Skip to content

Industries

Voice AI for Banks in Saudi Arabia: Use Cases and SAMA Rules

Voice AI use cases for Saudi banks and finance companies: card services, installments, collections and fraud, with SAMA outsourcing, cloud and risk controls.

Ranen teamUpdated 7 October 20267 min read

Banks and finance companies in Saudi Arabia receive a large share of routine calls that follow fixed rules: balance and card questions, installment dates, payment reminders and lost cards. A voice AI agent can complete many of these end to end, around the clock, in Arabic dialects and English, and hand the rest to staff with context. The constraint is not the technology. It is identity verification, approved limits, and the SAMA and PDPL obligations that come with putting a third party in the call path.

This article covers the use cases that fit, the controls each needs, and the regulatory questions your compliance and risk teams will ask. It is general information, not legal or regulatory advice. Regulatory references are drawn from the SAMA Rulebook and law firm summaries cited below; confirm the current versions that apply to your institution.

Short answer

Start with verified, rules-based requests such as balances, card services and installment information, then collections and card blocking within approved limits. Expect SAMA's outsourcing and cloud requirements to apply, keep data in the Kingdom unless SAMA approves otherwise, and give every action a limit, a log and a human route.

Use cases that fit a voice agent

Use caseWhat the agent doesWhen a person takes over
Balance and card servicesReads balances, recent transactions, card status, statement dates after verificationDisputed transactions, complaints
Installments and financingNext due date, amount, remaining installments, payment channelsRestructuring requests, hardship cases
CollectionsReminders and promises to pay within approved optionsAnything outside approved options, disputes, vulnerable customers
Fraud and card blockingBlocks the card immediately after verification, records the reportFraud claims, refunds, any doubt about identity
Identity verificationRuns the bank's verification steps before account-specific actionsFailed or inconsistent verification

Outbound calls fit the same pattern: payment reminders, collections follow-up and card delivery confirmations. Volume and handle-time assumptions for a business case are covered in our voice AI ROI worked example.

Identity verification comes first

No account-specific information should be read out before the caller passes the bank's existing verification policy. The agent should run the same steps a human agent would, for example matching the calling number to the registered mobile, then a one-time password or knowledge-based questions, and should stop and hand over after failures rather than retry indefinitely.

Voice biometrics and data minimization

If the bank uses voiceprints, treat them as sensitive data: DLA Piper lists biometric data among the PDPL's sensitive categories. Card and ID numbers spoken during verification should be masked in transcripts and recordings so they are not stored in clear.

Collections within approved limits

Collections is where a voice agent needs the tightest boundaries, because SAMA's Debt Collection Regulations and Procedures for Individual Customers set specific rules on phone contact. As published in the SAMA Rulebook, these include:

  • No more than ten attempts to contact a consumer by phone within 30 days.
  • Notifying the consumer at the beginning of the call that it is recorded.
  • Documenting all calls with retail consumers and keeping records for no less than ten years from the date of the call.
  • Not communicating with anyone other than the consumer or their guarantor.

The agent's dialer logic must therefore count attempts across all channels and agents, not only its own. Offers such as payment dates or installment options should come from a list the credit team has approved, with anything else handed to a collector.

Fraud reports and card blocking with handover

When a caller reports a lost card or a suspicious transaction, speed matters more than conversation. A sound flow is: verify, block the card, confirm the block, record the report, then transfer to the fraud team with a summary. The agent should not judge whether a claim is valid, promise refunds, or discuss investigation outcomes. If verification cannot be completed, it should transfer at once rather than leave the card active. See when a voice agent should hand over to a human for trigger design.

What SAMA and the PDPL mean for deployment

Outsourcing

SAMA's Rules on Outsourcing, issued in December 2019, apply to banks licensed in the Kingdom. They require a written no objection from SAMA for material outsourcing, with proposals submitted at least 15 business days in advance for domestic banks. Outsourcing is material when disruption would significantly affect operations or risk management, and the assessment considers customer data sharing. Contracts must cover service levels, audit and access rights, business continuity, confidentiality and security, sub-contracting and termination. Whether a voice agent is material depends on its scope; answering customer calls with account data is likely to be assessed carefully. Finance companies should check the SAMA instruments that apply to them.

Cloud and data location

Section 3.4.3 of SAMA's Cyber Security Framework states that, in principle, only cloud services located in Saudi Arabia should be used, and that use outside the Kingdom requires explicit SAMA approval. It also expects SAMA approval before using cloud services or signing with the provider, no secondary use of the institution's data, return and irreversible deletion of data on termination, and rights to review and audit the provider's cyber security.

Customer protection and complaints

SAMA's consumer protection principles include equitable treatment, with special attention to older customers and those with special needs, clear disclosure, protection of customer data, and effective complaints handling. The SAMACares framework sets a maximum of five working days to respond to complaints received directly. A voice agent should recognize complaints, log them in the bank's complaints system and never close them on its own.

Personal data

Under the PDPL Implementing Regulations, explicit consent is required for credit data and automated decision-making, and a data protection impact assessment is expected for new technologies and large-scale processing, according to Clyde & Co. DLA Piper notes that banking transfers outside the Kingdom need SAMA approval. Our guide to PDPL and call recordings covers notice, retention and breach duties.

Risk controls to put in place

  1. Per-action permissions: which intents the agent may complete, which need human approval, which are read-only.
  2. Monetary and offer limits, enforced by the system, not only by the prompt.
  3. Verification gates before any account-specific response, with lockout after failures.
  4. A request for a person honored at any point in the call.
  5. Complete logs of what the agent heard, said and did, retained to sector requirements.
  6. Masking of card and ID numbers in transcripts and recordings.
  7. In-Kingdom hosting, customer-managed keys and an exit plan with verified deletion.
  8. Pre-launch testing on real call recordings, then a pilot on one line with daily review.

Integration options and their effect on recording and routing are compared in call forwarding vs SIP trunk vs PBX integration.

How Ranen handles this

Ranen sets permissions and limits per action, such as a refund ceiling, and supports human approval for sensitive actions. Every word and action is logged and reviewable, with a summary, intent and outcome for every call. Calls, recordings and transcripts are hosted in data centers inside Saudi Arabia, with TLS 1.3 in transit, AES-256 at rest and customer-managed keys for enterprise clients, and card and ID numbers are masked automatically. Ranen transfers to staff at once with the caller's intent and the steps already taken. Enterprise plans are tailored to integrations, hosting and compliance needs; see pricing or request a demo on your own recordings.

Frequently asked questions

Can Saudi banks use AI voice agents for customer service?

Nothing in the sources reviewed prohibits it, but a bank will need to assess the arrangement under SAMA's outsourcing rules, the cloud requirements in its Cyber Security Framework and the PDPL. Material outsourcing requires a written SAMA no objection.

Does banking customer data have to stay in Saudi Arabia?

SAMA's Cyber Security Framework states that, in principle, cloud services should be located in Saudi Arabia, and use outside the Kingdom requires explicit SAMA approval.

Can an AI agent handle debt collection calls?

It can make reminder and follow-up calls within approved options, provided it respects SAMA's collection rules, including the ten-attempt limit in 30 days and the recording notice at the start of the call.

What happens if a customer reports fraud to the voice agent?

After verification the agent blocks the card, confirms the block and transfers to the fraud team with a summary. It does not assess the claim or promise refunds.

Sources

  1. SAMA Rulebook: Rules on Outsourcing
  2. SAMA Rulebook: Cyber Security Framework, 3.4.3 Cloud Computing
  3. SAMA Rulebook: Consumer Protection and Financial Conduct
  4. SAMA Rulebook: SAMACares complaint handling periods
  5. SAMA Rulebook: Debt Collection Regulations and Procedures for Individual Customers
  6. Clyde & Co: Saudi Arabia issues Implementing Regulations to the Personal Data Protection Law
  7. DLA Piper: Data Protection in Saudi Arabia

Hear Ranen on your own calls

Book a demo and we run Ranen on a sample of your call recordings, then size the plan with you.

Related articles

All articles