CX and AI for financial services

Your customers tell you when they are struggling. Can you prove you heard them?

Consumer Duty moved the bar from good intentions to evidenced outcomes. We build the customer contact layer that produces that evidence as a by product of doing the work properly.

The Fortay impact in financial services

30%reduction in cost per contact
4 to 1platforms consolidated into one
37%first contact resolution improvement
100%of interactions logged and retrievable
The problem

Most firms have the right intent. The difficulty is evidencing it.

Customer makes contact

Queues at the moment of highest anxiety. Some abandon and never come back.

Identification and triage

The same details taken three times across three channels.

Vulnerability signals

Spotted if the agent is experienced and not under pressure.

Resolution

Deflected from the queue rather than resolved. The customer contacts again.

Evidence

Handling time is measured. Outcome is not. The file cannot answer the FCA.

Deflection and resolution are not the same thing. Deflection reduces inbound volume. Resolution delivers the outcome the Duty requires, and it is the only one of the two you can evidence.

The silo problem

Five systems hold one customer relationship. None of them holds all of it.

This is why assembling a Consumer Duty evidence pack is a project rather than a report.

Telephony

Who called, but not the outcome.

Core platform

The account or policy, but not the conversation.

CRM and inbox

What was promised, but rarely what was delivered.

Complaints system

The complaint, but not the signs that preceded it.

Recording and QA

A sample of calls rather than all of them.

1 to 9%Traditional QA reviews a single figure percentage of calls, so the evidence base is an extrapolation from that sample unless every interaction is captured.Why it matters
What we do

Most firms arrive with the same question. Can we use AI here without creating a regulatory problem?

It is a hard question to answer internally. Pilots stall in governance, contact data sits across five systems, and it is difficult to say with confidence which use cases are safe to automate.

Fortay Connect is an independent CX and communications consultancy. We work across the market leading communications and contact platforms, which is what lets us stay outcome focused and technology neutral. Regulated firms bring us in to design the governance first, work out which contact types can be automated safely, and then build on whatever fits the risk profile.

Most of the work is in setting the boundaries. The technology decision comes after.

The service

The Customer Conversation Review

Three weeks. We map where contact is lost, where evidence is missing, and which use cases your risk profile will support. You keep the findings.

What the review covers
Proof

A Welsh mutual that has already done this

Monmouthshire Building Society
They did not arrive with a platform under their arm. They arrived with a notebook.

The strawman comparison made the decision obvious because the work behind it was rigorous, and the partnership has run straight through into delivery.

Project sponsorMonmouthshire Building Society
Monmouthshire Building Society
  • 4 to 1platforms retired into a single cloud estate
  • 100%of contact centre calls now reviewed by AI, up from a single figure sample
  • 25payment seats fully PCI compliant, manual workaround retired
  • 10consultancy days from discovery to decision

A 157 year old Welsh mutual. Three platforms benchmarked through a structured RFP, then delivered by the same team that ran the discovery.

What changes

Four areas where the work shows up in your Duty evidence

Ordered by how quickly the value arrives. Each one produces evidence as a by product rather than as a reporting exercise.

Vulnerable customer care that holds up

Detection sits in the contact layer rather than depending on which agent happened to take the call.

  • Indicators of distress and confusion and financial difficulty detected in real time
  • Documented escalation protocols with the full record preserved
  • Escalation rate tracked as a metric rather than assumed
  • Consistency that manual detection cannot match under volume

A Senior Manager who can own the risk

Governance designed before the technology goes live, not retrofitted after an incident.

  • Decision logic reconstructable by your compliance team
  • No black box responses reaching a customer
  • Bias and accuracy audits built into the operating rhythm
  • Clear oversight data for the accountable Senior Manager

Resolution rather than deflection

Cost per contact falls either way. Only resolution evidences a good outcome.

  • Routine contact handled end to end rather than pushed back to the queue
  • Complex cases routed with context so handling time falls
  • Repeat contact tracked, because a deflected customer usually returns
  • Cost measured per resolution rather than per contact

Evidence on demand

Assembling the Duty evidence pack stops being a manual exercise across five systems.

  • Every interaction logged with a retrievable audit trail
  • Resolution quality and consumer understanding tracked as metrics
  • One timeline per customer across every channel
  • Reporting the FCA expects rather than handling time alone
By sector

Insurance

Claims contact at the worst moment of a customer's year. Vulnerability is the norm rather than the exception.

Building societies

Branch heritage, closed core platforms, and members who expect to be known.

Motor and consumer finance

High volume contact, affordability conversations, and a heavy complaints backdrop.

Wealth and pensions

Fewer contacts, higher consequence, and an evidence burden on every one.

Lending and payments

Arrears and forbearance conversations where the escalation path has to be provable.

Risk and compliance

A named Senior Manager is already accountable for your AI

The FCA has confirmed that AI accountability fits inside existing SM&CR structures. There is no standalone AI Officer role.

SMF4or SMF24 is where AI risk usually lands, at Chief Risk Officer or Chief Operations Officer
35mpotentially vulnerable consumers in the UK, of whom 37 per cent prefer AI support when it is done sensitively
2024the Digital Markets, Competition and Consumers Act widened the definition of a vulnerable customer

Sources: FCA commentary on AI accountability under SM&CR, and NICE research on vulnerable consumers, 2025.

What the AI never does

  • Give regulated advice or make a personal recommendation
  • Make an affordability or eligibility or underwriting decision
  • Confirm whether cover applies to a claim
  • Conclude a complaint or issue a final response
  • Decide a customer's vulnerability status alone. It detects the indicators and escalates

What we put in place

  • Governance designed and signed off before anything reaches a customer
  • Decision logic your compliance team can reconstruct for any response
  • Scheduled bias and accuracy audits to catch model drift
  • A written answer on data residency and whether your data trains the provider's models
  • Outcome metrics built in from day one rather than added before the first audit
How we work

From discovery to embedded change

We work across the market leading platforms, so the design follows the outcome and the risk profile rather than a single product set.

STAGE 01

Map the customer journey

Contact flow across channels, the systems holding each part, and where evidence is currently missing.

STAGE 02

Set the boundaries

Which contact types can be automated safely under your risk profile, and which cannot.

STAGE 03

Design the architecture

Governance first, then technology. Explainable by design so the accountable Senior Manager can own it.

STAGE 04

Implement and optimise

We do not stop at go live. We embed the behaviours and the measurement that keep the evidence intact.

Where to start

Three ways in, depending on how far along you are

Start here

The conversation scorecard

Three minutes. No cost. Instant result.

Ten questions on how customers reach you, what gets recorded, and what you could evidence if the FCA asked tomorrow. You get a score, a benchmark against firms of similar size, and your two weakest areas.

  • What happens to a contact outside your published hours
  • How a vulnerability indicator gets recorded today
  • Whether a deflected contact is counted as resolved
  • How long it takes to assemble an evidence pack
Take the scorecard
The full answer

The Customer Conversation Review

Three weeks. Fixed fee. You keep the findings.

We measure where contact is lost and where evidence is missing rather than asking you to describe it. Week one is discovery across your contact data and systems. Week two is analysis. Week three is the readout to your executive or risk committee.

  • Cost per contact and cost per resolution quantified against your current estate
  • The gaps in your Duty evidence base named and sized
  • Which use cases your risk profile supports and which it does not
  • A 90 day plan you can execute with us or with anyone else

The fee is credited in full against the first implementation phase if you proceed within 90 days. The findings are yours outright and portable to any provider.

Book a scoping call
If you are still looking

Process specific AI for regulated firms

Whitepaper. Free download.

How to scope and frame discovery before any technology decision, including the tractability questions to work through first.

  • Which processes are worth automating and which are not
  • What to establish before a shortlist exists
  • The governance questions that stall these projects
Download the whitepaper
Questions

Frequently asked questions

Can we use AI in customer contact under Consumer Duty?

Yes, provided you can evidence good outcomes rather than good intentions. That means interaction logging, retrievable audit trails, and outcome metrics such as resolution quality and consumer understanding and vulnerability escalation rate. Deflecting a contact is not the same as resolving it, and only resolution evidences a good outcome.

Who is accountable for AI outcomes under SM&CR?

Accountability fits inside your existing structures and does not require a standalone AI Officer role. In practice AI risk sits with the Chief Risk Officer under SMF4 or the Chief Operations Officer under SMF24. A named Senior Manager is already accountable, which is why we design the governance framework before anything goes live.

Will this work with our core banking or policy administration system?

In most cases yes, and often without touching the core platform at all. Where a modern API exists the connection is direct. Where a legacy core exposes nothing usable, automation can work at the interface layer, reading documents and driving the screens your staff already use. One building society automated three roles of back office data entry this way without the core platform being modified.

How do you handle vulnerable customers?

Detection sits in the contact layer and runs on every interaction rather than depending on which agent takes the call. Indicators of distress and confusion and financial difficulty are identified in real time, and a documented protocol escalates to a person with the full record preserved. The AI never decides vulnerability status on its own.

Our AI pilot has stalled. Can you unstick it?

Usually, and the blocker is often not the technology. Pilots stall on governance sign off, on IT capacity, or because the use cases in scope were never agreed. Establishing the boundaries and the evidence model first is what gets them moving, which is what the review is for.

Start with your own numbers

Consumer Duty asks you to evidence outcomes. Find out what you could evidence today.

Three minutes for a read on where you stand, or a scoping call if you want us to go and measure it properly.