Most firms treat vulnerable customer call monitoring as a training problem. Teach advisers the four drivers, add a tick-box to the CRM, run a refresher every year. That approach passes an internal audit and it misses the thing the FCA has been pointing at since 2021, and named explicitly in 2025: the customer who never says the word, and whose circumstances your adviser could have detected anyway.

That customer exists in every book. The only place the evidence lives is the recording.

FG21/1 is guidance, not rules — and that makes it harder#

Worth being precise, because a lot of vendor copy gets this wrong. FG21/1 is finalised guidance. It says so itself: "While firms are not bound to adopt or follow any of the specific actions described in this Guidance, they must meet the standards set by our Principles and treat customers fairly."

That sounds like latitude. In practice it is the opposite. A rule tells you what to do, and doing it is a defence. Guidance under the Principles tells you what outcome to reach and leaves the method — and the burden of showing you reached it — with you. There is no clause to point at that says "we did the required thing." You have to show the outcome.

One note on currency. FG21/1 was last updated on 22 July 2026, and the FCA's own update note says it contains outdated references that pre-date the Consumer Duty, directing readers to the Consumer Duty pages. Read it as the standing statement of what the Principles expect on vulnerability, and read the Duty rules alongside it rather than through it.

Which is why the interesting question is never did we train the team on vulnerability. It is can you show what happened on the calls where a vulnerability signal was present.

The gap the FCA named in 2025#

In March 2025 the FCA published its review of firms' treatment of customers in vulnerable circumstances — built on a voluntary questionnaire answered by 725 firms, work with 29 firms across 12 markets, a deep dive into seven banks and building societies, and consumer research covering 1,500 people.

The headline was reasonably positive. Many firms "had taken positive action and made good progress", and the Consumer Duty had "driven a renewed focus amongst firms on delivering good outcomes for customers in vulnerable circumstances".

Then the finding that matters. The FCA reported that consumers in vulnerable circumstances — "especially those with multiple characteristics of vulnerability" — "may not consistently receive outcomes as good as those of other consumers."

Firm-level progress, customer-level gap. And among the areas firms themselves asked for help with, one is the whole problem in a sentence: how to treat customers who do not disclose vulnerability, "both where this is detectable by the firm and in situations where firms don't 'have sight of' their customers".

Detectable, but not disclosed. That is the hard case, and the FCA has declined to make it easier — it confirmed it would not revise the guidance, publishing case studies instead. The standard is not changing. What is changing is the expectation that you can evidence it.

On a phone-based advice or sales floor, "detectable" has a precise meaning. It means something was audible on the call.

The four drivers, and what each sounds like#

FG21/1 names four drivers of vulnerability: health, life events, resilience and capability. Every vulnerability framework in the industry restates them. Very few translate them into what a reviewer is actually listening for.

Health. Cognitive difficulty is rarely announced. It shows up as repetition — the customer asking the same question three times across forty minutes — as confusion about something already agreed, or as a third party quietly supplying answers on the customer's behalf.

Life events. These arrive as asides, usually while the customer is explaining something else entirely. "Since my husband died I've not really kept on top of this." "I'm off work at the moment." "We've just had the baby." Bereavement, illness, redundancy, separation, new caring responsibilities. They are said in passing and they are almost never the subject of the sentence.

Resilience. Audible as hesitation about affordability, mentions of existing arrears, borrowing to cover essentials, or an unprompted worry about what happens if circumstances change.

Capability. Difficulty with numbers, asking what a common term means, agreeing quickly to something they have not been able to restate, or deferring entirely to the adviser's judgement.

None of these is a disclosure. Not one would reach a file note as a vulnerability flag. All of them are on the recording.

Detection is the easy half#

Here is where most vulnerability monitoring stops, and where it should start.

Catching the signal is necessary but it is not the thing being assessed. The expectation reaches past detection: that a firm's systems and processes support and enable customers in vulnerable circumstances to disclose their needs, and that frontline staff have the skills and capability to recognise those needs and respond to them. The FCA's good and poor practice for customers in vulnerable circumstances sets out both, with worked examples of each.

Respond. That is the scored part.

So the questions worth asking of a call where a signal was present are behavioural, and every one is answerable from audio:

  • Was the signal acknowledged, or did the adviser carry straight on to the next question on the fact-find?
  • Did the pace change — was the customer offered more time, a callback, or the option to have someone with them?
  • Was understanding checked afterwards, not with "does that all make sense?" but by asking the customer to say back what they had understood?
  • Did the call still close on first contact, and should it have?

That last one is the uncomfortable question, and it is the one a compliance director most needs answered. A call where a bereavement was mentioned at minute nine and a policy was closed at minute thirty-one is the call that becomes a complaint two years later. The recording proves what happened. The file note says "D&N discussed".

It is also why generic AI scoring is close to useless here. "Vulnerability handled appropriately" is a judgement, and your firm's interpretation of appropriate is not the industry's. Scoring has to be calibrated against your own compliance officer's corrections, or it produces an opinion dressed as a score. That distinction is the substance of call compliance monitoring for FCA-regulated advice firms, and it is not a detail.

The question a sample cannot answer#

There is a second reason this cannot be handled by sampling, and it comes from the Consumer Duty rather than from FG21/1.

PRIN 2A.9.8R requires a firm to "regularly monitor" the outcomes its retail customers are experiencing. PRIN 2A.9.10R(2) then requires that monitoring to enable the firm to identify whether a group of retail customers is experiencing a different outcome for a product compared with another group of customers for that same product.

Read the rule precisely: it is scoped to a product, and it does not name vulnerability as the grouping. Which groups to compare is the firm's judgement.

Here is ours, offered as our view rather than as the rule's text. On a phone-based advice or sales floor, set that rule beside the FCA's 2025 finding that consumers in vulnerable circumstances may not consistently receive outcomes as good as other consumers, and the grouping picks itself. You should be able to answer one question: do customers showing vulnerability signals get worse outcomes here than customers who don't?

That is a question about two populations. You cannot answer it from a sample at any sample size, because the calls carrying the signal are exactly the ones a random sample under-represents and a reviewer-chosen sample misses. To compare two groups you need both groups, which means the whole book.

It is also a question no firm can answer from a vulnerability tick-box, because the tick-box only ever records the customers who disclosed.

Where to start#

Three things, in order.

Define the signals before you define the score. Write down what each of the four drivers sounds like on your calls, in your customers' words, using real examples from your own recordings. A generic list produces generic detection.

Score the response, not the detection. Acknowledged, pace adjusted, understanding checked, close deferred where it should have been. Four binary questions, each evidenced by a timestamped quote, are worth more than any percentage.

Then look at the two populations. Once signals are flagged consistently across the book, that comparison becomes a report rather than a project. If the answer is uncomfortable, you have found it before the FCA or the Ombudsman does.

None of that requires the guidance to change. It requires knowing what was said.

CallGuard AI screens every call for vulnerability indicators against your own scorecard and evidences each finding with a timestamped quote from the transcript. The coaching brief for the adviser is drafted for you and goes out when your reviewer approves it, until you trust the calibration enough to stop checking. If you want to see it run, in a short demo we score synthetic calls against a scorecard like yours. When you want to try your own recordings, we put a DPA in place first.