high-risk calls for qa review

How QA Managers Can Prioritise High-Risk Calls for QA Review

TL;DR: For QA managers, the challenge is rarely finding more calls to review. It is deciding which calls deserve limited reviewer capacity first.

A risk-based QA process should:

  1. define the customer and compliance risks that matter
  2. assess interactions consistently against those criteria
  3. assign severity based on potential customer impact
  4. move the highest-risk calls to the top of the QA queue
  5. route each case to the appropriate reviewer or team
  6. use QA findings to identify wider patterns across agents, products and customer journeys

Traditional sampling can tell you what happened within the calls selected for review. Risk-based QA helps determine which calls should be selected in the first place.

See what 2% QA coverage can miss →

Why QA managers need a better way to prioritise high-risk calls

Most QA teams operate with a simple constraint:

There are far more customer interactions than reviewers available to assess them.

A team might handle tens of thousands of calls each month while having capacity to manually review only a fraction.

Traditional QA processes solve the capacity problem by sampling.

That can be useful for measuring general performance. It is much less effective when the objective is to identify specific interactions involving customer harm, vulnerability, complaints or serious control failures.

If calls are selected before anyone knows what happened within them, high-risk interactions can remain outside the review population entirely.

For a QA Manager or Head of Quality Assurance, this changes the central question from:

How many calls can the team review?

to:

Which calls should reach the team first?

Risk-based QA is designed to answer that second question.

What counts as a high-risk call for QA review?

A high-risk call contains signals that increase the likelihood of customer harm, regulatory exposure, a control failure or a poor customer outcome.

There is no universal list that works for every financial services firm.

A collections team will monitor different risks from an insurer, lender or retail bank. The QA framework should reflect the firm’s customers, products, policies and regulatory obligations.

Most frameworks will still contain several common categories.

Customer vulnerability

Interactions involving potential vulnerability should frequently receive higher QA priority.

Indicators might relate to:

  • financial difficulty
  • bereavement
  • health circumstances
  • low financial resilience
  • difficulty understanding information
  • life events affecting the customer’s ability to make decisions

The FCA expects firms to monitor whether customers with characteristics of vulnerability are receiving appropriate outcomes and to investigate differences between customer groups.

Read the FCA’s work on outcomes monitoring and vulnerable customers →

Complaints and dissatisfaction

Formal complaints are generally straightforward to identify.

Early dissatisfaction can be much less obvious.

Examples include:

“I’ve already explained this three times.”

“Nobody told me that would happen.”

“I don’t think I’ve been treated fairly.”

A QA process that can surface these signals earlier gives reviewers an opportunity to investigate before a problem develops further.

The FCA has also highlighted the importance of granular complaints data, effective escalation and using complaint insights to identify root causes.

Read the FCA’s review of complaints and root cause analysis →

Potential customer harm

Some calls need faster review because the consequences of an error are greater.

Examples could include:

  • an affordability assessment in consumer credit
  • a collections conversation with someone in serious financial difficulty
  • important information a customer appears to have misunderstood
  • disputed insurance cover
  • inappropriate pressure or conduct
  • an incorrect statement affecting a customer’s decision

QA prioritisation should therefore account for potential impact, rather than treating every failed criterion equally.

Material process or control failures

QA teams also need to identify cases where required processes have not been followed.

Depending on the firm, that could include:

  • missing disclosures
  • incomplete checks
  • incorrect information
  • failure to recognise vulnerability
  • poor complaint handling
  • failure to follow agreed support processes

The clearer these criteria are, the easier they become to apply consistently across interactions.

A practical risk hierarchy for QA managers

Not every flagged interaction should enter the queue at the same priority.

A simple hierarchy can help QA teams connect the risk identified with the action required.

PriorityExample signalQA responseLikely owner
CriticalSerious potential customer harm or urgent vulnerabilityImmediate investigation and escalationSenior QA / Compliance
HighComplaint, significant vulnerability, material control failurePrioritised human review within defined SLAQA / Compliance
MediumRepeated dissatisfaction, possible process failure, unclear customer understandingReview after critical and high-risk casesQA reviewer
LowMinor deviation with limited customer impactRoutine QA or coaching workflowQA / Team leader

The exact labels matter less than having clear rules behind them.

QA managers should be able to explain:

  • why one issue receives greater priority than another
  • what happens when multiple risks appear in one call
  • when a reviewer must escalate a case
  • how quickly each priority level should be reviewed
  • who owns the next action

This turns a risk score into an operational QA process.

How to prioritise high-risk calls for QA review

1. Start with your existing QA framework

Prioritisation should begin with the risks the firm already cares about.

Review your:

  • QA scorecards
  • compliance monitoring framework
  • Consumer Duty monitoring
  • complaints criteria
  • vulnerability policies
  • conduct controls
  • internal escalation rules

Identify which criteria should affect the priority of a customer interaction.

Avoid a broad “high risk” label that reviewers interpret differently.

Define exactly what needs to be found.

2. Separate severity from simple pass/fail scoring

Traditional QA scorecards can treat several failures similarly even when their potential consequences are very different.

For prioritisation, QA managers need an additional dimension:

How serious is this if the assessment is correct?

A minor process deviation may require coaching.

A vulnerability issue associated with potential customer harm may require immediate escalation.

The scoring model should reflect that difference.

3. Define what happens when risks overlap

Risk rarely appears neatly in isolation.

One interaction might contain:

  • financial difficulty
  • dissatisfaction
  • a potential vulnerability
  • a missed process step

Each indicator individually might receive a medium score.

Together, they could justify high-priority review.

QA frameworks therefore need rules for combinations of risk signals, rather than assessing every criterion independently.

4. Assess interactions before building the review queue

This is the point where manual QA reaches a practical limit.

To prioritise calls according to risk, the firm first needs visibility into what happened within those calls.

Doing that manually across thousands of interactions recreates the original capacity problem.

Automated QA can assess a much larger interaction population against predefined criteria and identify potential risk signals before human review begins.

The QA team then receives a queue based on the content of the interaction rather than random selection.

5. Give reviewers a risk-ranked queue

The output needs to be usable by the people doing the work.

A reviewer should be able to open the QA queue and immediately understand:

Critical → High → Medium → Low

They should also see why each interaction received that priority.

That supporting evidence might include:

  • the risk criterion triggered
  • the relevant part of the conversation
  • the initial assessment
  • associated customer or journey information
  • previous related flags

A score without context simply creates another investigation step.

6. Route each case to the right person

Not every high-risk interaction belongs with the same reviewer.

A complaint may need escalation to complaints handling.

A serious vulnerability issue may require a specialist team.

A coaching issue may belong with an agent’s manager.

Effective QA prioritisation therefore combines:

risk + urgency + ownership

The queue should help determine what happens next as well as what gets reviewed first.

7. Keep human judgement within the process

Automated QA can identify and prioritise potential risk at scale.

Human reviewers remain responsible for understanding context, validating findings and determining the appropriate response.

Reviewers should be able to:

  • inspect the supporting evidence
  • confirm an assessment
  • override it where necessary
  • add context
  • document the final decision
  • record subsequent action

This also gives the firm an auditable record of how the risk was handled.

Why random QA sampling can miss the calls that matter most

Random sampling answers a useful question:

What does a representative selection of our interactions look like?

It does not deliberately find the interactions with the greatest potential risk.

A routine enquiry and an interaction containing a serious vulnerability disclosure can have exactly the same probability of entering a random sample.

That creates an obvious limitation for teams using QA to identify harm.

Across 1.38 million conversations assessed by Detect, Aveni identified vulnerability signals, complaints, dissatisfaction and other compliance risks throughout the wider interaction population.

At a hypothetical 2% manual sampling rate, 182,408 high-risk conversations would have remained outside human review.

The alternative is to reverse the process.

Sampling approach

Select calls → review calls → discover whether risk exists.

Risk-based approach

Assess interactions → identify potential risk → prioritise human review.

Random sampling can still provide useful benchmarking and representative insight. Risk-based QA gives teams an additional way to make sure limited reviewer capacity is directed towards interactions showing the strongest risk signals.

Read: The 182,408 high-risk conversations nobody reviewed →

What QA managers should measure after introducing risk-based prioritisation

Moving to risk-based QA also changes which metrics become useful.

Rather than focusing primarily on the number of reviews completed, QA leaders can track:

Coverage

What proportion of customer interactions are being assessed for potential risk?

High-risk cases identified

How many critical, high and medium-risk interactions are being surfaced?

Time to review

How quickly does a high-risk interaction reach a human reviewer?

Time to escalation

How quickly are serious cases routed to the appropriate owner?

Reviewer confirmation rate

How often do human reviewers agree with the automated assessment?

Overrides

Where are reviewers changing assessments, and why?

Recurring risks

Are particular issues concentrated around:

  • an agent
  • a team
  • a product
  • a process
  • a customer group
  • a specific stage of the journey

These metrics help the QA function move from reviewing individual calls to understanding where risk is accumulating across the operation.

How QA prioritisation supports Compliance Monitoring and Consumer Duty

Although QA managers are likely to operate the process day to day, the resulting data has wider value.

For Compliance Monitoring teams, risk-based QA provides more structured evidence about where potential conduct and control issues are appearing.

For Consumer Duty and Customer Outcomes teams, the same information can help identify:

  • customer groups receiving poorer outcomes
  • recurring vulnerability issues
  • complaint themes
  • journeys producing unusual levels of dissatisfaction
  • weaknesses in customer understanding
  • repeated failures after remediation

The FCA’s outcomes-monitoring guidance emphasises using information to identify risks, understand poor outcomes, take action and assess whether that action improved the result.

Read the FCA’s outcomes monitoring good practice →

This gives the QA team a more direct role in the wider monitoring framework.

QA findings become evidence that Compliance and Consumer Duty teams can aggregate, investigate and act on.

Explore Aveni’s approach to Consumer Duty monitoring →

How Detect helps QA teams prioritise high-risk calls

Aveni Detect is designed to help financial services firms apply QA and compliance assessments across customer interactions at scale.

Firms can configure assessments around their own QA frameworks and monitor for indicators including vulnerability, complaints and other conduct or compliance risks.

Detect can then surface higher-risk interactions for human investigation.

This changes where reviewer time is spent.

Instead of manually searching for calls that warrant attention, QA teams can focus on:

  • validating risk
  • understanding context
  • escalating significant cases
  • identifying root causes
  • coaching agents
  • analysing wider patterns

At Octopus Money, Detect increased QA coverage from 15% to 100% of adviser and coach conversations, with red-flag cases surfaced for human review.

See how Octopus Money increased QA coverage from 15% to 100% →

Give your QA team a better starting point

For QA managers dealing with high call volumes and limited review capacity, reviewing more interactions manually is rarely a sustainable answer.

The more useful objective is to make sure human reviewers begin with the interactions most likely to require their judgement.

Define the risks.

Assess interactions consistently.

Prioritise according to severity.

Put the right cases in front of the right people.

Then use what QA finds to improve the wider operation.

See how Detect helps QA teams identify and prioritise high-risk customer interactions →

FAQs: high-risk calls for QA review

What is a high-risk call in QA?

A high-risk call is a customer interaction containing indicators of potential customer harm, vulnerability, complaints, conduct issues, control failures or other material risks defined within the firm’s QA framework.

How should QA managers prioritise high-risk calls for review?

QA managers should define relevant risk indicators, assign severity levels, assess interactions consistently and rank calls according to potential customer impact. Critical and high-risk interactions should reach human reviewers ahead of routine cases.

What is risk-based QA?

Risk-based QA is a quality assurance approach that directs review resource towards interactions showing greater potential risk. Calls are prioritised using defined risk criteria rather than relying entirely on random selection.

What should QA managers look for in customer calls?

Common indicators include vulnerability, complaints, dissatisfaction, financial difficulty, potential customer harm, conduct concerns and material process failures. The exact criteria should reflect the firm’s products, customers, policies and regulatory obligations.

Does the FCA require firms to review 100% of calls?

No. The FCA does not prescribe a fixed percentage of customer calls that firms must manually review. Firms are expected to use monitoring that helps them identify poor outcomes and emerging risks, take appropriate action and assess whether that action has worked.

Read the FCA’s outcomes monitoring guidance →

Is random QA sampling still useful?

Yes. Random sampling can provide a representative view of general performance. Risk-based QA serves a different purpose by deliberately surfacing interactions that show stronger indicators of potential harm or compliance risk.

Can AI prioritise calls for QA reviewers?

Yes. AI can assess customer interactions against predefined QA criteria, identify relevant risk signals and rank cases for human review. Reviewers can then validate findings, investigate context and determine the appropriate response.

How does risk-based QA help a Head of Compliance Monitoring?

Risk-based QA gives Compliance Monitoring teams greater visibility into where potential risk is occurring across customer interactions. It can help identify recurring conduct issues, control failures, vulnerability trends and patterns that warrant thematic investigation.

How does QA prioritisation support Consumer Duty?

QA prioritisation can help firms identify interactions associated with poorer customer outcomes, analyse recurring patterns and route serious cases for investigation. The resulting data can also support wider Consumer Duty outcomes monitoring and remediation.

What is the main benefit of prioritising QA by risk?

The main benefit is better use of limited reviewer capacity. QA teams spend less time finding relevant calls and more time investigating the interactions most likely to require human judgement.

Share with your community!

In this article

Related Articles

Join our newsletter

Be the first to hear about new features, releases, and best-practice guides.

Aveni AI Logo