MST HOLDING returns to Expo Relación Cliente 2026: once again at one of the industry’s key events

The date is already marked on the calendar, and this year we are looking forward to it more than ever. MST HOLDING will once again be taking part in Expo Relación Cliente 2026, Spain’s leading customer experience event, taking place on 7 and 8 October at Kinépolis Ciudad de la Imagen in Madrid. And, as always, we will be bringing plenty of new developments with us.

If you have been following our journey, you already know that standing still is not really our thing. So get ready, because this article will tell you everything you need to know about our participation: where to find us, what you will discover at our stand, and why this year’s edition promises to be different from all the previous ones.

An event that sets the pace for the industry

For years, Expo Relación Cliente has been one of Spain’s leading events for everything related to customer experience and the contact center industry. Each edition brings together leading companies, brands and professionals to share trends, technology and real success stories.

This year’s edition comes with a highly relevant theme focused on how artificial intelligence is rewriting the rules of the relationship between brands and people. Artificial intelligence in customer service is no longer a promise for the future: it is already transforming, here and now, the way companies communicate with their customers.

For us, this is nothing new. We have been working for some time to ensure that technology serves people, not the other way around. And at Expo Relación Cliente 2026, we will be showing exactly what that means.

What everyone will be talking about this year: AI, data and people

If there is one topic set to define this year’s event, it is the conversation around artificial intelligence applied to customer experience. Not as a passing trend, but as a real tool that is already changing very specific aspects of customer service: how issues are resolved, how quickly customers receive a response, and how companies can anticipate their needs before they even express them.

But there is something we firmly believe, and something you will also be able to see at our stand: technology alone does not solve anything. AI works when it is supported by well-designed processes, well-trained teams and a clear strategy for continuous improvement. This is precisely where our consulting pillar comes into play, ensuring that every technological advance translates into better service, rather than simply more automation.

Find us at Stand 48

Our participation in Expo Relación Cliente 2026 will also be an opportunity to share our vision of where the industry is heading.

Throughout the two-day event, the MST HOLDING team will be at Stand 48, a space designed to meet with clients, partners and professionals interested in discovering how we are addressing the new challenges facing customer experience.

In addition, Jessica Barceló, CEO of MST HOLDING, will be attending this year’s event, joining the team and sharing our vision of how an industry undergoing one of the most significant transformations in recent years is evolving.

As co-sponsors of Expo Relación Cliente 2026, we want to once again play an active role in this space for conversation, knowledge sharing and innovation.

Because events such as ExpoRC are not just about discovering new technologies. They are also an opportunity to share real experiences, listen to different perspectives and, above all, talk about the challenges that organisations need to solve today.

More than three decades listening to customers

We have been working in this industry for more than 33 years, and if there is one thing that has remained unchanged throughout that time, it is the way we understand our business: the customer always comes first. What has changed — and significantly — is the technology we use to make that possible.

This consistency and our commitment to doing things well have earned us recognition that makes us extremely proud, including being recently recognised as one of the leading contact centers in the industry. But what truly motivates us is not the awards themselves; it is continuing to improve the experience we deliver every single day.

Would you like to join us at Expo Relación Cliente 2026?

If you want to discover first-hand the trends transforming customer experience, learn about the latest developments in the industry and meet the MST HOLDING team, you can register for Expo Relación Cliente 2026 through this link: https://ifaes.credoffice.net/vCongress/landingForm?eid=7&atid=22&puid=de6aa444-8495-488f-b678-0a11243c7d5f&pid=147&lg=es

Book your place and come and visit us.

7–8 October 2026 | Kinépolis Ciudad de la Imagen, Madrid | Stand 48

See you at ExpoRC26.

www.mstholding.com

AI That Serves Customers Without Telling Them: 3 Myths About Article 50 of the AI Act That Are Confusing Contact Centers

A customer calls to check their account balance. Another sends a WhatsApp message to change a hotel booking. Someone else wants to schedule an appointment at a car repair shop. In all three cases, it is increasingly likely that the response will come not from a person, but from a virtual assistant.

And since 2 August 2026, there is a legal obligation that many companies have yet to fully address: customers need to know when they are interacting with AI.

This requirement comes from Article 50 of the European Union’s Artificial Intelligence Act (AI Act). In our conversations with clients across different industries, we repeatedly come across the same misconceptions. Let’s debunk them one by one.

Myth 1: “I use AI to assist people, not replace them, so this doesn’t apply to me”

This is often the first assumption, and it is a mistake.

The regulation does not distinguish between “AI that replaces people” and “AI that helps provide better customer service”. What matters is one thing: if an AI system interacts directly with a customer, the customer must be informed that they are interacting with a machine, unless this is obvious from the context.

It does not matter if the chatbot only identifies the reason for the enquiry before transferring the customer to a human agent. If it interacts with the customer, it counts.

Myth 2: “The legal department can solve this by adding a clause”

Not quite.

Article 50 is not something that can be addressed simply by signing a document once and considering the matter closed. It is a requirement that needs to be embedded in the customer experience itself: in the welcome message of a voicebot, in the first message of a chat conversation, and in the way a WhatsApp assistant introduces itself.

In practice, this means reviewing scripts, conversational flows and automatically generated content, such as call summaries or semi-automated email responses, that reaches customers without making it clear that AI has been involved in producing it.

Myth 3: “If my BPO provider manages the channel, the responsibility is theirs”

It depends, and this is where many operations are caught by surprise.

The responsibility for informing customers lies with the party deploying the technology in front of the end customer. If you outsource customer service operations, this responsibility should already be clearly reflected in your contracts and SLAs with your BPO provider, rather than simply being assumed.

What Does This Look Like Across Different Industries?

Managing this requirement in banking is not the same as managing it in tourism. Here are some examples of where problems commonly arise:

  • Banking: virtual assistants handling balance or transaction enquiries, where the initial AI disclosure may be buried within an options menu.
  • Travel and tourism: chatbots managing bookings and travel changes, particularly during peak periods when the bot may handle the entire conversation without clearly identifying itself as AI.
  • Automotive: workshop appointment assistants that often rely on legacy scripts created before this obligation existed.
  • Healthcare and pharmaceuticals: bots used to schedule appointments or answer basic queries, a particularly sensitive area given the nature of the information involved.

The same pattern appears across all these industries: the technology was originally deployed to reduce waiting times, while the “I’m a virtual assistant” disclosure was treated as a minor design detail.

The Real Issue Is Not the Fine

Penalties exist, but what we see in many operational audits is a more fundamental problem: many companies do not have a clear inventory of every customer touchpoint where AI is interacting with customers.

Without that map, there is no way to guarantee compliance with the regulation, no matter how good the company’s intentions may be.

Before December Arrives

Generative AI systems that were already in operation before August 2026 have until December to adjust their technical labelling. However, this deadline should not be confused with the obligation to inform users, which is already enforceable.

There are two questions we usually ask when we begin working with an operation:

Have you mapped every touchpoint where AI interacts with your customers?

Do your contracts with BPO providers clearly define who is responsible for meeting this obligation?

If you do not have a clear answer, this is often the starting point for our CX Consulting and AI Technology projects at MST Holding: identifying where AI is being used across your operation, how this is communicated to customers, and how it is documented.

Do You Know Whether Your Operation Falls Within the Scope of Article 50?

Talk to our CX Consulting and AI Technology team and find out how to assess your customer service operation against the requirements of the EU AI Act.

400 Prefix: How It Will Change the Way Businesses Call Their Customers Forever

It has probably happened to you before: your phone rings, you see a number you don’t recognize, you think it might be a family member or something urgent… and it turns out to be a sales call. Sometimes it’s even worse: a scam attempt. That moment of uncertainty will soon disappear in Spain, as the Government has approved a new measure that completely changes the rules for commercial calls.

What the New Regulation Actually Says

Spain’s Ministry for Digital Transformation and the Civil Service has published a resolution establishing that, from October, all commercial calls must be made from a nine-digit number beginning with the 400 prefix.

The idea is straightforward: as soon as you see a number starting with 400 on your screen, you’ll immediately know that a business is calling you for commercial purposes.

There is one important detail to understand: these numbers will be one-way only. In other words, customers will be able to receive calls from these numbers but will not be able to call them back. This is no coincidence—it is designed to reduce the risk of fraud that occurs when people return calls to unknown numbers, a common tactic used in telephone scams.

One point worth noting is that an earlier draft of the regulation, published in February, proposed making these numbers two-way. However, the final version approved in April changed this approach and established them as one-way numbers. If you’ve read otherwise elsewhere, it was most likely referring to the earlier draft.

When Will It Become Mandatory?

The new numbering range will become operational within six months of the publication of the resolution. From October 2026, telecommunications operators will begin blocking commercial calls that do not use the 400 range.

From that point onward, any commercial call made from a number other than one beginning with 400 may be blocked directly by the telecom operator, without the user having to take any action.

This measure does not come out of nowhere. It implements the Customer Service Act (Ley SAC), approved in December 2025, which already required commercial calls to use a dedicated numbering code so they could be clearly identified.

What About Customer Service Calls?

This is where some confusion often arises, so it’s worth clarifying.

The 400 prefix is exclusively for commercial calls—those made by a company to sell products or services or acquire new customers.

Customer service calls—those related to an existing contract, support request or incident—follow different rules. These may only be made from specifically assigned short numbers, the free 800 and 900 ranges, or standard geographic numbers.

This requirement was already established by the ministerial order aimed at preventing caller ID spoofing, which came into force in March 2025 and also prohibited the use of mobile numbers for this type of customer service call.

In short:

  • Sales calls will come from a 400 number.
  • Customer service calls will come from an 800, 900, or geographic number.
  • They should never come from a standard mobile number.

Why Has the Government Introduced This Measure?

The objective is clear: to combat telephone fraud.

Digital Transformation Minister Óscar López summed it up well by saying that everyone has answered a call believing it was someone they knew, only to discover it was a commercial call.

The new numbering system forms part of a broader national strategy against telephone fraud. According to the latest official figures, since the plan was introduced in March 2025 it has enabled operators to block 192 million fraudulent calls and 17 million fraudulent SMS messages. These numbers illustrate the scale of the problem the Government is seeking to address.

What Does This Mean for Companies That Make Commercial Calls?

This is where the new regulation directly impacts contact centers, telesales teams and any organization running outbound telemarketing campaigns.

The change involves far more than simply replacing a phone number. Businesses will need to review their outbound calling infrastructure, adapt their dialing platforms and ensure that every commercial campaign is carried out exclusively using numbers within the new 400 range.

The industry has already expressed concerns. The Spanish Contact Center Association (AEERC), which represents a large part of the sector, has warned that the implementation period is shorter than originally anticipated under the Customer Service Act.

For companies operating outbound campaigns, this means a genuine technical transition: coordinating with telecommunications operators, updating automatic dialing systems and verifying that every commercial line has been correctly assigned to the new numbering range before October. The sooner this migration begins, the lower the risk of campaigns being blocked once the regulation takes effect.

What Can You Do If You Receive a Non-Compliant Commercial Call?

If, from October onward, a company calls you from a number that does not begin with 400, you may report the call to the Telecommunications User Assistance Office (OAUT) or to Spain’s National Commission on Markets and Competition (CNMC).

This provides an additional layer of consumer protection by placing responsibility on the organization making the call rather than on the person receiving it.

Conclusion

The introduction of the 400 prefix is much more than a simple numbering change. It represents another step toward a more transparent relationship between businesses and consumers while strengthening the fight against telephone fraud.

For consumers, it means being able to decide at a glance whether to answer a call.

For businesses, it means that technological and operational adaptation can no longer be postponed. October is closer than it seems.

www.mstholding.com

Customer Service in Catalan, Valencian, Basque, and Galician: What the Customer Service Law Requires from the Financial Sector

If a customer calls their bank in Basque and the agent does not understand the language, what happens? Until now, financial sector regulation required institutions to respond to written complaints in the same language in which they had been submitted. It was a limited right and relatively easy to manage. Law 10/2025 significantly expands this right, with much broader practical implications for customer service teams.

This is currently one of the areas with the highest level of interpretative ambiguity, but precisely for that reason it deserves detailed analysis: financial institutions need guidance in order to start taking action.

What Already Existed: The Right to Receive a Response in the Language of the Complaint

Sector-specific regulation already established that customers have the right to submit complaints in Spanish or in any co-official language of the territory where they reside (Catalan, Basque, Galician, or Valencian) and to receive the response in that same language. This right applied to formal written complaints managed under the regulatory framework supervised by the Bank of Spain, the CNMV, and the DGSFP.

To manage this requirement, many institutions relied on specialized teams or translation services. The volume was manageable because it was limited to a specific type of communication.

What the Customer Service Law Adds: Language Throughout the Entire Interaction

Law 10/2025 goes much further. Its approach is that linguistic criteria should not be limited to formal complaints: they must apply to the entire interaction with the Customer Service department, including phone calls, live chats, emails, messaging services, and any other communication channel.

If an institution operates in a territory with a co-official language, it must be able to assist and respond in that language whenever requested by the customer, both orally and in writing. Customer service teams must also be trained accordingly.

Articles 29 ter.2 and 29 septies.4 of the amended Law 44/2002 establish this linguistic framework. The regulation does not state that every call must be handled in a co-official language. It states that when a customer requests it, the institution must be able to respond. But that “must be able to” carries very specific organizational implications.

The Operational Challenge: People, Training, and Availability

Having agents capable of providing fluent support in Catalan, Basque, Galician, and Valencian across all shifts and all channels is not easy, especially for medium-sized institutions or national organizations whose customer service centers are located in a single site.

The market for professionals fluent in some of these languages (particularly Basque) is limited. Geographic dispersion of customers adds further complexity: an institution may simultaneously serve customers in the Basque Country, Catalonia, and Galicia, each with different language needs during the same working shift.

The law does not establish specific availability thresholds, but this does not exempt institutions from compliance. What it does require is a structural customer service model, not merely occasional solutions.

Can Technology Be the Solution?

The answer is nuanced but encouraging. The law does not rule out the use of language assistance technology or AI-powered real-time translation systems, provided that service quality is guaranteed. This opens the door to real-time support tools for agents who do not fully master the language: systems capable of transcribing and translating conversations, allowing agents to understand customers and respond coherently.

However, technology does not eliminate responsibility for service quality. If the system makes translation errors that affect the proper resolution of the request, responsibility still lies with the institution. In addition, the system must be auditable.

Callback as a Temporary Solution, Not a Structural One

If, at a specific moment, no agent is available in the requested language, offering a callback from a qualified agent may be a valid solution. But with the same limitations applicable to waiting-time KPIs: it cannot become the standard approach. The institution must be able to demonstrate that it has a structural model for providing support in co-official languages, and that callbacks are only used exceptionally.

The Risk of Inaction

Co-official languages are considered a high-priority issue by Consumer Protection Authorities, especially in Catalonia, the Basque Country, and Galicia. The likelihood of receiving a complaint or undergoing an inspection in this area is higher than for many other regulatory requirements, partly because it is a right that citizens know and value, and partly because it is relatively easy for inspectors to verify whether an institution can provide service in a co-official language.

Institutions operating in these territories should include this issue in their compliance risk map and develop an action plan supported by documented evidence: who provides support in each language, what training agents have received, how demand is managed when immediate availability is not possible, and what technology is used as support.

Consulting C3 and MST Holding actively participate in the UNE Committee responsible for defining the audit standard for the Customer Service Law and maintain ongoing contact with the AERC to communicate the sector’s concerns to the organizations responsible for clarifying them.

MST and Costa Cruises Awarded for Their Employee Experience Strategy

Recognition for Our Approach to Employee Experience

At MST, we are celebrating. Together with our client Costa Cruises, we have won the award for Best Employee Experience Strategy in Contact Center at the 17th edition of the Platinum Customer Experience Awards.

This recognition fills us with pride because it validates a principle we strongly believe in: to deliver an outstanding customer experience, we must first take care of the people who make it possible every day.

In an environment as demanding as the Contact Center industry, people are the true driving force behind service excellence. That is why, together with Costa Cruises, we have developed an Employee Experience strategy focused on employee well-being, motivation, professional development, communication, and recognition.

People at the Heart of Our Strategy

This award recognizes a way of working built on listening, continuous improvement, and shared commitment. We have implemented initiatives designed to create a more positive, collaborative, and goal-oriented work environment.

Behind this project lies a comprehensive approach that includes training, coaching, close leadership, management tools, engagement initiatives, and a strong team culture that supports continuous growth.

We firmly believe that when professionals feel supported, valued, and empowered, they are able to deliver their very best in every customer interaction. This directly translates into an enhanced Customer Experience.

Employee Experience and Customer Experience: Two Paths Moving Forward Together

For us, Employee Experience and Customer Experience are deeply interconnected. One cannot exist without the other.

A motivated, well-trained, and engaged team is better equipped to create more meaningful conversations, effectively address customer needs, and build stronger relationships based on trust.

This recognition, achieved together with Costa Cruises, confirms that investing in people not only improves the workplace environment but also drives service quality, operational efficiency, and business results.

An Award Shared with the Entire Team

This Platinum Customer Experience Award is, above all, a recognition of the people who make this project possible every day.

To all the teams involved in delivering the Costa Cruises service, thank you for your dedication, positive attitude, and ability to turn every challenge into an opportunity for improvement.

As our CEO states:

“This award recognizes much more than a strategy. It recognizes the hard work, passion, and commitment of the people who make our project possible every day. At MST, we are convinced that taking care of our teams is the best way to take care of our customers. We proudly share this recognition with Costa Cruises and with all the professionals who have contributed to making it possible.”

Moving Forward

Winning this award motivates us to continue working with the same enthusiasm and sense of responsibility. We understand that Employee Experience is constantly evolving, just as customer expectations continue to change.

For this reason, we will continue to invest in innovation, active listening, training, employee well-being, and continuous improvement as the foundations for building workplaces where people can grow, create value, and feel part of something meaningful.

At MST, we would like to thank Costa Cruises for their trust and for sharing our vision of a people-centered customer experience.

This recognition reinforces our commitment to a way of working where Employee Experience, Customer Experience, and Operational Excellence advance together.

www.mstholding.com

Resolution Deadlines for Complaints: The Financial Sector Moves from Two Months to One

If there is one aspect of Law 10/2025 that will directly impact the day-to-day operations of customer service teams in the financial sector, it is the new framework for complaint resolution deadlines. The maximum response time is reduced from two months to one. Half the time to resolve complaints, while maintaining the same quality standards in responses and with the obligation to document everything. For many institutions, this is not a minor adjustment: it is a complete process redesign.

However, there are important nuances. The Customer Service Law (Ley SAC) does not establish a single deadline for all complaints in the financial sector. Instead, it introduces a distinction by type of service, requiring each complaint to be classified from the very moment it is registered.

The New Deadline Framework

Once the law comes into force, financial institutions must manage complaints according to the following differentiated structure:

• General complaints: maximum of 1 month from the formal submission of the complaint until the reasoned response is communicated to the customer. This specific deadline applies to the financial sector under sector-specific regulations, which take precedence over the general Customer Service Law. For all other sectors, the general deadline remains 15 business days.

• Payment services (payments, transfers, cards): maximum of 15 days. The shorter deadline already established under PSD2 remains in place. In this case, sector-specific regulation is stricter, not more flexible.

Previous regulation treated complaints in a generic manner, with a single two-month deadline for all cases. The Customer Service Law breaks this uniformity and introduces the need to classify and categorize each complaint according to the nature of the service involved. This has a direct impact on management systems, workflows, and agent training.

Why Accurate Classification from the First Contact Is Essential

If the deadline for a complaint related to a bank transfer is 15 days, while a complaint regarding a life insurance product allows one month, the system must identify the type of complaint from the very first registration and activate the correct deadline counter. Without this automatic or guided classification, the risk of non-compliance increases significantly, especially during periods of high volume.

This requires reviewing intake forms, categorization systems, escalation workflows, and automatic alerts for the teams responsible for each type of complaint. An issue related to an unauthorized card charge cannot be managed under the same deadline structure as a complaint concerning mortgage conditions.

Correct classification from the start provides another key advantage: prioritization. In high-volume environments, understanding that some complaints must be resolved within 15 days while others allow one month enables a far more efficient distribution of workload.

The Real Impact on Internal Processes

Cutting resolution times in half without reducing response quality requires identifying the real operational bottlenecks. Based on Consulting C3’s experience working with financial institutions, the most common issues are:

• The number of internal escalations required to resolve a complaint, as each escalation adds delays.

• Dependence on other departments (product, risk, legal) to obtain the necessary information. If these departments do not operate under internal SLAs aligned with the new regulatory deadline, the Customer Service department will not be able to comply.

• Agents’ ability to draft high-quality reasoned responses without always depending on higher-level validation.

• Internal approval times for responses, especially in complex or high-value complaints.

Evidence and Documentation: What Regulators Will Require

Compliance alone is not enough: institutions must also be able to prove it. Companies must maintain clear records of the exact time each complaint was received, its classification, the applicable deadline, and the date on which the response was communicated. This documentary traceability is what protects institutions during inspections or in the event of direct customer claims.

One particularly sensitive point is the starting moment of the deadline. The law establishes that the countdown begins from the formal submission of the complaint. Does the customer receive an automatic acknowledgment with date and time? Does that acknowledgment specify the applicable maximum response time? These are questions that must already be answered before the regulation comes into force.

What Financial Institutions Should Be Doing Now

• Review the current complaint management process and identify where the greatest delays occur.

• Implement an automatic or guided complaint classification system by service type, activating the corresponding deadline from the first registration.

• Align the internal SLAs of support departments (product, risk, legal) with the new one-month regulatory deadline.

• Ensure customers receive an automatic acknowledgment including the start date and maximum response deadline.

• Review alert systems so teams are notified when a complaint is approaching its deadline.

The shift from two months to one is not impossible to manage, but it requires a deliberate redesign of processes. It is not enough to do the same work in less time: it must be done differently.

www.mstholding.com

Zero Sales During a Complaint: the Separation Required by the Customer Service Act in the Financial Sector

Imagine calling your bank to dispute a charge you do not recognize. You spend several minutes explaining the issue, the agent understands the situation… and suddenly offers you a discounted home insurance policy. Beyond being poor practice, this is now a legal breach. Law 10/2025 expressly prohibits it, and financial institutions must review their processes, incentives, and team training to ensure it does not happen.

At first glance, this requirement may seem secondary within the regulation. However, its organisational implications are significant, especially in a sector where customer service teams have spent years being trained to maximise the commercial value of every customer interaction.

What the law prohibits

Article 29.3 of the amended Law 44/2002, in connection with Article 13 of the Customer Service Act (LSAC), establishes two obligations that financial institutions must implement before 28 December 2026:

• Organisational separation between Customer Service Departments and commercial teams. Both structures cannot share sales targets or sales incentives.
• An express prohibition on making commercial offers while handling a complaint or claim, without exceptions.

This prohibition is not arbitrary. It is directly linked to the risk of mis-selling — selling an unsuitable product by taking advantage of a customer’s vulnerable position — a practice that has been under the scrutiny of the Bank of Spain and the CNMV for years. The Customer Service Act now turns this into a legal obligation with clear sanctions.

Separation of teams or separation of functions?

One of the most common questions raised by financial institutions is whether the law requires physically separate teams for customer service and sales, or whether a functional separation is sufficient. Consulting C3’s interpretation, aligned with the position held by the AERC, is that the regulation requires functional separation, not necessarily structural separation.

In practice, this means that while an agent is managing a complaint or claim, they cannot perform any commercial action. Incentives, targets, and scripts must all be designed to exclude any commercial component during those interactions. If an agent’s compensation includes sales-related variables, institutions must ensure these do not apply or generate incentives during complaint handling.

This also impacts CRM systems: if, during a complaint call, the agent’s screen automatically suggests products that could be offered to the customer, this functionality must be disabled while the interaction is classified as a complaint.

What about customer retention?

This is where one of the most interesting discussions arises: if a customer calls to cancel a service, can the institution attempt to retain them? Is this considered a prohibited commercial action or a legitimate customer relationship management activity?

According to the AERC’s interpretation, the key distinction lies in the approach. What the law prohibits is a purely commercial action: making a financial offer to prevent the customer from leaving. What could still be allowed is informing the customer about alternatives that genuinely address the issue they are experiencing.

The difference is subtle but crucial. If a customer wants to close their account because fees are too high, offering them a discount would be considered a prohibited commercial action. However, if the customer is experiencing a technical issue with a digital service and, while resolving it, the agent informs them that there is an improved version without that issue, the context is different. The underlying principle should always be the same: are we solving the customer’s problem, or are we taking advantage of their vulnerability to sell them something?

The controls that the law requires

Having a written policy is not enough. The regulation requires specific and documented controls:

• Review and update of scripts and customer service protocols to remove any commercial call-to-action during complaint or claim handling.
• Systematic call monitoring to detect and document potential breaches, together with corrective action plans.
• Specific and documented training for Customer Service agents regarding this functional separation, with particular emphasis on ambiguous scenarios such as customer retention.
• Review of incentive models to ensure that no commercial component influences complaint management.
• Interaction records available for audit by the Bank of Spain, the CNMV, or the DGSFP at any time.

If the Customer Service model is properly designed, complying with this requirement is easier than it may seem. The real challenge appears when organisations have spent years combining functions that the law now requires to be clearly separated. The deadline is approaching quickly, and the risk of inaction goes beyond regulatory sanctions: an institution that sells during a complaint process not only breaches the law, but also damages customer trust in a way that is difficult to repair.

www.mstholding.com

Bots, IVR and the SAC Law: automation can no longer be the only customer service option

The financial sector has spent years investing heavily in the digitalisation of customer service: conversational bots, sophisticated IVR systems, self-service apps, and virtual assistants. A model that has proven highly efficient. Until now.

Law 10/2025 introduces a principle that changes the rules: no customer can be trapped in an automated system if, at any point, they wish to speak with a human agent. The concept is simple, but its operational implications are far deeper than they may initially appear.

What the law says: the explicit right to human assistance

The amended Law 44/2002 establishes that financial institutions must guarantee access to a human agent for any customer who requests it, at any stage of the interaction. Chatbots and virtual assistants are considered complementary tools, never substitutes for customer service.

The regulation also establishes two mandatory minimum service channels: telephone support and at least one non-face-to-face channel. Institutions may add more channels, but they cannot eliminate these two or replace them with exclusively automated systems. The compliance deadline is 28 December 2026.

The real change: leaving the bot without leaving the channel

Until now, many institutions configured their automated systems so that if a customer wanted to speak with a person, they had to leave the channel — for example, exit the app chat and make a phone call. The SAC Law removes that option.

If a customer starts an interaction within an automated channel and requests human assistance, they must be able to receive it within that same channel, without needing to switch channels or start the process again.

This means reviewing all automated customer service flows and ensuring that there is always a functional and accessible route to a human agent. In many cases, this requires redesigning IVR decision trees, chatbot flows, and escalation processes within messaging and chat environments.

The practical question for technology teams is straightforward: if a customer is checking the status of a transfer through the app chatbot and writes, “I want to speak with a person”, what happens next? If the system simply provides a phone number and asks the customer to call, that flow is non-compliant.

24/7 service and its reasonable limits

The law specifically refers to 24/7 availability for essential services and urgent or irreversible situations. In the financial sector, this includes card blocking, fraud reporting, or urgent transfers: for these types of requests, human assistance must be available outside standard business hours.

The expectation is not that every service must have human agents available at all times. The key is identifying which parts of the operation are considered critical or urgent and guaranteeing coverage for those specific cases.

The challenge of data protection and vulnerable customer groups

Personalised customer service introduces another dimension that the law addresses directly: data protection. In telephone and digital interactions, it is not always possible to verify a customer’s identity or determine whether they belong to a specially protected group without asking questions that could compromise their privacy.

In April 2026, the AERC submitted a formal consultation to the Spanish Data Protection Agency (AEPD) seeking clarification on how to reconcile the right to personalised service with data protection obligations, particularly regarding customers with disabilities. The AEPD’s response is highly anticipated across the sector and, once published, will need to be incorporated into customer service protocols.

What your institution should review before year-end

• Audit all automated service flows (bots, IVR systems, apps, chatbots) and identify whether there is an option to transfer the interaction to a human agent within the same channel.

• Verify that this transfer is fully functional during all hours in which the channel is operational.

• Review customer identification protocols to ensure data protection compliance in personalised interactions, particularly for vulnerable groups.

• Document the mandatory minimum service channels (telephone + non-face-to-face channel) and confirm that no process excludes their use.

• Define which services are considered urgent or critical and therefore require human assistance coverage outside normal business hours.

Digital transformation is irreversible, and the SAC Law is not intended to stop it. What it demands is that technology remains aligned with customer needs. Consulting C3 and MST Holding work with financial institutions to redesign these operations efficiently: preserving what already works, adapting what the regulation requires, and documenting everything necessary to successfully pass an audit.

The 3-Minute Limit on Customer Service Calls: What Your Financial Institution Needs to Know

Law 10/2025 on Customer Service sets a clear countdown for all financial institutions: they have until December 28, 2026, to adapt their operations. One of the requirements raising the most questions among operations teams is the new waiting time limit for inbound customer service calls, as it directly impacts workforce planning, technology, and the service model itself.

During the executive webinar organized by Consulting C3 together with the Spanish Association of Customer Relationship Experts (AERC), this was the topic that generated the highest number of questions. And for good reason: the nuances that separate compliance from non-compliance are significant.

What does the law say?

The amendment to Law 44/2002 is clear: 95% of inbound Customer Service (SAC) calls must be answered within a maximum of 3 minutes. This threshold is measured on an annual basis, meaning that not every individual call is required to meet the target, but the overall yearly average must comply.

Achieving this 95% target has major operational implications. Those managing customer service centers know that reaching this level effectively means maintaining an abandonment rate between 1% and 2%, which requires a complete review of workforce management and capacity planning models.

When does the waiting time start counting?

This detail directly affects how measurement systems must be configured. The law distinguishes between two scenarios:

• If the customer calls the Customer Service department directly without going through any automated system, the timer starts from the very first second of the call.

• If the customer first accesses an IVR or any other self-service system, the timer starts the moment the customer explicitly requests to speak with a human agent.

This second point is especially relevant for institutions already operating IVR systems: the clock does not start when the customer dials the number, but when they request human assistance. The contact center platform must accurately and audibly register that moment, as an approximate estimation will not be sufficient.

Callback: a safety valve with conditions

The law allows institutions to offer a callback service when waiting times are expected to exceed the limit. However, offering a callback does not exempt the institution from complying with the KPI. The metric still measures the actual waiting time, regardless of whether the customer accepted a deferred call.

Callback cannot become a systematic workaround. If an institution relies on it massively and takes hours — or even days — to return calls, it creates clear evidence of non-compliance that can easily be detected during an audit. The law requires real responsiveness and the ability to prove it with data. The UNE Committee is currently working on clarifying whether a callback offered before exceeding the threshold counts as KPI compliance.

Example: if service hours end at 10:00 PM and a customer accepts a callback at 9:55 PM, that call cannot simply be postponed until the following day. Responsiveness remains an enforceable criterion even if it is not quantified with the same level of detail as the main KPI.

Measurement, logging, and reporting obligations

Complying with the KPI is not enough: institutions must also be able to demonstrate compliance. Financial entities are required to maintain systematic KPI records available for regulatory audit at any time. This involves periodic reporting with data broken down by time slot, channel, and service type, properly stored and preserved.

The calculation is annual, but supervision may occur at any moment. And oversight will not only come from regulators: customers who believe they were not assisted within the required timeframe will be able to file complaints with Consumer Protection Authorities starting January 1, 2027.

What should your institution be doing right now?

• Measure current waiting times and calculate how far you are from the 95% within 3 minutes threshold. Without real data, there is no baseline.

• Review telephone service capacity planning: shifts, demand peaks, and agent-to-call volume ratios.

• Assess the role of callback within the customer service model. If you already use it, make sure response times and records are properly documented.

• Confirm that the technology platform accurately detects and logs the exact moment a customer requests human assistance through the IVR.

• Prepare regulatory reporting processes: format, frequency, and data custody chain.

Consulting C3 and MST Holding have been working for months with financial institutions on diagnostics and adaptation plans for the SAC Law. As members of the UNE Committee, we provide our clients with the most up-to-date interpretation of every regulatory requirement.

SAC Law in the Financial Sector: What Your Institution Needs to Know (and Do)

The Customer Service Law (SAC Law) is now a reality. And although many financial institutions have been hearing about it for months, one question still raises more doubts than expected: what actually applies to us?

Banks, insurers, asset managers, credit institutions… the financial sector operates under its own regulatory layer, which does not always fit neatly with a general law. And that is precisely where interpretation issues begin.

In this article, we explain what the SAC Law means for the financial sector, which changes are unavoidable, and where the main adaptation challenges currently lie.

What is the SAC Law and why it matters now

The Customer Service Law (SAC Law) establishes a new framework of obligations for all companies providing services in Spain, with the aim of ensuring high-quality, accessible, and effective customer service.

Its main pillars include the prohibition of automated systems as the sole customer service channel, the obligation to resolve complaints within specific timeframes, the right to be assisted by a human agent, and the need to implement service quality monitoring and control systems.

So far, nothing new for those who have been following regulatory developments. The real challenge arises when a financial institution tries to apply this law on top of an already existing regulatory structure: MiFID II, Solvency II, Bank of Spain regulations, CNMV requirements… overlap is inevitable, and it is not always clear which rules take precedence.

The financial sector has its own rules. Now what?

One of the key complexities of applying the SAC Law in banking and insurance is that these institutions are already subject to very specific obligations regarding customer service and complaint management. The Bank of Spain, the CNMV, and the DGSFP have long required formal procedures, defined timelines, and documented records.

So, does the SAC Law add another layer on top, or does it simply reinforce what already exists?

The answer is not straightforward—and that is exactly what creates uncertainty within compliance and operations teams. Some obligations, if already covered by sector-specific regulations, may be considered compliant with the SAC Law. However, others require specific review, as the new law goes beyond what financial regulation has required so far.

Some concrete examples:

  • Complaint resolution deadlines under the SAC Law may differ from those set by financial supervisors. Which one prevails?
  • The right to human assistance is a new requirement that not all institutions fully guarantee across their current channels.
  • Service quality monitoring requires metrics and indicators that many organizations have not yet sufficiently formalized.

The three real challenges of adaptation for financial institutions

Beyond theory, in practice there are three areas where the impact of the SAC Law is most evident:

1. Customer service models
Institutions operating with highly digital channels or strong reliance on automated systems will need to assess whether they comply with the requirement for access to human assistance. It is not just about having a phone line—it must function according to the standards set by the law.

2. Complaint management
This is likely the area with the greatest impact. The SAC Law tightens deadlines and requires a more robust tracking system. For the financial sector, which already has established processes, the challenge lies in identifying where current procedures fall short.

3. Customer experience as a strategic lever
This is where the SAC Law stops being just a compliance issue and becomes an opportunity. Institutions that use this adaptation to genuinely improve their service model will not only meet regulatory requirements, but also gain in customer satisfaction, loyalty, and reputation.

What is your organization’s level of compliance?

This is the key question every financial institution should be asking right now. And answering it properly requires more than just reading the law—it requires aligning it with real operations, internal processes, and existing sector regulations.

This analysis is not simple. But it is necessary. And the sooner it is done, the more room there is for structured and well-planned adaptation.

How to adapt the SAC Law in banking and insurance: from regulation to action plan

One thing is becoming clear in the financial sector: the real challenge is not understanding the SAC Law, but implementing it. Many organizations are familiar with the regulation but still struggle to translate it into concrete changes in their customer service and complaint management models.

The difference between compliance and effective compliance lies precisely there: in how the law is embedded into daily operations. Which processes need adjustment, which channels require redesign, and how to measure true alignment with the new requirements.

With this objective in mind, MST Holding has developed a dedicated session for banking and insurance, designed to help organizations move from interpretation to execution.

On May 13th, we will host a webinar where we will address, in a practical way, what the SAC Law specifically requires in the financial sector, how to adapt customer service and complaint models step by step, and how to assess the real level of compliance through a structured self-diagnosis.

In addition, attendees will gain access to materials designed to facilitate this transition, including a practical guide focused on transforming customer service models and an express diagnostic tool to clearly identify each organization’s starting point.

The session will feature Patricia Guerrero Castro, Operations Director at Consulting C3, and José Francisco Rodríguez, President of the AEERC, providing expert insight from both operational and industry perspectives.

The event will be held online via Teams, is completely free of charge, and includes access to the recording for those unable to attend live. Places are limited.

MST Holding: expertise and knowledge serving the financial sector

At MST Holding, we have spent more than 30 years designing and implementing customer service models for companies in the financial, insurance, and services sectors. We understand the regulations—but more importantly, we understand operations: real processes, bottlenecks, and the points where compliance meets day-to-day reality.

That is why, when we support an organization in adapting to the SAC Law, we do not start from scratch—we build on what already works.

If your institution is currently assessing the impact of the SAC Law or needs a clear roadmap for adaptation, now is the time to approach it with the right criteria.

www.mstholding.com

Exit mobile version