What Ofgem Enforcement Means for Evidencing PSR Checks
In short
DATS is the AI consulting system from DILR.AI that helps UK energy suppliers place and govern the evidence layer behind Priority Services Register and vulnerable-customer checks, a gap the OVO enforcement exposed. This guide explains what the OVO case suggests a supplier should be able to show, and how a placement-first, audit-ready build is sequenced.
DE
Dilr.ai EngineeringEngineering team
Published Oct 4, 2026Read 13 min
In June 2026 Ofgem closed its investigation into OVO Energy's monitoring of prepayment meter customers with a settlement of a 7 million pound payment to Ofgem's Voluntary Redress Fund and a 3.4 million pound package of credit and debt relief for some of the supplier's most vulnerable customers. The number that matters to a compliance team is not the size of the payment. It is what Ofgem said the supplier had got wrong.
Ofgem's finding was about delivery, not the existence of a policy. It concluded that some customers were not properly identified, supported or kept up to date on the Priority Services Register, and that there was a gap between the supplier's documented processes and how they were delivered in practice. That is the exposure every UK energy supplier now carries. A written Priority Services Register (PSR) policy will pass an internal audit. It will not, on its own, show a regulator that a specific vulnerable customer was identified, acted on and recorded at the moment it mattered.
This guide is for the Director of Customer Operations measured on Ofgem standing, Ombudsman dispute volumes and the public star rating, and for the technology lead who owns the billing platform and the record behind every call. It is about one narrow thing: what enforcement now expects a supplier to be able to evidence, customer by customer, and what a standing, audit-ready evidence layer looks like when it is built deliberately rather than reconstructed under pressure. It does not cover how a voice agent detects vulnerability inside a live call, which is the subject of our guide to voice AI vulnerable-customer detection, nor the wider map of where AI pays across a utility, which sits in AI for utilities in the UK.
This guide is shipped by the team behind DATS, the senior-led AI consulting system from DILR.AI for regulated enterprise, including utilities and energy. Or read how an AI operating model turns governance, RACI and lifecycle into something audit-ready by design.
What did the OVO settlement actually penalise?
The OVO settlement penalised a delivery failure, not a missing policy. Ofgem's investigation concluded that inadequate monitoring of prepayment meter customers, including those on the Priority Services Register, breached rules designed to protect customers in vulnerable situations and exposed them to a clear risk of harm. The outcome was a 7 million pound payment to the Voluntary Redress Fund and 3.4 million pounds of credit and debt relief in lieu of compensation.
Read the decision closely and the pattern is specific. Ofgem described vulnerable customers experiencing self-disconnection who were not provided with the assistance required, and welfare visits that OVO put in place during the investigation for customers who had disconnected for more than 72 hours and not responded to any communication. In Ofgem's words, there was a wider gap between the documented processes and how they were delivered in practice. Cathryn Scott, Ofgem's Director of Market Oversight and Enforcement, put it plainly: "It is clear that OVO fell short in its support of vulnerable PPM customers, and it's right that they've taken action to improve their processes."
This is not an isolated case, which is why it should concern every supplier rather than one. A separate Market Compliance Review of prepayment meter installations across 2022 and 2023 saw eight suppliers, excluding OVO, pay a combined 73.6 million pounds in compensation, debt write-off and hardship payments. Prepayment-meter protection for vulnerable customers has been enforced across the sector, not at one supplier, and the OVO case shows what that enforcement turns on: whether the protection was delivered and can be shown, not whether a policy document exists. A supplier that treats the OVO outcome as OVO's problem is reading it wrong.
Why does a Priority Services Register policy pass an audit but fail in practice?
A Priority Services Register policy passes an audit because an audit usually checks that the policy exists and is approved. It fails in practice because delivery happens one customer at a time, across phone, web and field visits, often in systems that were never designed to prove what was done. The Register is only useful if a customer is identified, the right support is applied and the record survives long enough to answer a regulator months later.
The scale of the underlying gap shows up in the enforcement itself. In the OVO case Ofgem found that some customers were not properly identified, supported or kept up to date on the Register, so identification is not a solved problem before a single system question is asked. Every missed identification is a customer who may later self-disconnect, fall into debt or raise a complaint, and at that point the supplier has to show not that it had a process but that the process ran for that person. The Register obligation binds the supplier, not its technology provider, so the evidence has to live inside the supplier's own systems, under the data-retention rules that govern how long a record is kept, and be produced on demand. Much of that record starts on the phone, which is the subject of our guide to AI voice for utilities.
The same consistency problem shows up in the complaints data, where the Energy Ombudsman has started to score it directly. In 2025 the Energy Ombudsman reported that, on average, suppliers correctly signposted consumers to the Ombudsman in only 48 per cent of cases, with performance ranging from 25 per cent at the weakest supplier to 68 per cent at the strongest, and rising from 44 per cent at the end of 2024 to 55 per cent by the end of 2025. Signposting is a mandatory step, and suppliers still get it right barely half the time. The chart below shows how wide the spread was.
Supplier signposting to the Energy Ombudsman, 2025How often suppliers correctly signposted consumers to the Energy Ombudsman: the 2025 average and supplier range, with the sector average at the end of 2024 and the end of 2025. The Ombudsman scores whether a supplier can evidence that it informed the customer. Source: Energy Ombudsman, Annual data 2025
If a mandatory signpost is delivered only 48 per cent of the time on average, a far more complex obligation like continuous vulnerable-customer support is unlikely to be delivered more reliably without a system that makes the delivery visible.
What does Ofgem expect a supplier to be able to evidence?
Read from its enforcement, Ofgem effectively expects a supplier to show, for an individual customer, that the obligation was met: who was identified as vulnerable, what protection was owed, what action was taken, when, and the outcome. An approved policy answers none of these at the level of one customer. The enforcement pattern is about a real person on a real date, so the evidence has to be specific, timestamped and retrievable.
Set against that standard, the raw material usually exists but the proof does not. The identification sits in a CRM, the call sits in a telephony platform, the meter action sits in a field system and the debt position sits in billing, and no single record ties them to one customer and one obligation. Pulling them into one cited, auditable record is the system problem underneath the compliance one. When the Ombudsman accepted 80,256 cases in 2025, down 14 per cent from 92,938 in 2024 but still a large book, and when billing disputes alone made up 56 per cent of the disputes it reviewed, each one of those cases is a request to reconstruct a history that was never assembled as a history. Reconstruction after a complaint is slow, expensive and, by definition, late.
The handling of vulnerable-customer data is itself a control, not an afterthought. Vulnerability markers and the reasons behind them are sensitive personal data, so the evidence layer has to be lawful under UK data-protection rules as well as useful to a regulator, which rules out bolting on an uncontrolled export or a shared model that moves the data somewhere it should not be, a line our guide to AI voice compliance across the UK and EU develops. The four steps below are where a documented process most often diverges from what actually happened, and each is a point the evidence has to cover.
From a PSR policy to defensible evidenceEach step is a point where a documented process can diverge from what actually happened, and each is where the evidence has to be captured as the work is done.
Why do most of these failures trace to delivery rather than policy?
Most of these failures trace to delivery because the gap opens at volume and under time pressure, not at the policy desk. A supplier can write a correct process and still miss customers when identification depends on an agent remembering to ask, a flag depends on a free-text note, and the follow-up depends on a manual task that nobody owns. The policy is right and the delivery is uneven, which is exactly the pattern Ofgem described at OVO.
The downstream pressure is visible in the public data. Citizens Advice helped more than 52,000 people with an energy billing issue between January and October 2024, about one every two minutes, an 83 per cent increase on the same period in 2020. Each of those is a contact the supplier has to handle and record, and many trace back to an earlier billing or identification step that did not run cleanly. Every one is another record the supplier may later have to produce.
The context makes the stakes higher, not lower. Ofgem has set out plans for a Debt Relief Scheme to help bring down the 4.4 billion pounds of debt in the energy system, which means a large book of accounts whose repayment-arrangement calls each have to be both made and recorded. A supplier scaling that volume of sensitive contact on manual evidence is scaling its enforcement risk at the same rate. This is the operational reality behind the compliance headlines in our AI for utilities guide, and it is why the evidence question cannot wait for the next audit cycle.
Where does an AI build actually help with evidencing, and where does it not?
An AI build helps most with the mechanical, high-volume parts of evidencing: making identification prompts consistent across every channel, capturing a structured record of what was said rather than a free-text note, and assembling a per-customer history that can be produced on demand. It does not, and should not, replace the human decision about whether a customer is vulnerable. That judgement stays with a person, and a sensible build keeps one on every decision that affects a vulnerable customer.
This matters because the evidence tells you where the limits are. Across the market, about 88 per cent of organisations report using AI, yet only around 6 per cent are mature enough to show a material earnings impact, on McKinsey's State of AI reading. The gap between using AI and getting a return is rarely the model. It is whether the governance, the record and the ownership were designed in, which is the same discipline an evidence layer needs and the one our enterprise AI consulting guide sets out. An uncited answer is unauditable, and the same logic applies to a vulnerability action with no record behind it.
Our enterprise AI work names the pieces this draws on. A company knowledge base built from your own documents returns answers with the source cited, so a wrong one traces to a file you can fix rather than a black box you cannot. Where a regulated workload means the model itself has to run inside the supplier's own systems rather than a shared cloud, that is the territory of a private small language model such as Dilr Mira, which runs on your own hardware. The consulting question is which of these belongs where, and that is a placement decision, not a procurement one.
How should a supplier sequence this without a risky big-bang programme?
A supplier should sequence this in stages, because an evidence layer touches identification, telephony, field operations and billing at once, and a single large programme across all of them is how the delivery gap reappears. The sensible order is to diagnose where the evidence actually breaks first, design the operating model that will hold it, then ship narrow production placements that the supplier owns, rather than committing to a platform before anyone has proven where the value sits.
That is how DATS is built. It is a five-stage system from DILR.AI, Discover and Diagnose, Prioritise and Place, Operating Model, Pilot to Production, then Scale and Run, delivered by senior practitioners who ship code rather than decks. The first engagement is a Placement Diagnostic over four to six weeks, which produces a ranked roadmap of where AI belongs and, as importantly, where it does not. The operating-model work then covers governance, RACI and lifecycle so the result is audit-ready by design, the ground that frameworks like the NIST AI RMF formalise. Where delivery follows, an AI execution office is embedded delivery with production placements the supplier owns and a named owner for each ship. The aim is not a large transformation. It is a small number of owned placements where the evidence is built in as the work is done.
What is the best way to close the evidencing gap for a UK energy supplier in 2026?
The best approach depends on where a supplier starts, and an honest answer names where a consultancy is not the right call. A supplier with a mature data and governance function, a single customer record and spare delivery capacity may be better building the evidence layer itself. Large consultancies such as Deloitte, PwC, EY, KPMG and Accenture, or an AI specialist like Faculty, suit a supplier that wants a large, resourced programme and is comfortable with the cost and pace.
The case for a placement-first partner is strongest in the opposite situation: pilots running but nothing governed, data spread across systems that do not talk to each other, and a compliance team that wants to place a defensible evidence layer deliberately rather than commit to a multi-year build. That is the problem DATS is built around, because it diagnoses where AI belongs before anything is built and ships placements the supplier owns rather than a dependency it rents. The quickest way to find out whether that fits is a scoping conversation. Whichever route a supplier takes, the test is the same one Ofgem applied to OVO: can you show, for a named customer on a given date, that the obligation was met. If the honest answer is not yet, the gap is a programme to close now, not a risk to note in the next board pack.
Is the 7 million pound OVO payment a fine?
The 7 million pound figure is a payment to Ofgem's Voluntary Redress Fund, agreed in a settlement alongside a separate 3.4 million pound package of credit and debt relief for affected customers in lieu of compensation. The label matters less than the standard behind it, because the commercial and reputational consequences for a supplier are real either way, which is why the evidencing standard behind the OVO case matters most.
Does the same evidencing standard apply beyond prepayment meters?
It applies to any obligation a supplier has to deliver and then show it delivered, not only prepayment meter monitoring. Vulnerable-customer support, accurate billing, complaint handling and the Priority Services Register follow the same pattern: a documented process, a per-customer delivery, and a record a regulator or the Energy Ombudsman can later ask for. The OVO case is useful because it names the gap precisely, but the evidencing discipline is general across a supplier's Ofgem obligations.
30-min scoping call · No deck · Confidential. We will tell you where your PSR and vulnerable-customer evidence actually breaks, and what it takes to close it.
Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.
Ofgem enforcement evidence energy suppliers UKPriority Services Register compliance evidenceenergy supplier compliance UKvulnerable customer AIai consulting redditbest ai consultancy uk 2026utilitiesdats
Questions this article answers
What did the OVO settlement actually penalise?
The OVO settlement penalised a delivery failure, not a missing policy. Ofgem's investigation concluded that inadequate monitoring of prepayment meter customers, including those on the Priority Services Register, breached rules designed to protect customers in vulnerable situations and exposed them to a clear risk of harm. The outcome was a 7 million pound payment to the Voluntary Redress Fund and 3.4 million pounds of credit and debt relief in lieu of compensation.
Why does a Priority Services Register policy pass an audit but fail in practice?
A Priority Services Register policy passes an audit because an audit usually checks that the policy exists and is approved. It fails in practice because delivery happens one customer at a time, across phone, web and field visits, often in systems that were never designed to prove what was done. The Register is only useful if a customer is identified, the right support is applied and the record survives long enough to answer a regulator months later.
What does Ofgem expect a supplier to be able to evidence?
Read from its enforcement, Ofgem effectively expects a supplier to show, for an individual customer, that the obligation was met: who was identified as vulnerable, what protection was owed, what action was taken, when, and the outcome. An approved policy answers none of these at the level of one customer. The enforcement pattern is about a real person on a real date, so the evidence has to be specific, timestamped and retrievable.
Why do most of these failures trace to delivery rather than policy?
Most of these failures trace to delivery because the gap opens at volume and under time pressure, not at the policy desk. A supplier can write a correct process and still miss customers when identification depends on an agent remembering to ask, a flag depends on a free-text note, and the follow-up depends on a manual task that nobody owns. The policy is right and the delivery is uneven, which is exactly the pattern Ofgem described at OVO.
Where does an AI build actually help with evidencing, and where does it not?
An AI build helps most with the mechanical, high-volume parts of evidencing: making identification prompts consistent across every channel, capturing a structured record of what was said rather than a free-text note, and assembling a per-customer history that can be produced on demand. It does not, and should not, replace the human decision about whether a customer is vulnerable. That judgement stays with a person, and a sensible build keeps one on every decision that affects a vulnerable customer.
How should a supplier sequence this without a risky big-bang programme?
A supplier should sequence this in stages, because an evidence layer touches identification, telephony, field operations and billing at once, and a single large programme across all of them is how the delivery gap reappears. The sensible order is to diagnose where the evidence actually breaks first, design the operating model that will hold it, then ship narrow production placements that the supplier owns, rather than committing to a platform before anyone has proven where the value sits.
What is the best way to close the evidencing gap for a UK energy supplier in 2026?
The best approach depends on where a supplier starts, and an honest answer names where a consultancy is not the right call. A supplier with a mature data and governance function, a single customer record and spare delivery capacity may be better building the evidence layer itself. Large consultancies such as Deloitte, PwC, EY, KPMG and Accenture, or an AI specialist like Faculty, suit a supplier that wants a large, resourced programme and is comfortable with the cost and pace.
Is the 7 million pound OVO payment a fine?
The 7 million pound figure is a payment to Ofgem's Voluntary Redress Fund, agreed in a settlement alongside a separate 3.4 million pound package of credit and debt relief for affected customers in lieu of compensation. The label matters less than the standard behind it, because the commercial and reputational consequences for a supplier are real either way, which is why the evidencing standard behind the OVO case matters most.
DE
Dilr.ai Engineering
Engineering team
Dilr Voice
Voice AI built for your sector
Dilr Voice answers and places calls 24/7 with compliance rules for regulated industries, from clinics and estate agents to financial services.