven-day view.
The rules have changed, and sampling no longer counts as evidence. When breaches hide in the calls you don’t review, and feedback takes three days to land, the fix is coverage that’s complete, evidenced and fast. That’s exactly the gap Auto-QA is built to close.
This post has been re-published by kind permission of MaxContact - view the original article.
Author: Hannah Swankie
Reviewed by: Megan Jones