Call-recording governance as an ISO 27001 control for collections firms
Collections firms hold call recordings containing personal and financial data that regulators and ISO 27001 auditors both scrutinise. This guide covers the access, retention, and disclosure controls that close the governance gap.
By Kellwick Team · August 6, 2026 · 7 min read
Call recordings in a collections or credit management environment carry a data density that few other assets match. A single call between an agent and a customer may contain full name, account number, outstanding balance, payment plan terms, income details volunteered during an affordability discussion, and in some cases health information disclosed to explain a period of financial difficulty. That recording sits on a server for months or years, accessible to an uncertain number of employees, with no retention clock visible to the person who made the call.
ISO 27001 does not single out call recordings for special treatment. But when an auditor with collections or financial services experience reviews the information asset register, access controls, and retention policy of a collections firm, the call recording estate is one of the first places they look. It is an asset class that frequently has the highest data sensitivity, the weakest access controls, and the most ambiguous retention position of anything in the ISMS scope.
The information asset picture: recording as a defined asset class
The starting point is classification. A collections firm's information asset register needs to include call recordings as a distinct asset class, not as an undifferentiated sub-item of "telephony systems." The record should capture: the system used to store recordings (on-premises recording server, cloud telephony platform, quality management suite), the data categories present in recordings (personal data, financial account data, special category data where applicable), the retention period, the access control model, and the asset owner.
Where recordings contain special category data - a customer disclosing a physical or mental health condition as context for a missed payment - the classification needs to reflect that. GDPR's Article 9 requirements for special category data apply to recordings just as they apply to structured database fields. In practice, collections firms rarely capture this at the recording level because it is difficult to know at the time of recording whether special category data will be disclosed. The governance response is to acknowledge that some proportion of recordings are likely to contain special category data and to apply access controls and retention terms appropriate to that risk level.
Access controls: who can listen to a recording and why
Access to call recordings in a collections environment is frequently broader than it needs to be. Team leaders have access. Quality assurance staff have access. Compliance has access. Sometimes IT has access. Sometimes access was granted during a system implementation and was never reviewed.
ISO 27001's principle of least privilege (A.8.3, A.8.18) applies here as it does to any other asset. The access control record for the call recording system should reflect: which roles have access and why, what the access was approved for (QA review, complaint handling, regulatory request, training), when access was last reviewed, and whether any access was removed since the last review.
A common finding in collections environments is that access to call recordings is managed entirely at the system level - a toggle that grants access to all recordings - rather than at the data level, where access is granted for a specific call or a specific customer account. Where the recording system permits record-level access control, this is preferable and the ISMS should document why the firm's current model was chosen and what compensating controls exist if system-level access is the only option.
De-provisioning is a particular risk. Agents who leave the firm should have recording system access removed as part of the standard joiner-mover-leaver process. But recording platforms are often not connected to the identity management workflow that handles CRM, email, and other standard systems. An auditor will ask when the recording system access list was last checked against the HR leaver list. If the answer is "never" or "last year," that is a finding.
Retention: the regulatory and audit convergence point
The FCA's Consumer Duty and the FCA's rules under CONC (Consumer Credit sourcebook) create retention obligations that interact with GDPR's storage limitation principle in ways that are genuinely difficult to resolve. CONC requires certain records to be retained for defined periods. GDPR requires that personal data is not retained longer than necessary. For call recordings, "necessary" is not self-evident and depends on the purpose for which the recording was made.
A defensible retention schedule for collections call recordings typically distinguishes between: routine servicing calls (shorter retention, aligned to the likely period within which a complaint or dispute could arise); calls relating to a payment arrangement or an affordability assessment (longer retention, aligned to the term of the arrangement plus a dispute window); calls in which a formal complaint was raised or a vulnerable customer flag was applied (retained until the complaint is resolved and the retention period for complaint records has expired); and calls subject to a legal hold or regulatory request (retained until the hold or request is resolved).
The ISO 27001 evidence requirement is that this schedule is documented, is approved by appropriate authority, and is implemented in a way that can be demonstrated. An automated retention and deletion policy in the recording platform - configured, tested, and evidenced with a configuration screenshot and a deletion log - is the standard the auditor wants to see. A retention policy document that has not been connected to any automated process is a gap.
Disclosure discipline: responding to DSARs and regulatory requests
Collections firms receive data subject access requests (DSARs) that frequently include a request for call recordings. They also receive regulatory requests from the FCA, the Financial Ombudsman Service, and other bodies that may require specific recordings to be produced.
The ISO 27001 evidence layer for disclosure covers two things: that the process for handling these requests is documented and followed, and that disclosures are logged. The log should capture: the request reference, the date received, the recordings identified as in scope, the disclosures made (to whom, on what date, in what format), and any recordings that were determined to be out of scope with a brief note on the rationale.
Disclosure discipline also means not over-disclosing. A DSAR entitles the data subject to their own personal data. A recording that includes a third party - a partner, a guarantor, another customer who was accidentally included in a transferred call - requires redaction before disclosure, or in some cases may be withheld in part under the third-party exemption. The evidence that this consideration was applied is the review note on the DSAR response record.
FCA and ICO context: parallel obligations, shared evidence
The FCA's supervisory focus on collections firms includes call monitoring as a standard element. Consumer Duty assessments frequently involve reviewing call recordings to assess whether agents are meeting the fair value and support obligations under the Duty. An FCA visit that finds inadequate access controls or an unimplemented retention policy will generate the same remediation requirements as an ISO 27001 audit finding - with the added consequence of regulatory sanction risk.
The ICO's enforcement pattern in credit and collections includes cases arising from inadequate protection of call recordings containing financial data. Evidence of a systematic access review process, a functioning retention schedule, and a DSAR handling log demonstrably strengthens the position in any ICO investigation.
The practical advantage of building ISO 27001 controls around call recording governance is that the same evidence pack - the access control record, the retention configuration, the disclosure log - serves the ISO 27001 audit, an FCA supervisory visit, and any ICO enquiry. It is built once and maintained in a single location.
Building the evidence before the audit arrives
The pre-audit checklist for call recording governance in a collections ISMS includes: an information asset register entry for recordings with classification, retention period, and asset owner; a current access control list for the recording system with a dated review record; a retention configuration record showing the current automated deletion settings; a deletion or archive log covering the last 12 months; a DSAR log covering the last 12 months with redaction notes; and a de-provisioning check showing that the recording system access list was reconciled against the HR leaver list within the last review cycle.
None of this requires the firm to build new technology. It requires the evidence that the technology is governed.
Where Kellwick fits
Kellwick provides independent ISO 27001 readiness advisory to credit and collections firms, working through information assets like call recordings as part of a full ISMS gap assessment. Kellwick reviews the access, retention, and disclosure controls in the context of the firm's regulatory obligations - FCA, ICO, and the standard simultaneously. If your recording governance needs a structured review before a certification audit or regulatory visit, our credit and collections readiness service is the starting point.
Need a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.