Following my previous blog on PCI DSS Compliance, I had some push-back on my claim that confusion persists in UK organisations regarding call recording for PCI compliance. So it’s only fair and reasonable that I should justify my observations and explain precisely why I believe that some organisations still aren’t getting it. Business Systems specialises in call recording technology implementations and with 25 years’ experience as an independent provider we have pretty much designed, installed and provided on-going service delivery and support for most solutions. In our work in the industry, we have had a steady stream of engagements where clients have mistakenly believed that their call recording solutions met their PCI obligations. The four most common mistakes we see are: Access to our recorder is password protected: while this may be good systems management practice, it is not PCI Data Security Standards compliant. It still does not satisfy Requirement 3.2 which stipulates that no personal identification information should be captured or retained. Our recordings are encrypted: while this was initially viewed as being OK, there has been further clarification on encryption which rules it out: “Sensitive Authentication Data cannot be stored whether encrypted or not”. We use audio masking to obscure the sensitive data: while this approach (it’s a bit like a TV Bleep machine) may seem reasonable, it is not PCI DSS compliant as the sensitive authentication data is still being retained. At collection our agents pause & resume the recording: again this fails to meet requirements and has been the subject of an explicit clarification. Sensitive authentication data must be removed from recordings… “with no manual intervention by your staff”. The fact that the pause has to be initiated manually by the agent means that it is liable to human error as the agent may simply forget to pause the recording. If you want to find out more on how Business Systems can help you ensure compliance, feel free to contact us: 0800 458 2988, [email protected]. Written by: Business Systems UK
Blog 19 August, 2026 WhatsApp Compliance in Financial Services WhatsApp compliance in financial services: why a ban is no longer enough For years, the standard answer to WhatsApp in regulated firms was simple: ban it. Write a policy prohibiting business communication on personal messaging apps, ask staff to sign it, and move on. That approach has now failed publicly, repeatedly and expensively. In 2024,
Blog 18 August, 2026 MiFID II Call Recording Requirements in 2026 MiFID II call recording in 2026: from sampled playback to full surveillance When the Markets in Financial Instruments Directive II came into force in 2018, most firms treated the recording obligation as a technology procurement exercise. Buy a recording platform, switch it on for the trading floor, tick the box. Nearly a decade on, recording
Blog 22 July, 2026 The Cost of Attrition: Why Workforce Engagement Management is a Self-Funding Strategy Contact centre attrition remains one of the most expensive challenges facing customer support leaders. CX Today reports annual turnover rates of 35-45% remain common across the industry, with each departure costing between £10,000 and £15,000 in recruitment, onboarding and lost productivity. For a 200-seat operation, that equates to roughly £700,000-£1.35 million in annual attrition costs
Blog 30 April, 2026 Customer Experience Tools: How to Choose (and Implement) the Right CX Platform for Your Business Choosing the right customer experience platform is a major decision for many businesses. The platform you choose shapes how customers interact with your business across every channel, determines what insights you can extract from those customer interactions, and influences whether or not your teams can deliver consistently excellent service. Yet many organisations approach this decision
Blog 16 April, 2026 Conversational AI in UK Contact Centres: Moving Beyond Basic Chatbots Many contact centres in the UK have implemented chatbot technology in some form or another, but with varying degrees of success. Recent industry research reveals that nearly 70% of customers become frustrated with chatbots and prefer speaking to human agents, and abandonment rates for basic chatbot interactions continue to remain stubbornly high. The problem isn’t
Blog 10 April, 2026 Proactive Customer Service: How Contact Centres Can Use Proactive AI to Anticipate Customer Needs The traditional model of customer service is almost entirely reactive: a customer discovers a problem, contacts your organisation, and waits for a solution. This approach places the burden squarely on the customer, requiring them to identify issues, navigate your contact channels, and often endure multiple interactions before their problem is solved. Proactive customer service powered
Blog 29 January, 2026 Microsoft Teams Recording Without the Risk: A Practical Guide for Regulated Organisations Microsoft Teams has become the backbone of collaboration across financial services, insurance, the public sector and other regulated industries. Trading conversations, client discussions, internal decisions and approvals are now happening daily across voice, video, chat and shared files. That shift brings opportunity, but it also introduces risk. For organisations operating under regulations such as FCA,
Blog 5 December, 2025 The clock is ticking: Why end-of-life recording systems are a critical compliance risk Outdated recording technology isn’t just an inconvenience, it’s a ticking time bomb for regulated firms. For financial services and other heavily regulated industries, end-of-life (EoL) voice recording systems can create dangerous blind spots. When vendors withdraw support, these unsupported platforms become vulnerable, exposing your firm to major compliance penalties under frameworks like MiFID II, FCA,