Getting client approval for Voice AI agents: Lessons from Prodigal

Articles,

Prodigal has supported AI-agent approvals across three of the largest debt buyers and several leading national lenders. Those reviews have given us a clear view of the questions compliance, legal, security, risk, and vendor-management teams ask before approving AI.

Before approving an AI agent, the client needs to understand its role, its limits, and the controls the firm will maintain after launch.

Scope and authority

The first step is defining exactly where the AI agent will operate.

What exact jobs will the AI agent handle, and what remains out of bounds?

The response should identify the approved portfolios, account stages, jurisdictions, channels, operating hours, payment options, and escalation paths. It should also state which activities remain restricted, such as providing legal advice, creating unapproved settlement terms, changing account information, or handling active litigation matters.

A clear scope helps the client evaluate the specific workflow under review and set a process for approving future expansion.

Which decisions are rule-based, which involve AI, and which require a human?

The firm should separate the agent’s ability to interpret a conversation from its authority to take action.

For example, the AI may recognize that a consumer is asking about a payment arrangement. The available terms should still come from approved client instructions, business rules, or the system of record. Situations requiring legal or operational judgment should move to a qualified employee.

What conditions force a transfer, stop, escalation, or manual review?

The firm should define the exact triggers, the action the agent takes, and the fallback when an employee is unavailable. This includes sensitive consumer statements, verification failures, unsupported requests, and technical issues.

Consumer and compliance controls

Clients will focus closely on conversations that create legal, regulatory, or reputational risk.

How does the agent identify itself and complete every required disclosure?

The response should explain when the disclosure is delivered, how the correct language is selected, how completion is recorded, and what happens when the consumer interrupts or asks a question midway through it.

The firm should also be able to show whether the disclosure was completed before the agent continued with the conversation.

How does the agent handle disputes, attorney representation, bankruptcy, hardship, cease-and-desist requests, and transfer requests?

Each scenario needs a defined workflow. The client should understand how the agent recognizes the situation, which activities stop, what information is recorded, and where the interaction is routed.

What prevents an incorrect settlement offer, payment plan, or account action?

The agent should retrieve terms from an approved source and validate them before communicating or executing an action; most checks should be handled deterministically. The approval documentation should demonstrate the control linking the conversation to the permitted action.

Data protection and client isolation

Collection law firms often manage multiple clients, portfolios, and sets of placement instructions within a single operation.

Where does our data go, who can access it, and is any of it used to train models?

The firm should provide a clear explanation through diagrams of data storage, subprocessors, access permissions, retention and deletion, and model training policies.
The client should be able to follow how its information moves through the system and who can interact with it.

How is each client, portfolio, and consumer interaction kept isolated?

The response should cover tenant boundaries, credentials, storage, session context, workflows, and business rules. Clients need confidence that their data and instructions cannot affect another creditor’s accounts.

Failure handling

AI agents depend on telephony, case-management systems, payment processors, and underlying models.

What happens when one of these systems fails?

For each dependency, the firm should explain which activity stops, what can safely continue, what the consumer hears, and whether the call transfers or ends.
It should also define whether any account or payment action can still occur and how the incident will be reviewed.

A documented failure process gives the client confidence that system issues will result in predictable, controlled behavior.

Testing and validation

Clients need evidence that the agent has been tested against the situations they will encounter on their accounts.

What testing proves the agent can handle real consumer conversations and difficult edge cases?

Testing should reflect the approved workflow and include interrupted disclosures, failed identity verification, background noise, language changes, disputes, attorney representation, bankruptcy, transfer failures, and unusual payment requests.

The firm and client should agree on acceptance criteria before launch, including which scenarios must pass and what level of human review is required.

Auditability and accountability

The law firm remains accountable for every interaction completed on a client’s accounts.

Can we inspect every call, decision, system action, and outcome?

The firm should be able to reconstruct an interaction using the recording, transcript, identity-verification status, disclosures, rules applied, information retrieved, transfer attempts, payment actions, final disposition, and any exceptions that occurred.

This level of detail supports complaint handling, client reviews, internal quality assurance, and regulatory inquiries.

Control after launch

Approval applies to a specific workflow, configuration, and set of business rules. Changes can introduce new risks and may require further review.

What changes require retesting, client notice, renewed approval, or rollback?

The change-control process should cover models, prompts, disclosures, payment options, integrations, transfer logic, portfolios, jurisdictions, and other business rules.

The firm should define who approves each category of change, how it will be tested, and how the previous version can be restored when necessary.

What law-firm executives should be able to answer

For every AI workflow, leadership should be able to explain:

What is the agent permitted to do?
What controls govern its actions?
What evidence can the firm provide to the client?

Clear answers make it easier for clients to evaluate the program, complete their internal reviews, and approve AI for use across their accounts.

Download Prodigal’s Client Approval Q&A Guide as PDF