Callstrike
Compliance

Voice phishing simulations in the United Kingdom

Phone numbers in the United KingdomSelf-provisioned after approval

The United Kingdom is one of the few countries where your own team rents the number once the company is cleared, and where the automated-calling rule everyone expects to stop a voice phishing simulation was written for direct marketing and does not reach an authorised test of your own staff. One question here is genuinely unsettled, and this page tells you which one rather than guessing at it.

Phone numbers

Supplied by Callstrike

Local and mobile numbers in the United Kingdom, after a one-time approval.

Running a simulation

Permitted

Rests on a documented assessment and a notice your people can actually find.

Consent

Notice, not permission

Asking fails the standard and ends the test in the same breath.

Getting a phone number in the United Kingdom

One approval per country, completed in the console.

Self-provisioned after approval

Your company files its regulatory details once for this country. Once that is approved, your team provisions numbers directly from available inventory. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Your company is cleared once for the country, and after that your own team searches the inventory and rents United Kingdom numbers without anyone provisioning on your behalf. Only a handful of countries in this portal work that way. The clearance is read by a person rather than a machine, so start it in the month before the campaign rather than in the week of it.

The detail that sends a clearance back is the address. It has to be a real place inside the United Kingdom rather than a post box, and it has to be the address your registration shows, so a virtual office taken out for the campaign is the likeliest reason to be asked again. The number you end up holding is also the number the pretext should come from, because the regulator's caller identification rules require the number you present to be one you have authority to use.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03Search the inventory and rent your numberYour team
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Business addressMust be within United Kingdom; a PO Box is not acceptable.Business address

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in the United Kingdom?

The position in short, before your counsel reads the detail below.

Yes. Nothing in United Kingdom law prohibits testing your own workforce against social engineering, and the rule most people expect to stop it does not reach the exercise. The restriction on automated calling systems is written, in its own words, for direct marketing purposes. An authorised security test against your own staff markets nothing, so the restriction is not engaged whichever voice is speaking. That is a statement about what the rule covers rather than a route around it.

What you do owe is a written basis, and it is legitimate interests rather than anything you ask your people to agree to. Set out the interest you are pursuing, why the exercise is necessary to pursue it, and why it does not override the rights of the people being tested. Because this is systematic monitoring of employees, budget for an impact assessment as well, and treat it as the place where you decide whether the monitoring is proportionate rather than as a document you produce afterwards.

Recording the calls is the one part of the United Kingdom answer that is genuinely open, and you should be suspicious of anyone who hands you a confident recipe for it. The regulations the whole industry cites were made under a section of an earlier statute that has since been repealed, and the page serving them shows nothing to say so. Take that question to your own counsel. Or design the exercise so that it never arises, which is what most programmes here quietly end up doing.

There is no standing body you have to clear this with. The United Kingdom has no equivalent of German co-determination, and its consultation machinery applies from fifty employees but only starts once at least a tenth of the workforce asks for it. Where you recognise a union, or already hold an information and consultation agreement, brief them under it. That is worth doing for the goodwill, not because a veto is waiting.

What your company needs to do

6 items, in the order you will need them.

  • Write the legitimate interest assessment before the first callThree elements, and none of them is boilerplate: the interest, the necessity of this particular method to serve it, and the balance against the rights of the people you are calling. An assessment written after a complaint is evidence of nothing except that a complaint arrived.
  • Do the impact assessment early enough to change the designSystematic monitoring of employees is the trigger, and the point of doing it first is that it can still alter what you build. If the assessment cannot influence the scope, the retention or who sees the results, it is a filing exercise rather than an assessment.
  • Publish a notice at the level of the programme, not the callTell people that security testing happens, what kinds, what is recorded, how long it is kept, and what will never happen to them as a result. That last clause is the one that changes behaviour internally, and it is the one most notices leave out.
  • Present a number you have authority to useUnited Kingdom-specificThe rule is that a presented caller identity has to be a valid, dialable number that uniquely identifies you and that you were allocated or given permission to use, and never a premium rate or revenue sharing number. The current guidance is recent enough that an internal playbook written before it is worth rereading.
  • Settle the recording question before you switch audio onUnited Kingdom-specificDo not let a supplier settle it for you. Decide with your own counsel which route to lawful interception your telephony actually sits on, or run the programme without audio. Either is a defensible position; assuming the widely repeated answer still holds is not.
  • If you are a regulated firm, map this onto operational resilienceIdentify the important business services a social engineering call could reach, and put a people-shaped scenario into the severe but plausible set. No United Kingdom regulator requires this specific technique, so cite what the rules say rather than what a supplier says they say.

The controls that do the work

How Callstrike is configured, and which provision in the United Kingdom each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

This is what turns the necessity and proportionality argument from a debate into a fact. The assessment and the impact assessment both ask what personal data the exercise processes and whether a less intrusive method would do. A programme that ends the call the moment an employee starts to give up a credential never processes the credential at all, so the answer is that the most sensitive thing in the scenario is absent rather than handled carefully. It also shrinks the unsettled recording question, because there is materially less on the recording to argue about.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The regulator's monitoring expectations are about proportionality and about what the monitoring does to the people subject to it. A call that ends with a second voice explaining what just happened, followed by written vishing training in the inbox while the moment is still sharp, is a materially different exercise from one that ends with a caught employee and silence until a report circulates. It is also the strongest thing you can put in front of a union or an information and consultation forum.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Your basis is legitimate interests, so this is not the permission you rely on. What it produces is the evidence half of the transparency duty: a dated record of what your workforce was told and when, or a hashed copy of the policy or handbook clause you are relying on together with a signed attestation of the scope it covers. Both exist before the campaign rather than being reconstructed after a subject access request arrives.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

Where the recording question or a nervous stakeholder makes telephony unattractive, this is the route that still teaches. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, and a call a person initiates in their own browser is not a telephone call at all, so the automated calling rules and the caller identification conditions have nothing to attach to.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

Can you run one, and on what legal basis

You can. Testing your own workforce against social engineering is a recognised security activity, and nothing in UK law prohibits it. The question is not whether you may, it is which lawful basis you are relying on, because you are processing personal data about identifiable employees and recording how they behaved under pressure.

The answer is legitimate interests under Article 6(1)(f) of the UK GDPR, and it has to be written down. A Legitimate Interest Assessment sets out the interest you are pursuing, why the simulation is necessary to pursue it, and why your interest is not overridden by the rights of the people being tested. Because this is systematic monitoring of employees, you should also expect to need a data protection impact assessment under Article 35, and the ICO's guidance is explicit that a DPIA is where you work out whether the monitoring is proportionate before you do it rather than after.

Consent is the wrong basis and reaching for it causes two problems at once. In an employment relationship it is not freely given, because the person cannot realistically refuse their employer without cost, so it fails the standard the UK GDPR sets. And asking destroys the thing you are measuring: a person who knows a simulated attack is coming is no longer being tested. Competitor pages that tell you to collect employee consent are giving you a basis that does not hold and an exercise that does not work.

What replaces it is transparency at the programme level rather than at the call level. Tell people that security testing happens, what kinds, what is recorded, how long it is kept and what will never happen to them as a result. The ICO's monitoring guidance is the standard to write against, and it applies to anyone who performs work for you regardless of the contract they are on.

The United Kingdom has no works council veto of the kind Germany has under the Betriebsverfassungsgesetz. The instrument here is the Information and Consultation of Employees Regulations 2004, which apply to undertakings with at least 50 employees but are request-triggered rather than automatic: a valid request needs at least 10 per cent of employees, subject to a floor of 15 and a ceiling of 2,500. So in most UK organisations there is no standing body you must clear this with. If you recognise a trade union, or you already have an information and consultation agreement, consult under it.

Recording the call, and why we will not give you a recipe

This is the part of UK practice where the confident answer everybody publishes is probably out of date, so read this section differently from the others.

The standard citation for recording business calls in the UK is the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000, which allow a business to intercept on its own system provided it has made all reasonable efforts to tell users of that system that interception may happen. That is a notification duty rather than a requirement to get every party's agreement, and it is why the United Kingdom is usually described as more permissive here than Germany.

Those Regulations were made under section 4(2) of the Regulation of Investigatory Powers Act 2000. That section was repealed, omitted by the Investigatory Powers Act 2016 in a repeal commenced in stages through 2018. The Regulations are still displayed on legislation.gov.uk, but only in their original form, so the page carries no revocation banner and reading it does not tell you the enabling power underneath has gone.

What governs interception now is the Investigatory Powers Act 2016. Section 3 creates the offence, and section 6 defines lawful authority exhaustively, in the words "if, and only if", by warrant, by one of sections 44 to 52, or by the routes for stored communications. Section 44 turns on the agreement of both parties, or of one party plus separately authorised surveillance. Section 3 itself does not bite where the person intercepting controls the private system in question or has the consent of whoever does.

We are not going to tell you which of those routes covers your recording, because that turns on facts about your telephony and your organisation that we do not have, and because the widely repeated answer rests on a power that no longer exists. Take this specific question to your own counsel, and treat any supplier who hands you a confident one-line answer with suspicion. What you can do regardless of the route is meet the ICO's expectations on monitoring: tell people recording happens, keep recordings only as long as the training purpose needs, and restrict who can listen.

An autonomous AI voice against a live operator

The rule people expect to bite here is regulation 19 of the Privacy and Electronic Communications Regulations 2003, which restricts automated calling systems. Read the words: it prohibits transmitting "communications comprising recorded matter for direct marketing purposes by means of an automated calling system" without the subscriber's prior agreement. The prohibition is written for direct marketing. An authorised security test against your own staff is not direct marketing, so regulation 19 is not the obstacle it is usually assumed to be, whichever voice mode you choose.

That is a genuine difference between the United Kingdom and the United States, and it is worth understanding rather than generalising from. In the US the Federal Communications Commission ruled in February 2024 that an AI-generated voice is an artificial or prerecorded voice for the purposes of the Telephone Consumer Protection Act, and the artificial-voice restriction there is not limited to marketing. In the same ruling the Commission declined to make any carve out of technologies that purport to provide the equivalent of a live agent.

So be careful with the claim that putting a human in the loop makes the automated calling rules go away. In the United Kingdom those rules were not engaged for this use in the first place, because of the direct marketing limit above. In the United States a live operator is a live call while a fully autonomous AI voice engages the artificial-voice restriction, which is a real reduction in exposure and is not an exemption. Anyone selling you human-in-the-loop as a way past a rule is describing something the FCC has already addressed in writing.

The choice between the two modes is therefore an operational one here rather than a legal one. An autonomous voice scales across a whole workforce. A live operator, whose own voice is transformed in real time, holds a conversation that adapts, which is what a test of a senior target or a payment process actually needs. Both remain subject to everything in the sections above and below.

The caller ID you present, and why it has to be yours

The constraint that actually bites on a UK simulation is not what you say, it is what number you say it from. Ofcom's General Condition C6 and its accompanying CLI guidance require that, where calling line identification data is provided, it is a valid, dialable number that uniquely identifies the caller and that the caller has been given authority to use, whether because it was allocated to them or because the holder gave them permission. It must not be a premium rate or revenue sharing number.

In practice that rules out the thing an untrained tester reaches for first, which is presenting a number belonging to somebody else because it makes the pretext more convincing. A simulation that spoofs an arbitrary UK number is not a more realistic test, it is a call your originating provider is responsible for getting right. The current guidance was published in July 2024 and applies from January 2025, which is recent enough that older internal playbooks are worth rereading.

This is the reason the number matters as much as the script. Running the simulation from a UK number your organisation holds gives you a caller ID you are entitled to present, a number that survives a curious employee dialling it back, and an audit trail that says who the caller was. The panel below shows what the current country matrix holds for the United Kingdom.

What the country matrix holds for the United Kingdom

Number types:
Local, National, Mobile, Toll free
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Getting a United Kingdom number you can present

Before a UK number can be issued to your workspace, a regulatory submission has to be approved. That submission is about establishing who you are and that the number will be used by the organisation it is issued to, which is the same question Ofcom's caller ID rules ask from the other direction: the authority to present a number has to come from somewhere, and this is where it comes from.

Have your registered business details and a business address to hand before you start, along with the name of the person who will be the authorised contact for the numbers. The submission is reviewed rather than automatic, so start it before you need it rather than in the week you plan to run a campaign.

One distinction to hold onto here, because the table above the seam answers half of it and not the other half. What the carrier asks for in the United Kingdom is a business address inside the country, and not a post office box. That table is generated from the carrier's own current published rules, so treat it as the authoritative summary of what to have ready. What we have not found is a United Kingdom regulator requirement standing behind it, in the way ComReg's numbering conditions stand behind Ireland's address rule. So read the address request as the carrier establishing who you are, rather than as an Ofcom condition, and do not assume a British equivalent of the documentary regimes Spain and Chile publish, because we looked for one and did not find it.

Where your sector adds its own requirements

In financial services the Financial Conduct Authority's operational resilience rules, published as PS21/3, took effect on 31 March 2022, with firms required to have completed mapping and testing so that they can remain within their impact tolerances by 31 March 2025. Firms identify their important business services, set an impact tolerance for each, and test against severe but plausible scenarios. Social engineering against staff is a plausible route into most important business services, so a scenario that ignores people is an incomplete answer to that requirement.

For the largest firms and financial market infrastructures there is also CBEST, the threat intelligence led assessment framework run by the Bank of England with the PRA and the FCA. It is a supervisory exercise rather than something you opt into: threat intelligence drives scenarios, testing is executed against live production systems unless an exception applies, and the whole assessment typically runs nine to twelve months.

Two honest limits on this section. Neither PS21/3 nor CBEST names voice phishing simulation as a required technique, so treat anyone who tells you a UK regulator mandates it as selling rather than advising. And the European instruments a reader may have met on our other country pages are not the ones you are working to here, so a compliance programme copied from an EU sister entity will be answering a different regulator's question.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in the UNITED KINGDOM. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance through a published security testing policy.

Verify or correct each proposition below against primary UK sources, and tell me what we must have in writing before the first call:

1. The lawful basis is UK GDPR Art 6(1)(f), evidenced by a Legitimate Interest Assessment, and employee consent is not available because it cannot be freely given.
2. An Art 35 DPIA is required because the programme is systematic monitoring of employees.
3. PECR 2003 reg 19 is limited to direct marketing purposes and so is not engaged by an authorised security test, whichever voice mode is used.
4. ⚠ The Telecommunications (Lawful Business Practice) Regulations 2000 (SI 2000/2699) were made under RIPA s.4(2), which IPA 2016 Sch.10 para.45 repealed. Tell me which route in IPA 2016 s.6 our recording would rely on, if any, on the assumption that the calls traverse a system we control.
5. Ofcom General Condition C6 and the CLI guidance applying from January 2025 require the presented number to be valid, dialable, uniquely identifying and authorised.
6. ICE Regulations 2004 impose no standing consultation duty absent a request from at least 10 per cent of employees, subject to the floor of 15 and ceiling of 2,500.

Flag anything that has changed since September 2026, and identify any sector rule (FCA operational resilience, CBEST) that alters the analysis for a regulated firm.

Common questions

Do we need employee consent to run a vishing simulation in the UK?
No, and relying on it would be a mistake twice over. Consent from an employee is not freely given, so it fails the UK GDPR standard, and telling people a simulated attack is coming means you are no longer testing anything. Use legitimate interests with a documented assessment, a DPIA, and a transparency notice covering the programme.
Does PECR stop us using an AI voice on the call?
Regulation 19 restricts automated calling systems for direct marketing purposes. An authorised security test against your own workforce is not direct marketing, so that regulation is not the obstacle it is often assumed to be. Everything about data protection, recording and caller identification still applies to the call either way.
Can we record the simulated calls?
Take this one to your own lawyers. The regulations everyone cites rest on a section of RIPA that the Investigatory Powers Act 2016 repealed, and the surviving routes to lawful authority are narrower than the old summary suggests. Whatever route applies, tell staff that recording happens and keep recordings no longer than the training needs.
Do we have to involve a works council or a union?
There is no general United Kingdom equivalent of German co-determination. The Information and Consultation of Employees Regulations 2004 apply from fifty employees but only once at least ten per cent of staff request negotiations. Where you recognise a union or already hold an information and consultation agreement, consult under that agreement.

Elsewhere in Western Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.