Quick answer: Before AI or human collections dial, verify the mobile number via OTP (or equivalent strong check) at onboarding and on change-of-number events. If OTP fails or the number is recycled, mark the account contact invalid and stop voice attempts until re-verified. This cuts wrong-party calls, PDPA leakage risk, and “you called my relative” complaints — and improves connect rate on real borrowers.
Fits with T&C consent and BNM & AI compliance.
Why collections dialers burn trust without OTP
- Malaysian mobiles get recycled; yesterday’s borrower is today’s stranger
- Friends/family pick up → accidental debt disclosure risk
- Agents “confirm” weakly (“is this Ahmad?”) without proof of possession

Recommended policy
| Event | Action |
|---|---|
| Onboarding | OTP required before disbursement / first servicing call |
| Number change in app | Re-OTP immediately; old number invalidated |
| Wrong-party outcome on call | Invalidate; require re-OTP or branch verification |
| N consecutive no-connect + carrier recycle signals | Soft-invalidate; trigger digital re-verify |
| Collections dial eligibility | Require phone_otp_verified_at within policy max age |
Pair with right-party contact (RPC)
OTP proves number possession. RPC on the call still confirms you’re speaking to the right person before discussing debt details. See delinquency journey / RPC.
Suarify + CRM pattern
- CRM exposes
phone_verified+verified_at - Suarify outbound campaign filters only verified phones
- Call outcomes
wrong_party/number_invalidwrite back and flip flags - Digital channel sends re-verify link before next dial wave
FAQ
Is OTP mandatory under Malaysian law for collection calls?
Not as a universal statute slogan — but it is strong PDPA risk control and operational best practice. Many lenders already OTP for login; extend it to the dialable MSISDN.
What about landlines?
Use alternate verification (account portal confirmation, branch, video KYC). Don’t pretend OTP covers PSTN.
Does verified phone mean we can discuss the full debt immediately?
No. Still run RPC / identity prompts per your script and privacy rules.
Also: Email before call · Calling hours · Pillar
