Building a 90-Day AI Voice Reactivation Workflow for UK Financial Services Firms
Published · Last updated
Thousands of dormant contacts are sitting in UK financial services CRM systems right now, and most firms are treating them as a data hygiene problem rather than a revenue opportunity. That instinct is understandable, but it is also expensive. Every uncontacted record carries a dual burden: a potential GDPR compliance liability and a lost commercial relationship waiting to be recovered.
AI voice agents are changing that calculation. With the right workflow architecture, firms can systematically work through dormant lists, verify consent, qualify intent, and route warm prospects to advisers, all without scaling headcount or cutting corners on FCA obligations.
This guide gives you a prescriptive, stage-by-stage reactivation workflow built specifically for UK financial services operators. Over 90 days, you will move from list preparation and consent verification in week one, through tiered outreach cadences in weeks two to eight, to a structured close-out and adviser handoff by week twelve. Every stage includes CRM write-back and audit trail requirements to keep your process defensible under existing regulatory frameworks. If you manage a dormant database and want a compliant, measurable path to revenue, this is where you start.
Why Dormant CRM Contacts Are a Dual Liability in UK Financial Services
In UK financial services, a dormant CRM contact is broadly defined as one with no meaningful interaction for six to twenty-four months. The precise threshold varies by sub-sector: mortgage brokers typically flag contacts after twelve months of silence, insurers after a lapsed renewal cycle, and IFA firms after six to twelve months without a review touchpoint.
That sitting database creates two distinct problems.
The compliance problem is immediate. GDPR Article 5(1)(e) requires personal data to be kept no longer than necessary for the purpose for which it was collected. A contact record held beyond its active business purpose, with no refreshed consent and no documented retention justification, is a storage limitation breach in waiting. Lapsed consent compounds the risk: where the original lawful basis was time-bound or behaviour-triggered, firms holding that data without a current valid basis face ICO enforcement exposure. Penalties reach up to €20 million or 4% of annual global turnover. FCA record-keeping rules create a parallel pressure, requiring firms to retain records for five to six years under SYSC 9.1.1R, while GDPR simultaneously penalises over-retention without justification. Unworked lists sit uncomfortably in that gap.
The revenue problem is a missed opportunity. Dormant contacts are not cold leads. They already cleared initial KYC checks, passed suitability screening, and expressed product intent. The cost to re-engage them is materially lower than sourcing and qualifying a new prospect from scratch. Every month those contacts sit unworked, that conversion advantage erodes.
The competitive dimension sharpens the urgency. The Treasury Committee's inquiry into AI in financial services found that adoption in financial services substantially outpaces other UK sectors, with insurers and international banks leading the way. Manual reactivation approaches are becoming a structural disadvantage.
A structured, documented 90-day AI voice reactivation workflow addresses both liabilities at once. It moves stale data through a consent-verified, fully logged process that satisfies GDPR accountability requirements, while converting qualified prior-intent contacts into a measurable revenue line.
The FCA and GDPR Compliance Foundations You Must Have in Place First
Before you configure a single call script, your regulatory foundations must be solid. This section covers what the law requires and what documentation you must have ready before Week 1 begins.
The FCA's principles-based approach
The FCA's principles-based supervision model, with no AI-specific legislation as of 2026, means regulated firms must assess each AI use case against existing mandates covering consumer protection, market integrity, and competition rather than wait for prescriptive rules. For voice AI outreach, your campaign design, script content, and opt-out mechanics must each be defensible against Consumer Duty standards.
Choosing your GDPR lawful basis
For dormant contact reactivation, the two viable bases under UK GDPR are legitimate interests and consent. Legitimate interests suits contacts with a clear prior relationship, provided you complete a Legitimate Interests Assessment and build an immediate opt-out into every call. Consent applies where no recent relationship exists or where original data collection did not cover reactivation outreach; it demands a verifiable consent log and tested withdrawal mechanics. ICO guidance on automated decision-making is the authoritative reference for structuring both options. Your choice determines script transparency requirements and audit obligations.
UK PECR and AI voice agents
Under PECR, fully automated calls with no live human path require prior consent. AI voice agents that offer an immediate live-transfer option sit in a different position, but firms must document that classification and apply it consistently.
Documented workflows as regulatory assets
Under principles-based supervision, documented governance is your primary defence. A stage-gated workflow shows the FCA and ICO that outreach was structured, proportionate, and auditable.
Three artefacts required before Week 1
Data audit report: a full inventory of dormant records, data age, and quality status
LIA or consent verification log: depending on your chosen lawful basis, either a completed balancing test or a timestamped consent record with withdrawal-path evidence
Suppression list: reconciled against the FCA Register, TPS, and CTPS, with deceased and invalid records removed
Prerequisites: What to Prepare Before the 90-Day Clock Starts
With your compliance foundations documented, five operational steps need to be completed before any calls are made.
1. CRM data hygiene
Segment your dormant contacts into three recency bands: 6 to 12 months, 12 to 24 months, and 24-plus months. Within each band, tag by product interest (mortgage, pension, insurance, investment) and last known consent status. This segmentation directly determines your outreach tier architecture in Weeks 2 through 8, so accuracy here protects both compliance posture and conversion rates.
2. AI voice agent configuration
Define the agent's permitted scope before a single script line is written. Map your firm's FCA permissions to the products and services the agent is authorised to discuss, and confirm what it must not do, such as deliver regulated advice or quote specific products without human adviser involvement. Every script must then be reviewed against FCA Consumer Duty requirements, particularly the communications outcome under PRIN 2A, which requires that information is understandable and supports good consumer decisions.
3. CRM integration and write-back mapping
Confirm that every call outcome maps to a named CRM field before the workflow launches. The minimum outcome codes are: answered, voicemail left, declined, interested, and do-not-contact. Each code must trigger a field update automatically, not via manual entry, so the audit trail is complete and consistent from day one.
4. Escalation routing
Document in advance which contact categories require immediate handoff to a human agent. Contacts flagged as potentially vulnerable under FCA guidance, those with open complaints, and those in active claims must never remain in an automated call sequence. Define the flag logic in your CRM so escalation triggers without human review of every record.
5. Internal sign-off checklist
Obtain compliance officer approval for all scripts, execute data processing agreements with your AI voice vendor covering GDPR processor obligations, and produce a written risk assessment scoping the campaign. These three artefacts are the governance record that demonstrates proportionate, proactive management if the workflow is ever subject to regulatory scrutiny.
Week 1: Consent Verification and List Qualification
With prerequisites signed off and your CRM integration confirmed, Week 1 has a single, non-negotiable objective: verify consent before a single product message is delivered.
The Consent Sweep
The AI voice agent's entire task this week is identity confirmation, communication preference capture, and outcome logging. No product discussion, no sales messaging. Under COBS 4's requirement that all communications be fair, clear, and not misleading, initiating outreach without first establishing valid consent creates direct regulatory exposure.
Call Script Structure
Every consent call follows the same five-step sequence:
Identify the firm by full trading name
Reference the prior relationship ("You previously spoke with us regarding...")
State the call's purpose explicitly, confirming this is a preference update, not a sales call
Offer an immediate opt-out before any further exchange
Confirm or update contact preferences in real time if the contact remains on the line
This structure satisfies COBS 4's cold calling provisions requiring explicit purpose declaration and opt-out availability on initial contact.
CRM Write-Back Protocol
Every call writes back immediately to four fields: consent status (verified, declined, no answer after three attempts, or number invalid), the timestamp, the script version used, and the agent ID. The audit trail starts on day one, not retrospectively.
Suppression Logic
Contacts who decline, return an invalid number, or are matched against the TPS/CTPS register are hard-suppressed from all subsequent workflow stages and flagged permanently in the CRM under PECR obligations. No retry, no escalation.
Week 1 Output
By day seven, your dormant database resolves into three clean segments: confirmed opt-in (ready for tiered outreach), soft non-contact (no answer, eligible for secondary cadence), and hard suppression (permanently removed). This segmentation is the architecture that Weeks 2 through 4 are built on.
Weeks 2 to 4: Tier 1 Outreach for Highest-Intent Dormant Contacts
With your Week 1 consent-verified list segmented and loaded, Weeks 2 to 4 focus exclusively on the contacts most likely to convert.
Who qualifies as Tier 1: confirmed consent from Week 1, combined with at least one of the following CRM signals: a prior product enquiry that did not complete, a quote requested but not closed, or a policy, mortgage, or investment product within 90 days of renewal or maturity. These contacts have demonstrated prior intent, which is what separates them from the broader dormant pool.
Call cadence: run a maximum of two attempts per contact per week, at different times of day, with a minimum 48-hour gap between attempts. This approach aligns with the FCA's Consumer Duty proportionality principles, which require firms to act in good faith and avoid foreseeable harm rather than follow prescriptive call frequency rules. Two attempts per week is best practice, not a regulatory ceiling, but it reflects a defensible, documented rationale.
Script design: personalise to the specific product context. A contact with an unfinished mortgage review hears a different opening than one approaching a pension contribution deadline or an insurance renewal. Every Tier 1 script includes a concise value proposition and, critically, an immediate offer to transfer to a human adviser or book a callback. The AI voice agent qualifies and connects; it does not advise.
Outcome routing: the decision tree has three paths. Interested contacts are flagged immediately for adviser follow-up or booking confirmation. Contacts who answer but are not ready move to Tier 2 nurture in Weeks 5 to 8. Contacts who do not answer after two attempts also move to the Weeks 5 to 8 secondary cadence rather than being suppressed.
CRM write-back after every Tier 1 call: log the outcome code, disposition, interest level (hot, warm, or cold), call duration, and any specific objection or product query raised. Advisers receiving a warm transfer should have full context loaded before the conversation begins, removing the friction that kills handoff quality.
Weeks 5 to 8: Tier 2 and Tier 3 Outreach and the Nurture Cadence
Contacts who answered in Weeks 2 to 4 but signalled they were not ready to engage, plus those from the soft non-contact bucket who never answered the Week 1 consent call but never formally opted out, form your Tier 2 cohort. They are not warm leads, but they are not closed either.
Tier 3 is the oldest dormant segment: contacts with no meaningful interaction in 24 or more months. Brand recall has faded and product circumstances have almost certainly changed, so specific product propositions are premature.
Tier 2 Script Architecture
Open with a soft re-engagement hook rather than a product ask. Reference something relevant to the contact's prior interest: a rate environment shift for a mortgage contact, a regulatory change affecting their pension, or a service improvement at the firm. This approach satisfies COBS 4's fair, clear, and not misleading communication standard by leading with genuine relevance. The call to action should be light; invite a callback booking or a brief preference update, not a product discussion. Pushing too hard at this stage moves compliant nurture into pressure selling territory.
Tier 3 Script Architecture
Keep Tier 3 calls narrow. Confirm identity, confirm communication preferences, and do nothing more unless the contact re-engages. If they do re-engage, promote them immediately to Tier 2 handling and apply the corresponding script. If they do not, apply a 12-month suppression flag, close the contact within the current workflow cycle, and document the decision in the CRM.
Combined Cadence and CRM Discipline
For both tiers across Weeks 5 to 8, the cadence is a maximum of one call attempt per contact per week, with call times alternated to respect availability patterns. After every successful call interaction, an automated summary email is generated and sent to the relevant adviser, creating a second documented record alongside the CRM entry. This two-layer approach directly supports FCA record-keeping obligations under COBS Schedule 1.
Every outcome, including no-answers, must be written back to the CRM with attempt number, date, time, and disposition code. A contact with four logged no-answer attempts across four weeks demonstrates proportionate, documented outreach if the record is ever reviewed.
CRM Write-Back and Audit Trail Architecture Throughout the 90 Days
Logging every call outcome across all three tiers is only half the architecture. The structure underpinning those logs determines whether your 90-day workflow survives regulatory scrutiny.
Why write-back is non-negotiable
The compliance case is already established, what matters here is the architecture. Continuous CRM write-back is the primary evidence base for demonstrating that outreach was proportionate, consent-based, and in the customer's interest. Under principles-based supervision, documented proof of process replaces prescriptive rules; without it, your workflow has no regulatory standing.
Minimum required fields per call
Every call, regardless of outcome, must write back:
Contact ID and call date/time stamp
Call outcome code (answered, voicemail, declined, no answer, number invalid)
Agent script version used (critical if scripts are updated mid-campaign)
Consent status (confirmed, declined, or unresolved)
Interest level (hot, warm, cold, or not applicable)
Escalation flag (vulnerable customer, open complaint, or immediate transfer required)
Next action assigned (adviser follow-up, callback booked, suppressed, or no further contact)
Summary email as a second audit record
After every successful interaction, an automated summary email is sent to the relevant adviser or account owner. It contains the call outcome, interest level, and recommended next action. This creates an independent record outside the CRM, which matters if a CRM entry is later edited or disputed.
Retention periods
FCA COBS record-keeping rules and GDPR Article 5(1)(e) storage limitation both apply. Configure your CRM to retain call outcome records and consent logs for a minimum of five years, reflecting standard FCA conduct record requirements, and suppress any record that has exceeded its retention period automatically.
From campaign to permanent asset
The database that emerges from 90 days of structured, fully logged outreach is not a campaign artefact. It is a cleansed, segmented, compliance-ready contact asset that supports future reactivation cycles, adviser pipeline reporting, and regulatory disclosure without requiring any retrospective data work.
Sub-Sector Adjustments: Mortgage Brokers, Insurers, and IFAs
The core workflow architecture applies across all three sub-sectors, but script-level adjustments are non-negotiable. Each firm type carries distinct dormancy dynamics and regulatory constraints that a single generic script cannot satisfy.
Mortgage brokers hold dormant contacts who typically stalled because rates or affordability thresholds made proceeding unviable at the time. Reactivation scripts should reference changed rate conditions and offer an affordability reassessment or product transfer review as the call-to-action. Critically, the AI voice agent must stay on the information side of the regulated advice boundary: it can flag that conditions have shifted and offer to connect the contact with an adviser, but it cannot recommend a specific product or course of action. That distinction must be hardcoded into the script, not left to the agent's discretion in-call.
Insurance firms face a split dormancy picture. Lapsed quote contacts, who requested a premium but did not convert, respond well to an updated comparison framing. Dormant policyholders require a softer, service-led approach; the AI agent should not probe claims history or policy status before a human adviser is involved, as doing so risks triggering obligations under ICOBS that the automated interaction is not equipped to handle.
IFAs operate the most relationship-sensitive databases. Where the CRM holds the named adviser's details, the reactivation script should reference them directly and frame the outreach as a proactive client review on behalf of that adviser, not a sales call. Tone here should be warmer and more personal than the scripts appropriate for mortgage or insurance outreach.
Across all three sub-sectors, the FCA's Consumer Duty requires that automated outreach accounts for potentially vulnerable customers. Every AI voice agent script must include a vulnerability identification prompt, with an immediate escalation path to a human agent and a suppression flag applied automatically on that contact record.
Firms operating across banking and insurance lines must maintain separate script libraries and consent frameworks, reviewed independently against COBS and ICOBS respectively. A single unified script reviewed only against one sourcebook is a compliance gap.
How to Measure the 90-Day Workflow: The Metrics That Matter
Once your sub-sector scripts are configured, the next task is establishing what success looks like across the full 90 days. Six metrics give you a complete picture.
Contact reach rate measures the percentage of dormant contacts successfully reached via live answer or confirmed voicemail across the entire cycle. It is the primary efficiency benchmark for your AI voice agent; a persistently low rate signals either data quality problems or call-time scheduling that needs adjusting.
Consent verification rate from Week 1 establishes your addressable pipeline before any product messaging begins. Track the proportion of dormant contacts who actively confirm consent during the Week 1 sweep. This figure sets the ceiling on everything downstream and provides documented evidence of a compliant outreach foundation.
Reactivation conversion rate by tier should never be reported as a single blended figure. Track Tier 1, Tier 2, and Tier 3 separately. The gap between tiers reveals which dormant segments deliver the strongest return and directly informs how you weight your next database segmentation. If Tier 1 converts at a materially higher rate than Tier 3, your future list-building priorities become self-evident.
Adviser handoff acceptance rate measures what proportion of contacts flagged as interested and booked or transferred to a human adviser actually complete that follow-up. A low acceptance rate does not indicate a campaign problem; it indicates a qualification problem. The AI layer may be advancing contacts who are not genuinely ready, which requires script refinement rather than more volume.
Compliance incident rate tracks complaints raised, data deletion requests received, and suppression flags triggered post-contact. Keep this number visible at a senior level throughout the 90 days. A rising incident rate is an early warning that your consent framework or script language needs review, well before it becomes an FCA or ICO matter.
Revenue recovered per 1,000 contacts worked is the headline commercial metric. Divide total revenue attributed to reactivated contacts by the number of contacts in the workflow. This single figure converts the entire campaign into a boardroom-ready business case for the next reactivation cycle.
Weeks 9 to 12: Workflow Close-Out, Results Review, and Handoff to Advisers
With your metrics framework in place, the final phase converts campaign data into clean records, warm pipeline, and regulatory confidence.
Week 9: Final Suppression Pass
At the start of Week 9, apply permanent do-not-contact flags to every contact that did not respond across any tier of the workflow. Update the CRM suppression list immediately and create a dated data minimisation record documenting which records were suppressed, the legal basis, and the action taken. Under UK GDPR's accountability principle, this documentation must be retained and producible on request; it is not an optional housekeeping step.
Warm Pipeline Handoff
Every contact flagged as interested or in-progress during Weeks 2 to 8 receives a structured briefing note compiled directly from CRM write-back data: contact history, interest level, specific product query raised, call duration, and recommended next action. Transfer these to human advisers formally, not informally. Under COBS 2.1, the firm's duty of fair treatment does not pause at the AI-to-human boundary; no context should be lost in that transition.
90-Day Performance Review
Compile a single campaign summary report covering reach rate, consent rate, reactivation rate, adviser handoff acceptance rate, compliance incidents, and revenue recovered. Present it internally and set it as the baseline for Cycle 2. A report without a baseline is just a number; a baseline turns it into a performance trend.
Regulatory Documentation Pack
Assemble consent logs, suppression records, script version history, call outcome data, and all post-call summary emails into one compliance dossier. FCA record-keeping rules require voice communication records to be retained for five years; structure the dossier so it can be produced during any supervisory review or ICO inquiry without delay.
Planning Cycle 2
Use the segmentation and script-performance data from the workflow to identify a refreshed dormant cohort and refine underperforming scripts before the next campaign begins. Schedule the next cycle now. Database health maintained as a rolling discipline consistently outperforms a one-off exercise.
How an AI Voice Agent Platform Supports This Workflow End to End
The close-out process described in the previous section produces a clean audit trail and a warm pipeline, but none of that is achievable without a platform built to handle the operational workload underneath it.
A purpose-built AI voice agent platform works through hundreds or thousands of dormant contacts simultaneously, executing the full call cadence without requiring live staff to dial, script, or log outcomes manually. Human resource is reserved entirely for the qualified handoffs the system generates, not the volume work that precedes them.
CRM integration, pulling records, writing back every outcome field in real time, and building the audit trail automatically, is the compliance backbone described in the earlier architecture section.
Post-call summary emails create a second independent record: after every successful interaction, an automated summary reaches the relevant adviser with outcome, interest level, and recommended next action.
Script configuration is built to the specific compliance requirements of each firm before a single call is made. FCA consumer duty obligations across the four outcome areas, products and services, price and value, consumer understanding, and consumer support, vulnerability identification protocols, and GDPR-compliant consent handling are embedded in the agent's logic at setup, so the workflow deploys within your existing compliance framework rather than requiring it to be rebuilt.
Callaidan's AI voice agents are configured to each client's FCA permissions, CRM field structure, and adviser escalation protocols, giving financial services firms a reactivation agent calibrated to their regulatory context rather than a generic dialling tool adapted after the fact.
From Compliance Liability to Revenue Line: Your 90-Day Starting Point
With the platform architecture in place, the case for action is straightforward.
Unworked contact lists accumulate regulatory exposure with every passing month, as already established, both GDPR's storage limitation principle and FCA consumer duty obligations are live liabilities, not future risks. The 90-day workflow resolves that exposure by moving every contact to a documented outcome: confirmed opt-in, active pipeline, or formally suppressed.
The three pillars do the work in sequence. Consent verification in Week 1 establishes a clean, legally sound foundation. Tiered outreach across Weeks 2 to 8 works that foundation into a qualified pipeline, matching call intensity to contact intent. Continuous CRM write-back, with formal close-out in Weeks 9 to 12, converts activity into a permanent audit record and a handed-off adviser pipeline.
The compliance advantage compounds over time. Firms running documented, stage-gated reactivation workflows are measurably better positioned under the FCA's principles-based supervision model than those running ad hoc outreach with no audit trail.
The commercial result is a revenue line attributed directly to contacts that were previously costing the firm money to store and nothing to work.
Financial services firms ready to run this workflow can explore how Callaidan's AI voice agent platform manages the full 90-day cycle, from CRM integration and consent verification through to adviser handoff and post-campaign reporting. Contact Callaidan to discuss your dormant database.
Conclusion
The 90-day workflow does one thing: it moves every dormant contact to a documented outcome. Consent first, tiered outreach second, close-out third, all within FCA and GDPR boundaries.
Dormant contacts carry active regulatory risk, and working them through a structured, auditable process converts that risk into a measurable commercial outcome. Tiered intensity matches effort to intent, protecting both budget and compliance posture. Continuous CRM write-back ensures every contact reaches a recorded outcome.
Your dormant database already exists. The infrastructure to work it compliantly and profitably is available now. The 90-day clock starts when you decide it does.
Frequently asked questions
What is considered a 'dormant contact' in UK financial services?
A dormant CRM contact is broadly defined as one with no meaningful interaction for six to twenty-four months. The precise threshold varies by sub-sector: mortgage brokers typically flag contacts after twelve months of silence, insurers after a lapsed renewal cycle, and IFA firms after six to twelve months without a review touchpoint. These contacts represent both a compliance liability under GDPR and a potential revenue opportunity since they've already passed initial KYC checks and suitability screening.
What are the main regulatory risks of holding dormant contacts in a CRM?
There are two primary risks: First, a GDPR compliance issue—Article 5(1)(e) requires personal data to be kept no longer than necessary for its original purpose. Holding dormant records without refreshed consent or documented retention justification creates a storage limitation breach. Second, an FCA risk—firms must retain records for five to six years under SYSC 9.1.1R, while GDPR simultaneously penalises over-retention. The combination creates enforcement exposure, with ICO penalties reaching up to €20 million or 4% of annual global turnover, and FCA action under Consumer Duty principles.
Can AI voice agents legally make outreach calls to dormant contacts, and what are the key compliance requirements?
Yes, AI voice agents can legally conduct dormant contact reactivation in the UK, but strict compliance requirements apply. Under UK GDPR, firms must choose between legitimate interests (requiring a completed Legitimate Interests Assessment and immediate opt-out on every call) or consent (requiring a verifiable consent log and tested withdrawal mechanics). Under PECR, fully automated calls with no live human path require prior consent, though AI agents offering immediate live-transfer options sit in a different position. Under FCA Consumer Duty, all scripts must be fair, clear, and not misleading, and firms operating across different product lines (banking/insurance) must maintain separate script libraries reviewed against COBS and ICOBS respectively.
What happens during Week 1 of the 90-day workflow, and why is it so critical?
Week 1 has a single, non-negotiable objective: verify consent before any product messaging is delivered. The AI voice agent performs identity confirmation, captures communication preferences, and logs outcomes—no product discussion or sales messaging occurs. Every consent call follows a five-step sequence: identify the firm, reference the prior relationship, state the call's purpose, offer immediate opt-out, and confirm or update contact preferences. By day seven, the dormant database resolves into three clean segments: confirmed opt-in (ready for tiered outreach), soft non-contact (no answer, eligible for secondary cadence), and hard suppression (permanently removed from all contact). This segmentation is the foundation for all subsequent weeks and establishes a compliant, auditable outreach foundation.
What CRM write-back data must be captured for every call to ensure regulatory compliance?
Every call must write back the following minimum required fields: contact ID and call date/time stamp, call outcome code (answered, voicemail, declined, no answer, number invalid), agent script version used, consent status (confirmed, declined, or unresolved), interest level (hot, warm, cold, or not applicable), escalation flag (vulnerable customer, open complaint, or immediate transfer required), and next action assigned (adviser follow-up, callback booked, suppressed, or no further contact). Additionally, after every successful interaction, an automated summary email should be sent to the relevant adviser or account owner as a second independent audit record. These records must be retained for a minimum of five years under FCA COBS requirements and GDPR storage limitation principles, and the entire dossier must be producible during any supervisory review or ICO inquiry without delay.