Voice phishing simulations in the United Kingdom
The United Kingdom is one of the few countries where your own team rents the number once the company is cleared, and where the automated-calling rule everyone expects to stop a voice phishing simulation was written for direct marketing and does not reach an authorised test of your own staff. One question here is genuinely unsettled, and this page tells you which one rather than guessing at it.
Phone numbers
Supplied by Callstrike
Local and mobile numbers in the United Kingdom, after a one-time approval.
Running a simulation
Permitted
Rests on a documented assessment and a notice your people can actually find.
Consent
Notice, not permission
Asking fails the standard and ends the test in the same breath.
Getting a phone number in the United Kingdom
One approval per country, completed in the console.
Self-provisioned after approval
Your company files its regulatory details once for this country. Once that is approved, your team provisions numbers directly from available inventory. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
Your company is cleared once for the country, and after that your own team searches the inventory and rents United Kingdom numbers without anyone provisioning on your behalf. Only a handful of countries in this portal work that way. The clearance is read by a person rather than a machine, so start it in the month before the campaign rather than in the week of it.
The detail that sends a clearance back is the address. It has to be a real place inside the United Kingdom rather than a post box, and it has to be the address your registration shows, so a virtual office taken out for the campaign is the likeliest reason to be asked again. The number you end up holding is also the number the pretext should come from, because the regulator's caller identification rules require the number you present to be one you have authority to use.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03Search the inventory and rent your numberYour team
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Business addressMust be within United Kingdom; a PO Box is not acceptable. | Business address |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in the United Kingdom?
The position in short, before your counsel reads the detail below.
Yes. Nothing in United Kingdom law prohibits testing your own workforce against social engineering, and the rule most people expect to stop it does not reach the exercise. The restriction on automated calling systems is written, in its own words, for direct marketing purposes. An authorised security test against your own staff markets nothing, so the restriction is not engaged whichever voice is speaking. That is a statement about what the rule covers rather than a route around it.
What you do owe is a written basis, and it is legitimate interests rather than anything you ask your people to agree to. Set out the interest you are pursuing, why the exercise is necessary to pursue it, and why it does not override the rights of the people being tested. Because this is systematic monitoring of employees, budget for an impact assessment as well, and treat it as the place where you decide whether the monitoring is proportionate rather than as a document you produce afterwards.
Recording the calls is the one part of the United Kingdom answer that is genuinely open, and you should be suspicious of anyone who hands you a confident recipe for it. The regulations the whole industry cites were made under a section of an earlier statute that has since been repealed, and the page serving them shows nothing to say so. Take that question to your own counsel. Or design the exercise so that it never arises, which is what most programmes here quietly end up doing.
There is no standing body you have to clear this with. The United Kingdom has no equivalent of German co-determination, and its consultation machinery applies from fifty employees but only starts once at least a tenth of the workforce asks for it. Where you recognise a union, or already hold an information and consultation agreement, brief them under it. That is worth doing for the goodwill, not because a veto is waiting.
What your company needs to do
6 items, in the order you will need them.
- Write the legitimate interest assessment before the first callThree elements, and none of them is boilerplate: the interest, the necessity of this particular method to serve it, and the balance against the rights of the people you are calling. An assessment written after a complaint is evidence of nothing except that a complaint arrived.
- Do the impact assessment early enough to change the designSystematic monitoring of employees is the trigger, and the point of doing it first is that it can still alter what you build. If the assessment cannot influence the scope, the retention or who sees the results, it is a filing exercise rather than an assessment.
- Publish a notice at the level of the programme, not the callTell people that security testing happens, what kinds, what is recorded, how long it is kept, and what will never happen to them as a result. That last clause is the one that changes behaviour internally, and it is the one most notices leave out.
- Present a number you have authority to useUnited Kingdom-specificThe rule is that a presented caller identity has to be a valid, dialable number that uniquely identifies you and that you were allocated or given permission to use, and never a premium rate or revenue sharing number. The current guidance is recent enough that an internal playbook written before it is worth rereading.
- Settle the recording question before you switch audio onUnited Kingdom-specificDo not let a supplier settle it for you. Decide with your own counsel which route to lawful interception your telephony actually sits on, or run the programme without audio. Either is a defensible position; assuming the widely repeated answer still holds is not.
- If you are a regulated firm, map this onto operational resilienceIdentify the important business services a social engineering call could reach, and put a people-shaped scenario into the severe but plausible set. No United Kingdom regulator requires this specific technique, so cite what the rules say rather than what a supplier says they say.
The controls that do the work
How Callstrike is configured, and which provision in the United Kingdom each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
This is what turns the necessity and proportionality argument from a debate into a fact. The assessment and the impact assessment both ask what personal data the exercise processes and whether a less intrusive method would do. A programme that ends the call the moment an employee starts to give up a credential never processes the credential at all, so the answer is that the most sensitive thing in the scenario is absent rather than handled carefully. It also shrinks the unsettled recording question, because there is materially less on the recording to argue about.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
The regulator's monitoring expectations are about proportionality and about what the monitoring does to the people subject to it. A call that ends with a second voice explaining what just happened, followed by written vishing training in the inbox while the moment is still sharp, is a materially different exercise from one that ends with a caught employee and silence until a report circulates. It is also the strongest thing you can put in front of a union or an information and consultation forum.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Your basis is legitimate interests, so this is not the permission you rely on. What it produces is the evidence half of the transparency duty: a dated record of what your workforce was told and when, or a hashed copy of the policy or handbook clause you are relying on together with a signed attestation of the scope it covers. Both exist before the campaign rather than being reconstructed after a subject access request arrives.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
Where the recording question or a nervous stakeholder makes telephony unattractive, this is the route that still teaches. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, and a call a person initiates in their own browser is not a telephone call at all, so the automated calling rules and the caller identification conditions have nothing to attach to.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.