Insights · Compliance
FCA Consumer Duty:
Why vulnerability detection needs to be real-time.
The FCA Consumer Duty creates three obligations. Most firms can meet two of them. The third — documenting that vulnerability was assessed before consequential decisions — requires technology that does not yet exist in most compliance stacks.
The three obligations
FCA Consumer Duty (effective July 2023) requires UK financial services firms to:
- Identify vulnerable customers
- Take appropriate action to avoid foreseeable harm
- Document that vulnerability was considered in consequential decisions
Most firms have processes for the first two — vulnerability training, escalation pathways, specialist teams. But the third obligation is where the gap widens. If a loan is declined and the applicant was in genuine distress, the FCA expects evidence that distress was identified and appropriately handled before the decision was communicated. Post-hoc review does not satisfy this requirement.
Why post-hoc review fails
Compliance teams reviewing recorded calls after the fact are looking for evidence of vulnerability that has already caused harm. The complaint has already been filed. The customer has already experienced the distress. The regulatory exposure has already been created.
Real-time detection changes this equation. When emotional distress is identified during the interaction, firms can intervene — route to a trained handler, pause the decision, offer signposting — and document that they did so. This is the difference between a Consumer Duty audit trail that demonstrates compliance and one that documents failure.
Not just what they say — how they say it
Transcript-based analysis misses the signal that matters most. A customer saying "I understand" while their voice trembles, pitch rises, and speech rate accelerates is not a customer who understands — they are a customer in distress. Traditional speech-to-text systems cannot detect this. They process words, not the emotional state behind them.
EchoDepth listens to live calls in real-time, analysing the acoustic properties of speech itself:
- Voice prosody — pitch contour, speech rate, pause patterns, vocal tremor
- Arousal markers — physiological stress indicators audible in voice quality
- Valence signals — emotional tone shifts from positive to negative states
- Dominance cues — confidence collapse, acquiescence under pressure
This is not post-call transcription analysis. This is listening to the call as it happens — detecting the emotional subtext that words alone cannot convey.
Real-time intervention, not post-hoc review
When vulnerability signals cross configurable thresholds — sustained high arousal, valence collapse, dominance drop — EchoDepth flags the interaction in real time. Agents receive on-screen alerts. Supervisors can be notified. The call can be routed to a specialist handler. Intervention happens before a consequential decision is communicated.
The output is a timestamped audit trail: VAD scores, alert triggers, intervention actions taken. This is precisely the evidence the FCA requires under Consumer Duty — documented proof that emotional risk was assessed before a consequential decision was made.
The scale of the problem
In 2024, UK financial services firms faced £176M in FCA fines (up 230% year-on-year) and paid £479M in customer redress. The cost of not detecting vulnerability at the point of interaction is no longer theoretical.
EchoDepth does not replace human judgement. It gives human judgement a foundation — structured, timestamped evidence that emotional risk was assessed before decisions were made. See how it works →
Frequently Asked Questions
What does FCA Consumer Duty require for vulnerable customer identification?
FCA Consumer Duty (PS22/9, effective July 2023) requires firms to demonstrate proactive vulnerable customer identification — they must not rely solely on customers self-identifying as vulnerable. Firms must have systems and processes that identify vulnerability signals regardless of whether the customer volunteers that information, and must produce auditable evidence of proactive identification on request from the FCA.
How does EchoDepth detect vulnerability in real-time during live calls?
EchoDepth listens to live calls and analyses voice prosody — the acoustic properties of speech itself, not just the words. This includes pitch contour, speech rate, pause patterns, vocal tremor, and arousal markers. When a customer says "I understand" while their voice trembles and pitch rises, EchoDepth detects the emotional distress that transcript analysis would miss. Alerts trigger in real-time, enabling intervention before harm occurs.
What is the difference between transcript analysis and voice prosody analysis?
Transcript analysis processes words after the call ends — it knows what was said but not how it was said. Voice prosody analysis examines the acoustic signal in real-time: pitch, tempo, voice quality, pauses, and tremor. A distressed customer may use compliant language while their voice reveals emotional collapse. EchoDepth analyses both the linguistic content and the emotional subtext simultaneously during live interactions.
Is EchoDepth vulnerability detection GDPR compliant?
Yes. EchoDepth analyses interactions under legitimate interests (Article 6(1)(f)) — the lawful basis being the obligation to comply with FCA Consumer Duty and prevent harm to customers. Analysis occurs at the interaction level. No persistent biometric profile of the customer is built. A Data Protection Impact Assessment is conducted for each deployment. EchoDepth is ICO registered (ZB915633).