Quick answer: Bank Negara Malaysia’s fair treatment / debt-collection conduct expectations — together with the Consumer Credit Act and PDPA 2010 — still apply when an AI voice agent dials. Lenders remain accountable for calling windows, prohibited language, accurate balances, consent, and auditability. Done properly, AI can make those rules easier to enforce than a large human floor.
This is the compliance deep-dive in Suarify’s Malaysia collections cluster. Always verify against the current official documents on BNM, SC Malaysia, and PDP — this article is operational guidance, not legal advice.
Table of contents
- Core rules: BNM, Consumer Credit Act, PDPA
- Where collection calls go wrong
- Compliant-by-design AI calling
- Pre-deploy checklist
- FAQ
1. Core rules: BNM, Consumer Credit Act, PDPA
BNM market conduct / fair debt collection expectations
Cover how institutions and their agents may contact borrowers: professional conduct, privacy, restricted contact windows, and bans on harassment, intimidation, and misleading statements. Policy documents evolve — treat official BNM publications as source of truth.
Consumer Credit Act
Moves more non-bank consumer credit providers toward consistent conduct standards that previously felt uneven across lender types.
PDPA 2010
Governs collection, use, disclosure, and retention of personal data — including phone numbers, repayment history, and call recordings — with consent and security obligations.

Related nibblets: Calling hours · Email/notice before call · OTP phone verify · T&C updates
2. Where collection calls go wrong
Complaints to channels such as AKPK and financial ombudsman pathways often cluster around:
- Contact outside permitted windows
- Too many attempts in a short period (feels like harassment even without hostile words)
- Inaccurate balances quoted by different agents
- Threatening / misleading language (legal action not actually filed)
- Missing consent / wrong-party disclosure
These are usually process failures at scale — exactly where structured AI + CRM controls help.
3. Compliant-by-design AI calling

What good systems structurally prevent:
- Hour violations (dialer cannot start outside window)
- Balance drift (pull live LMS/CRM figures)
- Missing consent (block if flag absent)
- Script drift (versioned packs with audit history)
What AI does not replace: hardship judgment, complex restructure, and sensitive disputes — escalate those to humans.
Pillar: AI voice collections Malaysia
Commercial: Cost vs human agency
4. Pre-deploy checklist
Before going live with AI collections dials:
- [ ] System-enforced calling windows (not policy PDFs only)
- [ ] Consent check before every outbound attempt
- [ ] Optional: OTP-verified mobile on file; invalidate stale numbers
- [ ] Written notice / email-SMS path before aggressive call ladders (per your policy counsel)
- [ ] Recording + transcript with access controls and retention
- [ ] Script version control
- [ ] Live balance sync from LMS/CRM
- [ ] Distress / dispute auto-escalate
- [ ] Exportable audit trail for reviews
FAQ
Do BNM-style conduct rules apply to AI the same as humans?
Yes in substance: the lender remains responsible for how borrowers are contacted. The channel being AI does not create a compliance free pass.
Does AI increase compliance risk?
Not inherently. Poorly governed AI can — but well-governed AI often reduces hour, script, and consent failures versus unmanaged human dialing.
What if the borrower disputes the amount on an AI call?
Stop persuasion paths; log dispute; escalate to human / operations. Do not argue inaccurate figures.
Is consent required before AI collection calls?
Treat PDPA consent / notice obligations seriously. Keep verifiable records for the contact channels you use. See T&C consent updates.
Where do I read official sources?
Start at bnm.gov.my, sc.com.my, and pdp.gov.my, and have counsel map your license type to the exact policy documents in force.
