AI can meaningfully improve collections performance within the regulatory framework — propensity scoring, channel optimisation, timing models. What it cannot do is automate the things TCPA, FDCPA, and state-level consumer protection laws prohibit. Here is what the boundary looks like.
Collections is one of the highest-value AI applications in financial services by the numbers — small improvements in recovery rates on large portfolios compound quickly. It is also one of the most heavily regulated operational functions at any lender. TCPA, FDCPA, state-level consumer protection laws, and the CFPB's interpretive guidance on unfair, deceptive, or abusive acts and practices all constrain what an AI-driven collections operation can do. The practical question is not whether to apply AI in collections — the ROI case is clear — but what AI can do within the constraint set.
Collections AI projects fail in two ways. The first: the team builds a sophisticated propensity or segmentation model but does not integrate it into collections workflows in a way that changes collector behaviour. The model exists; nothing changes. The second: the team deploys automated outreach capabilities without adequately scoping the regulatory framework, and the compliance review catches problems that require significant redesign.
Key insight: TCPA and FDCPA do not prevent AI from improving collections — they define the boundaries within which AI can operate. Designing to those boundaries from the start produces a system that is both effective and defensible.
"We built the model. Then compliance reviewed the outreach automation we had planned and we had to redesign half of it."
What TCPA Actually Constrains
The Telephone Consumer Protection Act (TCPA) restricts the use of automatic telephone dialling systems (ATDS) and artificial or prerecorded voice messages to contact consumers without their prior express written consent. In a collections context, this constrains automated outreach — AI-driven diallers, automated SMS campaigns, and prerecorded voice messages — significantly.
Prior express written consent is required for autodialled calls or texts to mobile phones. For debt collection, this consent must be obtained at the time the credit relationship is established or through a subsequent consent process. Consent obtained at origination covers most account holders for initial collection contact, but consumers can revoke consent at any time, and revocations must be honoured immediately — a process that needs to be automated and audited.
The TCPA does not prohibit human-initiated calls using manual dialling. Collections operations can use predictive diallers in a compliant way if the dialler does not meet the ATDS definition — an increasingly nuanced technical and legal question after the Facebook v. Duguid Supreme Court decision in 2021. Any collections AI involving automated outreach should be reviewed by counsel with TCPA expertise before deployment.
TCPA constrains automated outreach to mobile phones without consent — the consent management process is as important to design as the outreach automation itself
FDCPA: What You Can Say and When
The Fair Debt Collection Practices Act (FDCPA) governs third-party debt collectors and imposes specific requirements on the timing, content, and frequency of collection communications. The CFPB's Regulation F, which took effect in 2021, extended some FDCPA principles and added specific guidance on electronic communications including email and text.
Key constraints with direct implications for AI-driven collections:
Contact frequency limits: Regulation F creates a presumption that contacting a consumer more than seven times in a seven-day period, or within seven days of a prior telephone conversation, violates the FDCPA. AI-driven outreach optimisation needs to track and enforce these limits across all communication channels.
Time-of-day restrictions: calls are permitted only between 8am and 9pm in the consumer's local time zone. An AI scheduling model optimising for contact rates needs to incorporate this constraint — and needs to use the consumer's time zone, not the operations centre's.
Cease and desist: if a consumer requests that contact cease, all communication must stop except to confirm receipt of the cease notice or to advise of specific legal action. This revocation process needs to be immediate and auditable.
Seven-in-seven contact frequency limits, time-of-day restrictions, and immediate cease-and-desist compliance are non-negotiable constraints that AI outreach must enforce
What AI Can Do Within These Constraints
Within the regulatory framework, AI delivers meaningful collections improvement through three specific applications.
Propensity to pay modelling. A model that predicts which accounts are most likely to pay in response to outreach — and under what conditions (settlement offer, payment plan, specific timing) — allows collections operations to prioritise contacts more effectively than simple days-past-due segmentation. Accounts with high propensity to pay at full balance get early personal contact; accounts that respond to settlement offers get offers earlier in the delinquency cycle when recovery is higher.
Channel preference optimisation. Different consumers respond to different channels. Some respond to text, some to email, some to phone calls. A model trained on historical contact data can predict which channel is most likely to produce a response for a given consumer profile, reducing contact attempts while improving contact rates.
Timing optimisation. Within the time-of-day constraints and the contact frequency limits, there is still meaningful variation in when a consumer is most likely to answer or respond. ML models trained on response rates by day of week and time of day — by consumer segment — can improve contact rates without increasing total contact attempts.
Propensity to pay modelling, channel preference, and timing optimisation deliver collections lift within the regulatory framework — together, improvements of 10–20% in recovery rates on targeted portfolios are realistic
State-Level Overlay
Federal TCPA and FDCPA requirements are the floor. A significant number of states have consumer protection laws that are more restrictive, and compliance at the federal level does not mean compliance in every state where borrowers are located.
California's Rosenthal Fair Debt Collection Practices Act applies FDCPA-equivalent requirements to first-party collectors (lenders collecting their own debt) in addition to third-party collectors — a broader scope than federal law. New York and other states have similar first-party coverage extensions.
Several states have more restrictive contact frequency rules than Regulation F, shorter time windows for permissible calling hours, or additional disclosure requirements for automated communications.
For a lender with a national portfolio, the compliance standard is the most restrictive applicable state law for each consumer, not the most permissive interpretation of federal law. A collections AI system with national scope needs to implement state-level rule variations or operate to the most conservative standard across the full portfolio.
State-level consumer protection laws can be more restrictive than federal TCPA and FDCPA — compliance requires the most restrictive applicable standard for each consumer's state
Building the Business Case Within the Constraints
The ROI case for collections AI is real within these constraints. The constraint set limits automated outreach, but it does not limit propensity scoring, segmentation, channel optimisation, or timing models — all of which improve outcomes without requiring automation of contact initiation.
Realistic targets for a well-scoped collections AI program: 10–20% improvement in early-stage recovery rates through better prioritisation and channel selection on accounts where propensity to pay is high. 15–25% reduction in average collection cost per recovered dollar through more efficient contact allocation. Measurable reduction in complaints from improved compliance with contact frequency and timing rules.
The compliance investment — consent management, revocation tracking, state-level rule implementation, audit logging — is not small. It is also not optional, and treating it as overhead rather than part of the system design leads to the pattern of building first and redesigning after compliance review. The right approach: scope the compliance infrastructure at the start, design the AI system to operate within it, and build the business case on what is achievable within that framework.
10–20% early-stage recovery improvement and 15–25% cost reduction per recovered dollar are achievable within the regulatory framework — scope the compliance infrastructure at the start, not after
Originally published on the CobuildX blog.
Top comments (0)