Complaints handling is one of the few enterprise processes that comes with its own clock, its own evidence standard and its own supervisor. In the UK, the FCA’s DISP rules require a prompt written acknowledgement, a final response within eight weeks for most complaints — and within 15 business days for complaints falling under the payment services and e-money rules, extendable to 35 business days in exceptional circumstances with a holding response. The final response must accept the complaint, reject it, or offer redress, and it must tell the complainant about their right to refer the case to the Financial Ombudsman Service.
The volumes are substantial even after a sharp fall. The Financial Ombudsman Service received around 214,600 new complaints in 2025/26, down roughly 30% from 305,700 the year before, with hire purchase (motor) the most complained-about product and current accounts close behind, driven largely by fraud and scam cases. Those are only the complaints that escalated past the firm.
This combination — a written rulebook, documentary inputs, a reasoned outcome and a deadline — makes complaints an unusually good candidate for agent assistance. It also makes it a workflow where the wrong automation boundary creates real exposure.
Where the work actually goes
Ask a complaints team where the eight weeks go and the answer is rarely “deciding”. It goes into reconstruction.
A single case requires pulling the customer’s transaction and servicing history from two or three systems, locating the relevant call recordings and correspondence, identifying which version of which policy or terms applied on the date in question, checking whether the customer has vulnerability characteristics recorded, working out whether a similar issue has already been remediated elsewhere, and assembling all of that into a file a case handler can judge. Only then does someone spend twenty minutes reaching a decision that the file largely dictates.
That reconstruction is the automatable part. It is mechanical, it is evidence-bound, and it is where the deadline is lost.
The boundary: prepare, do not decide
The design rule is the one that applies across regulated case management: the machine assembles the case, the qualified person decides it.
An agent-assisted complaints workflow can reasonably do the following. Classify the complaint against the firm’s own taxonomy and route it, flagging the applicable deadline. Extract the customer’s stated allegation and desired outcome from free text, a letter or a call transcript. Retrieve the applicable policy, terms and internal procedure as they stood on the relevant date. Reconstruct a timeline from systems of record. Identify whether the complaint matches a known systemic issue or an existing remediation. Draft a findings summary, with each assertion linked to the evidence that supports it. And draft the response letter to a template.
What it should not do is determine whether the firm was at fault, decide redress, or send the final response. Those steps carry consequence for the customer and for the firm, and a workflow in which an approval is a policy expectation rather than an enforced gate will eventually skip it. The gate belongs in the workflow definition — the pattern described in adding a human approval step to an agentic workflow — not in the training material.
Vulnerability is the strongest argument for the boundary. Complaints frequently disclose bereavement, illness, financial hardship or coercion, and those disclosures change what a fair outcome looks like. An agent can flag the indicators it found and cite the words that triggered the flag. Judging what they mean is human work.
The disclosure question changed in August 2026
If any part of the workflow speaks to the customer — an intake assistant, a status chatbot, an outbound information request — the EU AI Act’s Article 50 transparency obligations have applied since 2 August 2026, requiring that people are informed they are interacting with an AI system unless that is obvious from the context.
The practical consequence for design is a clean separation between customer-facing and internal components. An internal preparation agent that assembles files for a case handler and never addresses the customer sits outside that interaction obligation; a front-door assistant does not, and needs disclosure built into the first interaction rather than added to a footer later. Firms operating across jurisdictions should confirm the position for each deployment, since disclosure expectations vary and are moving.
Root cause analysis is the underrated prize
DISP 1.3.3R requires firms to put in place management controls to identify and remedy recurring or systemic problems — analysing the causes of individual complaints to find root causes common to types of complaint, considering whether those causes affect other processes or products, and correcting them where reasonable.
In most firms this is done with a categorisation field that case handlers pick under time pressure, which means the root cause data is roughly as good as the dropdown. An agent that reads the actual complaint text and the assembled evidence can propose a far richer classification — the specific process step, the system, the communication, the date range — and can cluster cases that a taxonomy separates. That output is not a decision; it is management information, which is precisely why it is a low-risk, high-value place to start.
It also produces something supervisors ask for directly: evidence that the firm can see its own patterns before they are pointed out.
What to measure
Three measures beat throughput. Handler acceptance rate — the proportion of drafted findings a case handler accepts without material change — tells you whether the agent is helping or generating review work. Evidence completeness — how often the assembled file was missing something the handler had to fetch manually — is the metric that predicts whether the deadline improves. And overturn rate at the Ombudsman, tracked against the pre-automation baseline, is the one that matters to the board: assistance that speeds up responses while degrading their quality is expensive, and the cost arrives late.
Deadline compliance is a hygiene measure rather than a benefit measure. It should not get worse; if it improves dramatically, check that cases are not being closed early to stop the clock.
How VDF AI supports complaints workflows
VDF AI runs the pipeline inside the firm’s own environment: ingestion of correspondence and call transcripts, retrieval over policies and procedures with the version that applied on the relevant date, deterministic checks against systems of record exposed as governed tools, and drafting by local models registered on the platform. No complaint file, extracted field or draft response leaves the boundary.
Approval steps are part of the workflow definition, so a draft reaches a case handler before anything is sent, and the handler’s decision is recorded alongside the model version and the evidence that produced the draft. Retrieval respects the same access rules as the underlying systems, so a handler sees what they are entitled to see and no more. What the firm ends up with is a shorter path to a decision, an evidence trail that answers the question a supervisor actually asks — on what basis was this conclusion reached, and who decided it — and root cause data good enough to act on.
Further reading
- AI Agents for Enterprise Case Management and Escalation
- AI Agents for Payment Investigation Workflows
- How to Add a Human Approval Step to an Agentic Workflow
- Human Oversight of AI Systems: EU AI Act Requirements
- Permission-Aware Private RAG On-Premises
Sources
- FCA Handbook — DISP 1.6, Complaints time limit rules
- FCA Handbook — DISP 1.3, Complaints handling rules
- Financial Ombudsman Service — Annual complaints data and insight 2025/26
- European Commission — Transparency obligations under Article 50 of the AI Act
Handling complaints against a regulatory clock? See how VDF AI builds governed agent workflows inside your own environment, or book a demo.