When Your Bank Answers the Phone: Who Really Has Your Information?
The hidden questions behind banking call centres, outsourcing, customer privacy and service quality
When I call my bank, who am I actually speaking to?
It sounds like a simple question.
But behind that telephone call is a much bigger issue.
When customers contact a bank, they may provide or confirm their name, National Identity Card details, account information, transaction information, card-related information, contact details, loan information, business information or details of a complaint.
In other words, a simple telephone conversation can involve highly sensitive financial information.
The customer naturally thinks:
“I am speaking to my bank.”
But operationally, the person answering the telephone could be a direct employee of the bank, a contractor or an employee of a third-party service provider.
And this is where an important conversation begins.
The issue is not whether outsourcing is good or bad.
The real question is:
If a bank outsources part of its customer-service operation, does the customer still receive the same level of privacy, confidentiality, security, accountability and service?
That is the question worth asking.
Outsourcing is not automatically a problem
Let me make one thing clear from the beginning.
I am not against outsourcing.
Outsourcing can provide organisations with:
- specialised expertise;
- 24-hour staffing;
- technology capability;
- operational flexibility;
- scalability;
- business continuity;
- specialised customer-service skills; and
- potential cost efficiencies.
Many industries successfully use third-party service providers.
Banking is no different.
However, banking has one major difference.
The information involved is extraordinarily sensitive.
Therefore, outsourcing a function does not remove the institution’s responsibility to protect its customers.
Sri Lanka’s banking environment is changing
The Central Bank of Sri Lanka has recognised outsourcing as part of the operational environment of licensed banks.
Importantly, in March 2026, the Central Bank issued a specific Banking Act Direction on Outsourcing of Business Operations of Licensed Banks.
This demonstrates that outsourcing is not simply an informal management decision.
It is an area requiring governance, risk management and regulatory oversight.
At the same time, Sri Lanka’s financial consumer-protection framework places importance on customer privacy and confidentiality and on appropriate supervision of agents and service providers.
Therefore, the conversation should move beyond:
“Is the call centre outsourced?”
We should be asking:
“How is the outsourced operation governed?”
Seven situations every customer should understand
Case Study 1 — The ordinary telephone call
Imagine a customer calls a bank to ask about a transaction.
The customer provides a few identifying details.
The agent confirms the customer’s identity and accesses the relevant system.
Nothing unusual happens.
But think about what has just happened.
A third party may potentially have access to:
identity information + account information + transaction information + contact information.
The customer may never know the organisational structure behind the telephone.
Therefore, strong access controls and authentication procedures are essential.
Case Study 2 — The recorded telephone call
Most customers have heard:
“This call may be recorded for quality and training purposes.”
That sentence is now so common that many people barely notice it.
But a recorded call can contain extremely sensitive information.
Therefore, important questions arise:
Where is the recording stored?
Who can access it?
How long is it retained?
Can it be copied or downloaded?
What happens when the retention period expires?
The technology may be sophisticated.
But the fundamental issue remains simple:
Customer information must remain customer information — not an uncontrolled organisational asset.
Case Study 3 — The outsourced employee
Imagine a third-party employee handling banking enquiries.
The person may be highly professional and properly trained.
There is nothing inherently wrong with that.
But the customer should reasonably expect that the person has:
- appropriate confidentiality obligations;
- adequate training;
- restricted system access;
- proper authentication procedures;
- cybersecurity awareness;
- supervision;
- quality monitoring; and
- a clear escalation mechanism.
The employment contract may belong to another company.
But the customer’s expectation of confidentiality does not change.
Case Study 4 — The frustrated customer
Now consider a different situation.
A customer has a genuine banking problem.
The first agent cannot resolve it.
The customer is transferred.
The second person asks the customer to explain everything again.
Then the customer is transferred again.
Eventually, the customer becomes frustrated.
This is where outsourcing becomes a customer-experience issue, not merely a staffing issue.
A bank may achieve operational efficiency while simultaneously creating customer frustration if responsibility is fragmented.
Customers do not care how many departments exist behind the telephone.
They want one thing:
A problem solved properly.
Case Study 5 — The cybersecurity incident
Now consider the most serious scenario.
Suppose customer information is accidentally exposed through:
- excessive system access;
- weak passwords;
- phishing;
- social engineering;
- an unsecured device;
- inappropriate downloading;
- poor employee practices; or
- a third-party security failure.
The question then becomes:
Who is responsible?
From the customer’s perspective, the answer should not become a complicated discussion about contracts between companies.
The customer contacted the bank.
The customer trusted the bank.
The customer expects the bank to protect the information.
This is why vendor management and third-party risk management are so important.
Case Study 6 — The cost-cutting argument
There is another side to this discussion.
Banks are businesses.
They have significant expenses.
They employ thousands of people, operate branches, maintain technology platforms, invest in cybersecurity, comply with regulations and provide services around the clock.
Therefore, management naturally looks for efficiency.
Outsourcing may sometimes reduce operational costs.
But there is a fundamental business question:
If operational costs decrease, does the customer receive better value?
Cost reduction alone should never become the only measurement.
A more meaningful equation is:
Cost + Security + Privacy + Accuracy + Speed + Empathy + Accountability + Customer Satisfaction
That is the balance.
Case Study 7 — Artificial intelligence and the next generation of banking
The future could make this discussion even more complicated.
Imagine a customer journey involving:
Customer → Chatbot → Authentication → AI system → Human agent → Specialist → Resolution
Technology can make banking faster.
Artificial intelligence can answer routine questions.
Automation can reduce waiting times.
Digital platforms can operate 24/7.
But every additional technology layer can also create another question:
Who has access to the customer’s information?
The future of banking therefore cannot be about technology alone.
It must be about trusted technology.
The hidden cost of poor service
There is another issue that banks and other financial institutions should consider.
A customer who receives poor service may not immediately close an account.
But something else can happen.
Trust begins to decline.
And trust is difficult to measure on a balance sheet.
A customer may tolerate:
- a long waiting time;
- a technical problem;
- a temporary inconvenience;
- an occasional service failure.
But customers become much less tolerant when they believe that nobody is taking responsibility for their problem.
That is why customer-service quality is not simply an operational issue.
It is a brand issue.
A bank can outsource a function. It cannot outsource trust.
This is the sentence I would like decision-makers to remember.
There is nothing inherently wrong with outsourcing.
There is nothing inherently wrong with using technology.
There is nothing inherently wrong with seeking operational efficiency.
But the customer should not become the weakest link in the process.
If a bank uses a third-party service provider, the customer should still receive:
the bank’s standards,
the bank’s security,
the bank’s confidentiality,
the bank’s accountability,
and
the bank’s commitment to service.
The organisational structure behind the telephone should never become the customer’s problem.
Ten questions Sri Lankan banking customers should ask
As customers, perhaps we should become slightly more informed.
Not confrontational.
Not suspicious.
Simply informed.
Here are ten reasonable questions:
1. Who is handling my information?
2. Is the customer-service operation internal or provided by a third party?
3. What information can the person handling my call access?
4. How is my identity authenticated?
5. Are calls recorded?
6. How are recordings protected?
7. Who can access those recordings?
8. How are third-party employees trained in confidentiality and cybersecurity?
9. Who is accountable if something goes wrong?
10. Has operational efficiency actually improved my customer experience?
These are not unreasonable questions.
They are questions of modern financial consumer awareness.
My perspective as a business professional
After more than three decades across tourism, hospitality, finance, technology, education and international business, I have learned one simple lesson:
Processes are important. People are more important.
An organisation can have sophisticated systems.
It can have expensive technology.
It can have impressive policies.
It can have international certifications.
But eventually, the customer interacts with a human being.
That human being becomes the face of the organisation.
Whether that person is sitting inside the bank’s building or working from a third-party service provider is ultimately less important than whether the organisation has created the right culture, controls and accountability.
This principle applies far beyond banking.
It applies to airlines.
Hotels.
Hospitals.
Telecommunications companies.
Insurance companies.
Government services.
Travel companies.
And increasingly, artificial intelligence platforms.
The future should be customer-centred, not merely cost-centred
I strongly believe that businesses should pursue efficiency.
But efficiency should not mean simply:
“How cheaply can we provide the service?”
The better question is:
“How efficiently can we provide a secure, reliable, human and trustworthy service?”
That is a very different philosophy.
The cheapest call centre is not necessarily the most efficient call centre.
The fastest answer is not necessarily the best answer.
The most technologically advanced system is not necessarily the safest system.
And an outsourced employee is not necessarily a poorer service provider than an internal employee.
Everything depends on governance, training, technology, supervision, accountability and culture.
Finally, let us protect something money cannot easily buy
A bank can buy technology.
It can buy buildings.
It can buy software.
It can outsource operations.
It can hire consultants.
It can invest millions in cybersecurity.
But there is one thing that cannot simply be purchased:
customer trust.
Trust is earned slowly.
It can disappear quickly.
Therefore, whether a customer is speaking to a bank employee, a contractor, a contact-centre specialist or an automated system, the principle should remain the same:
The customer’s privacy should be protected.
The customer’s information should be treated confidentially.
The customer’s problem should be taken seriously.
And someone should ultimately be accountable.
A bank can outsource a function.
It cannot outsource trust.
A final question for the banking industry
Perhaps the next time we discuss outsourcing in banking, we should stop asking only:
“How much can the bank save?”
And start asking:
“How much trust can the bank preserve while becoming more efficient?”
That is the conversation worth having.
Disclaimer
This article has been authored and published in good faith by Dr. Dharshana Weerakoon, DBA (USA) for educational, professional and public-awareness purposes. It is based on publicly available regulatory and industry information, general business knowledge and the author’s professional observations and experience.
The article discusses banking operations, outsourcing, customer service, privacy, confidentiality, information security and financial consumer protection at a general industry level. It does not refer to, accuse, criticise or make findings against any particular bank, financial institution, employee, contractor or service provider.
Nothing in this article should be interpreted as alleging misconduct, negligence, unlawful disclosure, regulatory non-compliance, data breach or improper conduct by any individual or organisation.
The article does not constitute legal, financial, banking, investment, cybersecurity or regulatory advice. Readers should obtain appropriate professional advice where specific circumstances require it.
The author’s observations are personal and analytical and are intended solely to encourage informed discussion about customer trust, responsible outsourcing, privacy, confidentiality, technology and service quality in the evolving financial-services environment.
© Dr. Dharshana Weerakoon, DBA (USA). All rights reserved.
Further Reading: https://www.linkedin.com/newsletters/outside-of-education-7046073343568977920/
Further Reading: https://dharshanaweerakoon.com/sri-lanka-financial-system/
