The Consumer Credit Sourcebook is a UK regulatory framework that sets expectations for fair treatment in consumer credit activities, including collections and arrears handling. Banks and lenders must align payment recovery practices with conduct rules, making sure communication, flexibility, and customer treatment remain proportionate and compliant.
What the Consumer Credit Sourcebook Governs
The consumer Credit Sourcebook is a conduct framework for consumer credit activities, especially collections, arrears, forbearance, and customer communications. Its core function is to shape how lenders recover payments without crossing into unfair or disproportionate treatment.
For practitioners, the practical question is not whether debt recovery is permitted, but whether the process remains consistent with conduct expectations across the full credit lifecycle, from early arrears to escalation. That makes it a governance and treatment standard as much as a collections rulebook.
Where It Sits in UK Financial Services Conduct
Consumer Credit Sourcebook sits within UK regulatory expectations for retail credit firms, so it is best understood alongside broader conduct oversight rather than as a standalone collections policy. It influences call scripts, arrears strategies, customer vulnerability handling, and the use of repayment flexibility when a borrower shows signs of distress.
Because it governs regulated behavior, its interpretation often depends on customer context, product type, and the firm’s own policies. A technically lawful recovery action can still be inappropriate if it is not proportionate to the borrower’s circumstances or if communication becomes misleading, repetitive, or coercive.
What Compliance Looks Like in Practice
Compliance is usually visible in the way firms document and execute arrears journeys, hardship reviews, and collections contact rules. Good practice is reflected in clear records, consistent treatment, and evidence that staff and systems apply the same conduct standards rather than improvising case by case.
That is why this sourcebook affects frontline operations as well as policy. It influences how firms train agents, calibrate automated reminders, decide when to pause recovery activity, and ensure customer support options are offered before pressure escalates.
Why It Matters for Customer Treatment and Recovery Outcomes
The sourcebook matters because recovery performance and fair treatment are not opposites. A well-run collections process can protect both customer outcomes and lender recoveries by reducing avoidable complaints, missed vulnerability signals, and regulatory breaches.
In practice, the framework pushes firms toward proportionate recovery rather than purely volume-driven collections. That often means preserving room for negotiation, recognizing hardship signals early, and avoiding practices that could worsen arrears through poor communication or rigid escalation.
Risk and Threat Considerations
Weak application of the Consumer Credit Sourcebook can create conduct risk, complaint risk, and regulatory exposure, especially where collections processes are automated or heavily outsourced. The main danger is not just a single poor decision, but a repeatable pattern of unfair treatment that affects many accounts at once.
Failure mechanism: Poorly designed arrears workflows, inadequate staff training, or rigid automation can produce disproportionate contact, weak vulnerability handling, and inconsistent forbearance decisions.
Impact: Firms can face supervisory action, remediation obligations, customer harm, reputational damage, and higher operational friction from complaints and disputes.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Consumer credit conduct rules create enterprise regulatory risk that should be governed consistently. |
| Recommendation — Embed arrears and collections conduct risks into enterprise risk governance. | ||
| ISO/IEC 27001:2022 | A.5.31 — Legal, statutory, regulatory and contractual requirements | The sourcebook defines regulatory obligations that firms must identify and meet in collections handling. |
| A.5.36 — Compliance with policies, rules and standards for information security | The topic depends on staff and systems following defined treatment rules consistently. | |
| Recommendation — Track Consumer Credit Sourcebook obligations as part of compliance requirements management. Verify collections procedures follow approved conduct and treatment policies. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Collections workflows often require constrained authority so agents only take permitted recovery actions. |
| AU-6 — Audit Review, Analysis, and Reporting | Proportionate treatment in arrears handling depends on reviewable evidence of what happened and why. | |
| IA-5 — Authenticator Management | If collections tools use role-based access, credential lifecycle controls support accountable recovery operations. | |
| Recommendation — Limit collections staff and workflow permissions to approved recovery actions. Review collections activity logs for proportionate treatment and exception handling. Manage staff and system credentials tightly for collections and servicing platforms. | ||
Practitioner Guidance
Why practitioners should care: This term is operational, not merely legal. Collections, servicing, complaints, and compliance teams all need the same conduct standard so that recovery actions stay aligned with customer treatment expectations.
What to watch for: Look for repetitive contact patterns, limited discretion in scripts or workflows, weak exception handling for hardship, and gaps between policy intent and what agents or systems actually do. Those are the places where sourcebook obligations most often break down.
Practitioner takeaway: The strongest control is not a harsher recovery process, but a recoverable one that can adapt to customer circumstances without losing discipline.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org