You make AI voice collections RBI-compliant by building the Fair Practices Code conduct rules into the agent, logging every call for full audit, and meeting DPDP consent and purpose-limitation duties.
What conduct do India's collections rules actually expect?
Debt recovery in India runs on a simple principle. You can pursue what is owed, but never the borrower's dignity. The RBI's Fair Practices Code and its expectations for recovery agents set the tone, and a customer in default is still a customer the rules protect.
Strip away the legal language and a compliant collections call looks like this:
- No harassment or intimidation: no threats, no abusive language, and no pressure routed through the borrower's family or neighbours.
- Calls only within permitted hours, not late at night or early in the morning.
- The agent identifies themselves, the institution they represent, and why they are calling.
- A respectful tone throughout, even when the borrower is difficult.
- A clear route to raise a grievance, and a record that the borrower was told about it.
None of this is exotic. Any bank or NBFC running a recovery function knows these rules, and the regulated lender stays accountable for how recovery is conducted on its behalf, whoever or whatever places the call. The rules were never the hard part. Enforcing them on every collections call, across a floor of agents, at the tired end of a long shift, is where the exposure has always sat.
Where does the DPDP Act 2023 fit in?
Conduct is one half of the picture. Data is the other. The Digital Personal Data Protection Act 2023 governs how you handle the borrower's personal data, and collections touches plenty of it: phone numbers, outstanding amounts, employment details, sometimes hardship context shared in confidence.
These duties also sit at principle level. You need a lawful basis to process the data, usually consent or a purpose tied to the loan. You use it only for the purpose you collected it for, protect it with reasonable security, and keep records that show you did. For a voice programme, that means being deliberate about how the voicebot stores and handles that data.
Two things are worth holding onto for a collections programme: the borrower's consent and its scope, and a trail proving the data served recovery and nothing else. A voice agent that logs every input and every action makes that trail easier to produce, not harder.
Is an AI voice agent a new compliance risk, or a control?
Most risk teams meet AI voice collections as a worry first. A machine calling borrowers sounds like a headline waiting to happen, and that instinct deserves a proper hearing rather than a brush-off.
So look at where the risk actually lives on a human floor. An agent can lose their temper, dial outside permitted hours because the dialler pushed a number, skip the identification script under pressure, or promise something they should not. And you find out only if that particular call lands in the small share that QA happens to review.
Compliance on a human floor is mostly a hope backed by a sample. On an AI floor it is a control backed by a log.
An AI agent acts through tools, and every tool call is logged. Configure the calling hours and it simply cannot dial outside them. The identification line lives inside the flow, so it runs every time rather than depending on a memory that fatigue wears down. By call 300 the agent is as measured as it was at call one. None of this makes the machine cleverer than a good human agent. It makes the boundaries structural instead of a matter of discipline, which is what a risk reader is really being asked to trust.
Human floor
- Hours rely on discipline; slips happen
- ID script only if remembered
- Tone varies with mood and fatigue
- QA reviews a small sample
AI voice agent
- Cannot dial outside set hours
- ID line built into the flow
- Consistent, even at call 300
- 100% captured and scored
How does AI turn compliance from a hope into a control?
The difference that matters most to a risk reader is coverage. A human floor is audited by sampling: you listen to a slice of calls, score them, and infer the rest. An AI floor can be audited in full. Every interaction is captured, transcribed, and scored against your conduct rules automatically, around the clock, and we run this at 100% audit coverage across the interactions we handle, so the record is the whole population of calls and not a hopeful cut of it.
That changes what an audit even is. Instead of asking whether a breach happened somewhere in the calls nobody heard, you search every call for the pattern and know. A regulator's question stops being an argument and becomes a query.
What should a risk or legal team require before go-live?
None of this is automatic. An AI agent is only as compliant as the guardrails around it. Before you sign off a live deployment, a risk or legal team should hold out for a short, specific list:
- Guardrails: configurable calling hours, a locked identification and disclosure script, and hard limits on what the agent may say or promise.
- Audit: a complete, timestamped log of every call, transcribed and scored against your conduct rules, retained for the period your policy demands. Ask to run a live query against it yourself, not just read a sample report.
- Consent and purpose: proof of the borrower's consent, its scope on record, and controls that stop the data being used for anything beyond recovery.
- Data residency and sub-processors: a full map of where the data is stored and processed, and which third-party speech services touch it along the way, all behind a recognised security standard. We hold ISO 27001 certification for our information security management.
- Escalation: a clean handover to a human the moment a call turns to a dispute, hardship, or a grievance. The agent runs the routine, compliant conversation; a borrower in real difficulty is a person's job, not the model's.
Get those five in writing and the compliance question moves from trust to evidence. That is the entire point of running it this way.
This article describes India's recovery-conduct expectations and the DPDP Act 2023 at the level of established principles. It is not legal advice. Rules change, and your exact obligations depend on your institution, your regulator, and your data-protection posture. Confirm the current requirements with your own compliance and legal teams before you act.
Manual floor vs AI voice agent: compliance controls
| Human collections floor | AI voice agent |
|---|---|
Frequently asked questions
Does the RBI allow AI voice bots to make collections calls?
India's recovery-conduct rules are written around behaviour, not the caller's identity. They require no harassment, permitted calling hours, clear identification, respectful conduct, and grievance access. An AI voice agent can meet each of these if it is configured to, and if it identifies itself as an automated assistant. The obligation is to conduct the call properly, whoever or whatever places it.
How does an AI agent stay within permitted calling hours?
Calling hours are set as a hard rule in the agent's configuration, not left to a person watching the clock. The agent cannot place a call outside the window you define, and every attempt is logged. On a human floor the same rule leans on dialler settings and individual discipline, which is where slips tend to creep in.
What does the DPDP Act 2023 require for collections data?
At principle level, you need a lawful basis to process the borrower's personal data, usually consent or a purpose tied to the loan. You use it only for that purpose, protect it with reasonable security, and keep records showing you did. A logged AI agent makes the record-keeping and purpose-limitation trail easier to produce than a human floor does.
Can an AI collections agent handle disputes and grievances?
It should not try to. A well-designed agent recognises disputes, hardship, and grievances, then hands the call to a human with full context. The rule of thumb is simple: the agent runs the routine, compliant conversation and escalates anything that needs judgement or a human ear. The handover itself is logged, so you can prove the borrower was routed correctly.
How is a fully auditable AI floor different from human QA?
Human QA samples. It listens to a slice of calls, scores them, and infers the rest, so a breach can sit undetected in the calls nobody heard. An AI floor captures, transcribes, and scores every interaction automatically. We run this at 100% audit coverage. An audit stops being an argument about the unheard calls and becomes a search across all of them.