Skip to main content

Debt Recovery Hub

FCA Collections Compliance That Holds Up in an Audit

An FCA audit rarely exposes a single bad letter or call. It exposes a collections model that treats repayment as the only measure of success.

For firms collecting regulated consumer credit debt, a compliant collections model means showing that debt collection compliance shapes every decision, contact and escalation route around fair customer outcomes. You still need to recover money, but you must prove that your methods are proportionate, informed and controlled.

That proof starts by defining which debts fall under the FCA framework and which do not, determining the debt recovery pathway.

Key Takeaways

  • FCA collections compliance requires firms to apply CONC 7, the Consumer Duty and relevant data-protection requirements throughout the collections journey.
  • Forbearance must be built into daily workflows, with clear routes for affordability concerns, debt advice, disputes, bereavement and vulnerability.
  • Customer segmentation should guide suitable support rather than increase pressure, with records explaining why each customer received a particular treatment.
  • Real-time audit trails, outcome-based management information and tested automated controls are essential to demonstrate fair customer outcomes.
  • Outsourcing collections does not outsource accountability: firms must monitor third-party collectors, control customer harm and evidence effective remediation.

Start With the Regulatory Boundary

CONC 7 is the Financial Conduct Authority’s consumer credit sourcebook for arrears and default. It applies to regulated consumer-credit activity, including lenders, debt purchasers, debt collectors and administrators within the FCA perimeter. The CONC 7 handbook is the primary reference point for your policies, scripts, workflows and quality checks under the relevant debt collection rules.

The Consumer Credit Act 1974 also matters because it governs many regulated credit agreements and parts of the enforcement process. It forms part of wider financial regulation. The sourcebook sets the FCA’s conduct standards for people in or approaching financial difficulty.

The FCA’s Consumer Duty rules raise the standard further. You must act in good faith, avoid foreseeable harm and support customers in pursuing their financial objectives. In collections, that means you cannot rely on a technically compliant process if its design predictably causes harm or blocks a customer from getting help.

Ordinary unpaid commercial invoices usually sit outside this consumer-credit regime. If your work is B2B collections, the contract, applicable court rules, data-protection law and general standards of fair conduct remain relevant. The debt recovery UK market includes both FCA-regulated consumer accounts and commercial claims, but B2B cases should use only the relevant debt collection rules. Identifying the correct perimeter for each case is a core compliance control within your compliance framework and supports wider regulatory compliance.

A business recovering an overdue trade invoice should not describe the sourcebook as its governing rulebook unless the activity falls within the FCA perimeter. Equally, an authorised firm must not use a commercial collections template for a regulated consumer debt.

Turn the sourcebook into operational controls

CONC 7 requires clear, effective and appropriate policies and procedures for customers in or approaching arrears or default. Your policy needs to translate that rule into actions staff and systems can follow under pressure.

At a minimum, your documented controls should cover:

  • How your team detects missed payments, repeat payment failures and early signs of financial difficulty.
  • When collections activity pauses for debt advice, a dispute, bereavement or a vulnerability assessment.
  • How staff assess affordability before agreeing a repayment arrangement.
  • Which approval is needed before litigation, repossession or referral to third-party collectors.
  • What information your team records after every material customer interaction.

The rules require you to treat customers in arrears or default with forbearance and due consideration. They also expect you to give reasonable time and opportunity to repay. The FCA’s arrears and recovery rules make clear that you should suspend active recovery for a reasonable period when a customer, debt adviser or representative is developing a repayment plan.

Your staff need a controlled route to pause action. If the system only permits escalation, agents will escalate.

Building FCA Collections Compliance Around Customer Outcomes

A compliant collections model does not remove commercial discipline. For lenders, ethical lending continues into collections, where success means sustainable outcomes, not recovery volume alone.

A payment obtained through pressure, a plan that breaks after one instalment, or a customer who disengages because they cannot understand their options are poor outcomes. They can also expose weaknesses in your processes, communications and governance.

A finance professional reviews compliance reports in a modern office beneath a Compliance headline.

The Consumer Duty has four outcomes: products and services, price and value, consumer understanding, and consumer support. In collections, each outcome has a practical effect.

A customer must understand why you are contacting them, what they owe and what choices they have. Charges, interest and repayment plans must offer fair value. Support must include practical forbearance when someone needs more time, a different communication format or help from a debt adviser.

A recovered balance is not evidence of a good outcome if the customer paid more than they could afford or missed accessible support.

Your board should receive evidence that the model works for different customer groups, not only an overall recovery rate. The FCA’s Consumer Duty guidance places responsibility on firms to assess whether they are delivering good outcomes. Collections cannot sit outside that assessment.

Use decision gates throughout the journey. Before escalating, your workflow should test whether the account is disputed, whether an arrangement is active, whether a vulnerability indicator exists, and whether the customer has requested debt-advice time.

For example, a customer who misses one direct debit after a longstanding payment history may need a clear, low-friction reminder. Someone with repeated missed payments, reduced income and a recent request for breathing space needs a different route. Treating both customers identically may improve short-term contact volumes while producing weaker outcomes.

Put Forbearance Into the Daily Workflow

Forbearance is more than a broad instruction to “be flexible.” It means responding to the customer’s circumstances with options that have a realistic prospect of working.

Before asking for a payment commitment, give the customer a clear explanation of the balance, any interest or charges, and the available support. Ask relevant questions without turning the conversation into an interrogation. When affordability is unclear, a proportionate income-and-expenditure assessment can show whether a proposed arrangement is sustainable.

Ethical lending requires lenders and servicers to avoid pressuring customers to borrow more or miss priority bills. It also means not demanding an impossible instalment to stop contact. Debt collection rules restrict pressure tactics around court action and enforcement. Your escalation process must block threats that have no proper basis or seek payment beyond reasonable affordability.

Good practice goes further than the minimum rule through transparent communication across multiple channels. Explain the consequences of each option in plain language, and signpost free debt advice early. The FCA joined other regulators in warning firms about harmful debt-collection practices, including excessive contact and poor communication.

Make vulnerability change the next action

The Financial Conduct Authority’s vulnerability guidance describes people as especially susceptible to harm because of personal circumstances or inadequate care. Its FG21/1 guidance identifies health, life events, resilience and capability as common drivers.

A flag identifying vulnerable customers is useful only when it changes treatment. If your system records a mental-health condition but still sends automated demands at the same frequency, the control has failed.

A notepad and pen sit on a sunlit desk beneath a Forbearance headline.

Your workflow should let trained staff adjust contact frequency, communication formats, recovery pauses or referral routes when a flag is raised. Record the customer’s needs, the adjustment offered, whether they accepted it and any review date.

You also need careful data handling. Vulnerability information may include health details or other sensitive personal data. Under the Data Protection Act 2018 and UK GDPR, collect only information you need, restrict access, set retention rules and give staff clear instructions on accurate case notes.

The UK Regulators Network’s joint debt-collection statement states that customers in collections are highly likely to have characteristics of vulnerability, including inadequate income and over-indebtedness. That should shape your default assumptions, staff training and monitoring.

Segment Customers for Support, Not Pressure

Credit control teams often use risk segmentation based on balance, days past due and predicted recoverability. These measures help, but they do not show what support a customer needs or which treatment is suitable.

Add outcome-based indicators to the model. This gives staff a reasoned route to suitable action, rather than a blanket escalation rule.

Customer signalAppropriate routeEvidence to retain
First missed payment with no known difficultyClear reminder, easy repayment options and a chance to contact youNotice sent, channel used and response
Repeated missed payments or failed arrangementsAffordability discussion and tailored repayment reviewAssessment, offered options and agreed plan
Debt-advice involvementPause active pursuit for a reasonable periodAdviser details, pause date and review date
Vulnerability indicator or disclosed life eventSpecialist handling and adjusted communicationNeed identified, adjustment and outcome
Disputed balance or unclear account historyStop escalation until the issue is investigatedDispute record, investigation steps and resolution

Segmentation should never become a score that treats vulnerability as a recovery risk to overcome. Vulnerability is a service need that changes the route through the process.

Review outcomes for each segment by comparing arrangement completion, repeat contact, complaints, escalations and customer disengagement. A high-value cohort may need senior review, but account value alone does not justify harder contact.

This approach also improves FCA collections compliance because it shows why different customers received different treatment. Records should demonstrate a fair rationale based on circumstances, not an unexplained agent preference.

Build Audit Trails and Management Information in Real Time

An audit trail is the case history that lets an independent reviewer reconstruct what happened, why it happened and whether the customer received fair treatment. You cannot create a credible trail after the event by adding generic notes.

Computer screen showing audit logs and workflow analytics beneath an Audit headline.

For every material step, record the date, channel, agent or system, information received, decision made, approval level and next review point. Keep copies of correspondence, call recordings and sensitive case notes where your retention policy permits, in line with the Data Protection Act 2018. Record failed contact attempts too, because contact frequency can matter as much as the content of a successful call.

Automated workflows can improve consistency when they contain meaningful controls. A system should suppress contact during an agreed debt-advice pause, stop litigation referral where an arrangement is current, and route vulnerability disclosures to trained teams. It should also retain the trigger, decision logic and any human override.

Automation alone does not prove fair treatment. Test each workflow against real customer journeys. Check whether staff-entered data is accurate, queues meet service-level targets and rules create unexpected outcomes for any group.

Your board-level management information should test whether debt collection rules operate effectively and produce fair customer outcomes. A useful report could include the following measures:

MeasureWhat it can reveal
Arrangement kept rate and early break rateWhether repayment plans are affordable and sustainable
Time from vulnerability disclosure to adjustmentWhether specialist support works quickly enough
Contacts per account before engagement or paymentWhether contact strategies risk becoming excessive
Debt-advice pause complianceWhether systems and agents stop recovery activity when required
Complaints, upheld complaints and redress by journey stageWhere customers experience harm or confusion
third-party collectors’ outcomes against your own resultsWhether outsourced treatment meets your standards
Quality-assurance failures and remediation completionWhether identified weaknesses are fixed and retested

Do not report only a single monthly total. Break results down by product, arrears stage, communication channel, vulnerability indicator and outsourced provider. Trends can reveal a problem that averages hide.

When a metric worsens, document the root cause, the owner, the action date and the post-change test. That is the governance trail an FCA supervisor will expect to see during a Consumer Duty review.

Outsource Collections Without Outsourcing Accountability

Third-party collectors can act on your behalf, but they don’t take away your regulatory responsibility. You remain accountable for the customer outcome, the information shared, the conduct used and the decisions taken in your name.

Before appointing debt collection agencies, assess their permissions where relevant, complaint handling, vulnerability process, staff training, security controls, call monitoring and escalation standards. Then make those requirements contractual.

Your contract should give you access to case records, call recordings, quality results, complaint data and performance information. It should define UK GDPR and Data Protection Act 2018 controls, including access restrictions and retention obligations. It should also set out when the agency must stop activity, refer an account back, report a vulnerability disclosure or seek authority before legal action.

The FCA’s portfolio letter for debt purchasers, collectors and administrators stresses the need to embed fair treatment of vulnerable customers across the customer journey. That expectation includes your outsourced journey.

Sample cases every month, not only when a complaint arrives. Compare call quality, contact frequency, arrangement sustainability and escalation decisions across third-party collectors. If you find poor practice, stop the affected pathway, correct customer harm where needed and test the fix before restarting activity.

For commercial unpaid invoices outside the regulated consumer-credit framework, careful commercial debt recovery still protects your reputation and customer relationships. Commercial Debt Recovery can help you identify an appropriate specialist for the debt’s value, age, documentation and complexity.

Use a 90-Day Rebuild Plan

A smaller credit control team does not need to replace every system before improving its collections controls. It needs a clear sequence, named owners and evidence that each change works.

  1. Days 1 to 30: Map every arrears and recovery journey, including automated letters, calls, payment plans, vulnerability handling, debt advice, disputes, legal referral and activity managed by third-party collectors. Compare each step with the applicable debt collection rules and conduct requirements.
  2. Days 31 to 60: Fix the highest-risk gaps. Add mandatory case fields, contact-frequency controls, debt-advice pauses, forbearance options, vulnerability routes and approval checks for enforcement. Retrain staff using real case scenarios, then assess whether they apply the policy correctly.
  3. Days 61 to 90: Start quality sampling, management information reporting and outcome testing. Give senior management a remediation log with the issue, customer impact, accountable owner, due date and evidence of closure.

Keep a change register. It should show what you found, why it mattered, which customers may have been affected and what you did to correct the position. This record is more persuasive than a polished policy that has never been tested against live accounts.

Frequently Asked Questions

What is FCA collections compliance?

FCA collections compliance means recovering regulated consumer credit debt in line with CONC 7, the Consumer Duty and other applicable legal requirements. It requires firms to show that their policies, communications, decisions and escalation routes support fair customer outcomes.

Does CONC 7 apply to commercial debt collection?

Ordinary unpaid commercial invoices usually fall outside the FCA consumer-credit regime. However, contract terms, court rules, data-protection law and general standards of fair conduct still apply, so firms should identify the correct regulatory perimeter for each case.

How should firms treat vulnerable customers in collections?

A vulnerability indicator should change the customer’s treatment, not simply add a note to the account. Firms should adjust communication, contact frequency, recovery pauses or referral routes where appropriate, and record the need identified, the support offered and the outcome.

What evidence will support an FCA collections audit?

Firms should retain case histories showing the information received, decision made, approval level, customer communications, pauses, arrangements and review points. Management information should also test arrangement sustainability, complaints, contact frequency, vulnerability support, debt-advice pauses and outsourced collector performance.

Build a Collections Model You Can Defend

A defensible collections model provides evidence of debt collection compliance through fair, informed and controlled recovery decisions. It gives customers realistic routes to resolve their situation, protecting customer relationships while giving your board evidence that the process delivers good outcomes.

FCA collections compliance becomes stronger when forbearance, vulnerability support, audit trails and management information sit inside the daily workflow. If an auditor follows one customer file from missed payment to resolution, the record should show care, consistency and a clear reason for every significant decision.