BFSI Call QA in India: What RBI and IRDAI Rubrics Demand Beyond Sampling (2026)
The short answer
If your floor runs collections for a bank or NBFC, or tele-sales for an insurer, a 2-5% random sample is a weak answer to the question your client’s compliance team will eventually ask: how do you know every call followed the rules? [SRC004] [SRC005]
RBI holds lenders responsible for what their outsourced recovery agents do, and spells out the conduct: no intimidation or harassment, no shaming the borrower in front of family, referees, or friends, no threatening or anonymous calls, no persistent calling, no recovery calls before 8:00 a.m. or after 7:00 p.m., and no false or misleading representations. [SRC001]
IRDAI tele-sales guidance asks callers to state who they are, disclose that the call is recorded, follow an approved script, and sell strictly on the basis of the customer’s needs. Its verification percentages (1% live, 3% of sale calls) are minimums, not a target. [SRC002] [SRC003]
The defensible model in 2026 is census AutoQA with regulator-specific rubrics on 100% of calls, plus exception-based human review of every flagged or low-confidence call. CallPulse is Qualia’s census AutoQA layer for Hindi/English/Hinglish BFSI floors. It is not a regulator certification, and it is not pitched as the cheapest AI. It is pitched as audit-ready evidence on every call. [SRC005] [SRC007]
Who this is for (ICP A and B)
- ICP A (Head of Ops / Contact Center Ops): runs a mid-market Indian BPO floor for banks, NBFCs, card issuers, or insurers and needs to pass client audits without tripling QA headcount.
- ICP B (QA Manager / Quality Lead): owns the scorecard and calibration, and needs a rubric that maps cleanly to RBI and IRDAI language instead of generic soft-skill items.
If you are still deciding whether to leave sampling at all, start with why 2% call QA sampling fails and how to score 100% of calls without hiring more QA. This post is the BFSI-specific layer on top. [SRC009] [SRC011]
Why sampling is hard to defend on a BFSI floor
Three facts stack against a thin sample in regulated BFSI work.
- Responsibility does not transfer to the vendor. RBI states that the ultimate responsibility for outsourced activities, including recovery agents, stays with the regulated entity. IRDAI’s advertisement circular says the same for outsourced cold calling. Your client carries the risk, so it will push the evidence burden down to your floor. [SRC001] [SRC003]
- The breaches that matter are rare events. A threat in the last minute of a long call, a disclosure of the debt to a relative, or a 7:40 p.m. redial is rare per call and severe per incident. Industry analyses of Indian BFSI QA point out that these are exactly the categories a 2% sample misses. [SRC005] [SRC009]
- The industry norm is single-digit coverage. Vendor and industry guides describe manual BFSI QA at roughly 2-5% of calls, or a single-digit percentage, which leaves most conduct unobserved. [SRC004] [SRC006]
One analysis frames the inspector’s question as “did you have a reasonable mechanism to detect this conduct,” and argues that random sampling is increasingly hard to call reasonable when every call can be scored. Treat that as an industry reading, not an RBI quote, but it matches how client audits are trending. [SRC005]
RBI recovery-agent rules, translated into rubric items
RBI’s August 2022 circular applies to commercial banks (excluding payments banks), all-India financial institutions, NBFCs including housing finance companies, co-operative banks, and asset reconstruction companies. It excludes microfinance loans covered by the 2022 microfinance directions, and it supplements the Fair Practices Code for Lenders and outsourcing code-of-conduct guidelines listed in its annex. [SRC001]
| RBI expectation | Rubric item (pass/fail) | Evidence to store |
|---|---|---|
| No recovery calls before 8:00 a.m. or after 7:00 p.m. [SRC001] | Dial time inside the permitted window | Dialer timestamp, borrower time zone |
| No persistent calling [SRC001] | Attempt count per borrower within your client’s policy cap | Attempt log per account per day |
| No intimidation, harassment, or threatening calls [SRC001] | No threats (police, job, CIBIL scare tactics), abuse, or coercive tone | Verbatim transcript span plus audio clip |
| No public humiliation or intrusion on family, referees, friends [SRC001] | Debt not disclosed to anyone other than the verified borrower | Right-party verification step, clip of any third-party mention |
| No false or misleading representations [SRC001] | No invented legal consequences or misstatement of dues | Span of the representation plus correct account facts |
| No anonymous calls [SRC001] | Agent states name and the lender or agency they call for | Opening segment clip [SRC004] |
Gistly’s BFSI rubric lists the same items (self and lender identification, permitted hours, no threats, no third-party disclosure, no misrepresentation, frequency limits) as binary checks. That is the right shape: compliance items should be pass/fail with evidence, not a 1-5 “professionalism” score. [SRC004]
IRDAI tele-sales rules, translated into rubric items
For insurance outbound and cross-sell floors, the 2011 Guidelines on Distance Marketing of Insurance Products and IRDAI’s 2015 advertisement master circular give the backbone. IRDAI has consolidated many older guidelines since, so have your client’s compliance team confirm which provisions they treat as current before you lock the rubric. [SRC002] [SRC003]
| IRDAI expectation | Rubric item | Why census beats sampling |
|---|---|---|
| Caller name and language options disclosed; identity disclosed, proceed only after permission [SRC002] [SRC003] | Name, company, and purpose stated; customer permission captured before pitch | One skipped opening is a finding on that policy |
| Client told the call is recorded and can get a voice copy [SRC002] | Recording disclosure present and complete | Easy to auto-check on every call |
| Standardized script covering key features [SRC002] | Mandatory key features and exclusions covered before commitment | Script drift hides in calls no one samples |
| Solicitation strictly on analysis of client needs [SRC002]; financial need analysis referenced before close [SRC003] | Need-analysis questions asked and answers used in the recommendation | Mis-selling is the highest-cost miss |
| No nuisance or harm; do-not-call registry checked [SRC002] [SRC003] | DNC check logged; no pressure after a clear no | Complaints often trace to a handful of agents |
| Live monitoring of at least 1% and verification of at least 3% of sale calls [SRC002] | Human verification queue fed by AutoQA flags first | Spend mandated human minutes on the riskiest calls |
Caller Digital’s 2026 analysis lists the same IRDAI items (recording consent, accurate product description, no mis-selling claims, a verifiable need-analysis trail) and recommends a separate rubric per regulator, because an insurance rubric weights adherence higher than a collections rubric. [SRC005]
KYC, disclosure, and DPDP overlays
Most BFSI floors also carry checks that sit outside the RBI and IRDAI items above:
- Verification before action: was the customer authenticated with the client’s prescribed factors before any account change, and was an OTP confirmed without the agent reading it back? [SRC004]
- Product disclosure: no “guaranteed” language on market-linked products, charges and key conditions stated before commitment. [SRC004]
- Personal data handling: recordings carry account numbers, balances, and identity data, so retention, redaction, and access logs need to be in the evidence pack. See DPDP call QA compliance in India. [SRC008]
- Language reality: Indian BFSI calls code-switch constantly. A rubric that only works on clean English misses the calls where breaches happen. See Hinglish call QA. [SRC010] [SRC004]
The operating model: census AutoQA plus exception review
- Write one versioned rubric per regulator and campaign. Collections (RBI), insurance tele-sales (IRDAI), and service or KYC lines each get their own form, co-owned by QA and the client’s compliance lead. [SRC005]
- Score 100% of calls on the first pass. Every call gets a score on every compliance item, not just the ones a sampler happened to pick. [SRC006] [SRC007]
- Demand verbatim evidence. Every flag should cite the exact transcript span and timestamp, so a reviewer can confirm it in seconds and a hallucinated flag gets dropped. [SRC005]
- Route exceptions to humans. Likely breaches, low-confidence scores, and agent disputes go to a review queue. Clean, high-confidence calls are logged and auto-passed. [SRC005] [SRC011]
- Calibrate against senior reviewers. Measure agreement by item type. One industry benchmark treats Cohen’s kappa above 0.75 on adherence and disclosure items as the point where audit teams stop second-guessing the AI. Tone items usually lag. [SRC005]
- Close the loop the same day. A collections agent with a threat flag at 11 a.m. should be coached before the evening shift, not at the monthly review. [SRC004] [SRC006]
Humans do not disappear. They move from random listening to adjudication, calibration, coaching, and the regulator-mandated verification steps. That is where human judgment adds the most value per minute. [SRC006] [SRC011]
What an audit-ready evidence pack looks like
When a bank, NBFC, or insurer client asks how you monitor conduct, hand them artifacts, not adjectives:
- The versioned rubric per regulator, with each item’s source rule and change log. [SRC005]
- Coverage proof: share of calls scored end to end, by campaign and day. [SRC012]
- Flag log: every compliance flag with clip, span, reviewer decision, and remediation. [SRC005]
- Calibration report: AI vs senior human agreement by item type. [SRC005] [SRC012]
- Off-hours and attempt-count report for collections queues. [SRC001]
- Data handling: retention, redaction, and access records for recordings. [SRC008]
Use the Auto QA software buyer’s guide to test whether a vendor can actually produce these on your audio before you sign. [SRC012]
Where CallPulse fits (and where it does not)
CallPulse is built for census AutoQA on Indian floors: 100% call review, multi-parameter scoring, Hindi/English/Hinglish, CRM updates, and coaching surfaces while calls are fresh. On a BFSI floor that means loading RBI collections items and IRDAI tele-sales items as their own rubrics and sending every flag to a human queue with evidence attached. [SRC007]
- Yes: replace thin sampling on collections, cross-sell, and insurance tele-sales queues with full-floor compliance scoring. [SRC007] [SRC009]
- Yes: Hinglish-heavy BFSI campaigns where English-only tools miss the breach. [SRC010]
- Yes: BPOs that need a client-facing evidence pack instead of a monthly sample summary. [SRC007]
- No: claiming RBI or IRDAI certification, quoting penalties, or replacing the regulated entity’s own compliance function. Compliance ownership stays with your client and your floor. [SRC001] [SRC003]
The bar is the same across Qualia: human-level quality and dense value (Sierra-class ambition), at a price comparable to the human work it strengthens, not the cheapest AI invoice that fails the next client audit. If the same floor also runs AI voice legs for reminders or pre-collections, pair CallPulse with Qualia Voice so AI and human calls share one quality loop. For a wider shortlist, see best call QA software for Indian BPOs. [SRC014] [SRC013]
Related reading
FAQ
What does RBI require from recovery and collections calls?
RBI’s August 2022 circular on recovery agents says regulated entities remain responsible for the actions of their outsourced agents, and must ensure there is no verbal or physical intimidation or harassment, no public humiliation or intrusion into the privacy of the borrower’s family, referees, and friends, no threatening or anonymous calls, no persistent calling, no recovery calls before 8:00 a.m. or after 7:00 p.m., and no false or misleading representations. RBI says violations will be viewed seriously. Each of these maps to a pass/fail item on a collections QA rubric. [SRC001]
What do IRDAI rules expect on insurance tele-sales calls?
IRDAI’s Guidelines on Distance Marketing of Insurance Products (2011) ask tele-callers to disclose their name and language options, tell the client the call is recorded and that a voice copy is available, follow standardized scripts covering key features, and solicit strictly on the basis of the client’s needs. They also set minimum verification: live listening to at least 1% of calls, review of at least 3% of calls that lead to sales, and verification calls to at least 3% of new policyholders each month. IRDAI’s advertisement master circular adds identity disclosure, proceeding only after permission, a financial need analysis reference, and do-not-call checks. Confirm with your compliance team which provisions are current, since IRDAI has consolidated many older guidelines. [SRC002] [SRC003]
Is 2-5% call sampling enough for a BFSI contact center in India?
It is hard to defend. The breaches that hurt BFSI floors (a threat in the last minute of a long call, third-party disclosure, an off-hours dial) are rare events, and rare events slip through thin samples. Industry analyses of Indian BFSI QA describe 2-5% manual sampling as the norm and argue regulators now look for a reasonable monitoring mechanism, not a sampling method. IRDAI’s 1% and 3% figures are minimum floors for verification, not a ceiling on what a careful floor should monitor. [SRC002] [SRC004] [SRC005]
Does AI call QA replace BFSI QA analysts or regulatory verification?
No. Census AutoQA does the first pass on every call and routes exceptions (likely breaches, low-confidence scores, disputed items) to humans. Analysts move from random listening to adjudicating flagged calls, calibration, and coaching. Regulator-mandated steps such as insurer verification calls still need to run as the regulation describes. [SRC002] [SRC005] [SRC011]
Is CallPulse approved or certified by RBI or IRDAI?
No. Neither RBI nor IRDAI certifies call QA software, and this post makes no such claim. CallPulse is Qualia’s census AutoQA layer (100% call review, multi-parameter scoring, Hindi/English/Hinglish, CRM updates) that you configure with RBI- and IRDAI-specific rubric items so your compliance team has call-by-call evidence. Compliance ownership stays with the regulated entity and its service providers. [SRC001] [SRC007]
Sources
- Outsourcing of Financial Services: Responsibilities of regulated entities employing Recovery Agents (RBI/2022-23/108) - Reserve Bank of India
- Guidelines on Distance Marketing of Insurance Products (IRDA, 2011) - TaxGuru (reproduction of IRDA guidelines)
- Master Circular on Insurance Advertisements (IRDAI/LIFE/CIR/MISC/147/08/2015) - Insurance Regulatory and Development Authority of India
- AI Call QA for BFSI and Banking Contact Centers in India - Gistly
- Voice AI Call QA and Scoring in India 2026: Auditing 100% of Calls Instead of Sampling 2% - Caller Digital
- Call Quality Monitoring in BFSI: Compliance, QA and Risk Management - ConvoZen
- Automated Call QA Software | Score 100% of Calls | CallPulse - qualiabits.com
- DPDP Act and Call QA in India: What Contact Centers Must Prove Before the Consent Manager Milestone - Qualia Bits
- Why 2% call QA sampling fails Indian BPOs - Qualia Bits
- Hinglish call QA for Indian BPOs - Qualia Bits
- How to Score 100% of BPO Calls Without Hiring More QA - Qualia Bits
- Auto QA Software Buyer’s Guide: What to Ask Vendors Before You Buy (2026) - Qualia Bits
- Best call QA software for Indian BPOs in 2026 - Qualia Bits
- AI Voice Agents for BPO Call Centers | Voice Assistant - qualiabits.com
Evidence map
- RBI holds regulated entities responsible for outsourced recovery agents and prohibits intimidation, harassment, third-party privacy intrusion, threatening or anonymous calls, persistent calling, recovery calls before 8:00 a.m. or after 7:00 p.m., and false or misleading representations.
Evidence: SRC001 - IRDAI distance marketing guidelines require caller identity and language options, recording disclosure with a voice-copy right, standardized scripts, needs-based solicitation, and minimum verification of 1% live monitoring and 3% of sale calls.
Evidence: SRC002 - IRDAI’s advertisement master circular requires tele-callers to disclose identity, proceed only after permission, reference financial need analysis before closing, and check the do-not-call registry, with responsibility vesting with the insurer or intermediary that outsourced the calling.
Evidence: SRC003 - Indian BFSI contact centers typically audit a single-digit percentage (about 2-5%) of calls manually, which leaves rare high-severity breaches undetected.
Evidence: SRC004, SRC005, SRC006 - Defensible BFSI AutoQA uses versioned regulator-specific rubrics, verbatim evidence for every flag, human review of low-confidence calls, and agreement benchmarks against senior reviewers.
Evidence: SRC005, SRC004 - CallPulse documents 100% call review, multi-parameter QA, Hindi/English/Hinglish support, and CRM updates as census AutoQA for Indian floors.
Evidence: SRC007