RevRing
Home
Pricing
Link Hub
Sign In
RevRing

Revenue Acceleration Platform

Link Hub
Florida, USA

Product

  • Predictive Dialer
  • Power Dialer
  • RevRing CRM
  • Lead Management & Routing
  • AI & Automation
  • Analytics
  • Compliance & Security

Industries

  • Insurance
  • Real Estate
  • Legal
  • Healthcare
  • Lead Generation
  • Customer Service
  • More Industries

Integrations

  • CRM
  • Data Sources
  • Productivity
  • API

Learn More

  • Home
  • About Us
  • Pricing
  • Blog
  • Case Studies
  • Lead Marketplace
  • Publishers

Legal

  • Privacy Policy
  • Terms & Conditions
  • Contact Us

© 2026 RevRing. All rights reserved.

support@revring.com
← All articles

Stop TCPA Claims: U.S. Telesales Compliance Checklist With 5 Controls

Agent delivering telesales compliance disclosure

Five controls eliminate most TCPA and TSR exposure: a National Do Not Call Registry scrub run within the last 31 days, prior express written consent for autodialed or prerecorded marketing calls and texts, opt-out capture that hits internal suppression within 10 business days, clear caller identification on every contact, and audit-ready records tying consent to campaign IDs. Everything else in a telesales compliance checklist supports those five pillars. Skip one, and you’ve built your risk exposure into the dial list itself.


TL;DR:

  • Running a recent Do Not Call scrub within 31 days and maintaining an internal suppression file address most compliance risks before dialing begins.
  • Every contact must include caller identification, proper recording disclosures based on state laws, and immediate opt-out processing to ensure compliance during calls.
  • Proper consent records must specify how, when, and through which channel consent was obtained, with retention extending for the duration of the relationship plus several years.
  • Audit-ready documentation requires timestamped scrub logs, signed consent artifacts, policies, training records, and QA notes organized for quick retrieval; manual collection can lead to gaps.
  • Building compliance controls into dialer and CRM systems, such as automatic list gating and consent tagging, is essential to enforce rules consistently and avoid human errors.

Revring
revring.com
Build Compliance Into Every Call
RevRing connects communication tools, CRM systems, AI automation, and compliance functionalities in one tailored revenue infrastructure.
Explore RevRing

Table of Contents

  • What Belongs on Your Telesales Compliance Checklist?
  • Pre-Campaign Controls: List Hygiene, DNC Scrubs, and Suppression Workflow
  • Per-Call Conduct: Scripts, Recording Notices, and AI Voice Rules
  • What Counts as Defensible Consent, and How Should You Store It?
  • What Documents Should an Audit File Actually Contain?
  • How Do State Laws Change Your Calling Rules?
  • How Often Should You Audit Telesales Compliance?
  • Turning the Checklist Into Dialer and CRM Configuration
  • What Compliance Officers Get Wrong First
  • Where to Verify These Rules Yourself
  • Sources
  • FAQ

What Belongs on Your Telesales Compliance Checklist?

A working telesales compliance checklist breaks into three phases: what happens before you dial, what happens during the call, and what you keep afterward. Miss a phase, and the other two won’t save you in an audit.

Here’s the compact version you can pin to a wall or drop into your quality assurance rubric.

Pre-campaign gates (before any number gets dialed):

  • Run a fresh National Do Not Call Registry scrub, dated within 31 days of the campaign’s first dial.
  • Cross-reference the list against your internal master suppression file.
  • Confirm every record’s consent source matches the calling method you plan to use (autodialer, prerecorded voice, live agent, SMS).
  • Verify your seller account number (SAN) subscription covers every area code in the campaign, per Telemarketing requirements.

Per-call requirements (every single contact):

  • Agent states their name, the company they represent, and a callback number within the first 30 seconds.
  • Recording disclosure plays or is spoken where required, particularly in two-party consent states.
  • Script includes a clear, immediate opt-out mechanism the called party can invoke verbally.
  • Call gets tagged in the CRM with consent status, timestamp, and campaign ID at the moment of dial.

Recordkeeping minimums (what you retain and for how long):

  • Dated scrub logs showing registry download date, operator, and campaign association.
  • Signed or timestamped consent artifacts with exact disclosure language shown to the consumer.
  • Training rosters tied to policy version and sign-off date.
  • Quarterly QA sampling notes with remediation actions documented.

Assign an owner to each recurring task. Someone runs the scrub weekly. Someone reconciles the suppression file before every campaign launch. Someone pulls QA samples monthly. Without named owners and deadlines, a checklist becomes a document nobody follows.

Pre-Campaign Controls: List Hygiene, DNC Scrubs, and Suppression Workflow

Compliance failures rarely start on the call. They start with a dirty list that never should have loaded into the dialer. Fixing pre-campaign hygiene closes the majority of exposure before an agent ever picks up the phone.

1. Scrub against the National DNC Registry within 31 days. The Do Not Call Registry requires telemarketers to purge numbers registered there before dialing, and that scrub has to be current, not a leftover file from two campaigns ago. Keep the dated registry download and a log showing when the scrub ran, who ran it, and which campaign it fed. If your dialer platform automates this step, confirm the automation actually blocks stale lists rather than just flagging them.

2. Maintain a master suppression file separate from the registry scrub. This is your internal Do Not Call list, built from every opt-out request, revocation, and complaint your organization has ever received, regardless of which campaign generated it. The TSR treats internal suppression differently from the national registry: it’s your own liability, and it needs to be enforced before any campaign import, not checked afterward. A record that opted out of a real estate campaign in March has no business getting dialed in a legal-services campaign in October if it’s the same phone number and the same seller.

3. Reconcile your seller account number and fee status. The Telemarketing portal governs SAN registration, and the TSR requires most for-profit telemarketers to subscribe to area codes they intend to call, with annual fees tied to that subscription. Confirm your SAN covers the geographic footprint of the campaign before dialing starts. This is one of the most common gaps: growing companies expand into new area codes faster than their compliance team updates the subscription.

4. Map consent sources to contact methods before the list ever touches the dialer, applying best practices from lead-generation flows and landing page practices that can influence consent collection methods. A lead who filled out a web form giving consent for a phone call hasn’t necessarily consented to a prerecorded marketing message or an SMS drip. Tag each record with the consent type and channel it actually covers, then configure the dialer to only run that record through matching campaigns.

5. Assign automation gates that physically block noncompliant imports. The strongest programs don’t rely on a human remembering to scrub. They configure the system so a list can’t load into an active campaign unless the scrub timestamp is within the required window. If your current dialer or CRM doesn’t support that gate, that’s a platform gap worth fixing before it becomes a liability gap.

Pro Tip: Build your suppression file check as a required field, not an optional step, in whatever campaign launch workflow your team uses. If a campaign manager can hit “go” without a passing scrub check, eventually someone will.

Pre-Campaign Controls: List Hygiene, DNC Scrubs, and Suppression Workflow — overview diagram

Per-Call Conduct: Scripts, Recording Notices, and AI Voice Rules

Every live or automated contact carries the same non-negotiable elements, regardless of industry or script length. Get these wrong and no amount of pre-campaign hygiene fixes the exposure.

Caller identification comes first, every time. The agent (or the automated message) must state the caller’s name, the name of the company being represented, and a callback number or address where the consumer can reach that company. This isn’t a nice-to-have script line. Under the TSR’s disclosure requirements, it’s a baseline obligation, and it should happen within the opening seconds of the call, not buried after a pitch.

Recording notices depend heavily on where the called party sits, not where your call center sits. Federal law generally permits one-party consent for recording, meaning the company recording the call knows about it. But roughly a dozen states, including California, Florida, and Illinois, require two-party consent, meaning the person on the other end has to be told and, in some interpretations, has to agree. A recorded disclosure line at the start of the call (“This call may be recorded for quality purposes”) typically covers this in one-party states, but two-party states often require the consumer to have a genuine opportunity to object or hang up before the substantive conversation begins.

Opt-outs need to flow into suppression immediately, not at the end of the shift. When a consumer says “stop calling me” or “take me off your list,” that request has to reach your master suppression file. The TSR gives you a specific window: honor the request within a reasonable time, and internal industry practice (reinforced by TCPA enforcement patterns) treats 10 business days as the outer edge of “reasonable.” Waiting until a weekly batch upload is asking for a violation.

Here’s where prior express written consent (PEWC) becomes mandatory, not optional:

  • Any call placed using an automatic telephone dialing system for marketing purposes.
  • Any prerecorded or artificial voice message used for marketing, including AI-generated voices.
  • Any marketing text message sent via automated platform.
  • Calls to a cell phone for marketing where the consumer hasn’t given clear, written, opt-in consent tied to that specific number.

The FCC has confirmed that TCPA rules apply to AI-generated humanlike voices the same way they apply to traditional prerecorded messages. If your telesales program uses AI voice technology for any outbound marketing contact, treat it exactly like a prerecorded message requiring PEWC. Don’t assume a synthetic voice sits outside existing rules just because the underlying technology is new. That assumption is precisely what the FCC’s guidance shuts down.

Pro Tip: Script your opt-out acknowledgment word for word and require agents to repeat it verbatim: “I’ve noted your request and you will not receive further calls from us.” Ambiguous acknowledgments create disputes later about whether the request was actually heard and processed.

What Counts as Defensible Consent, and How Should You Store It?

Consent isn’t one thing. It’s a matrix, and which type you have determines which calls you can legally make. Confusing these categories is one of the most common (and most expensive) mistakes a telesales program makes.

Prior express written consent (PEWC) is required for autodialed or prerecorded marketing calls and for marketing text messages. It has to be in writing (electronic signature counts), clearly disclose that the consumer is authorizing automated marketing calls or texts, and identify the specific phone number covered.

Oral express consent can cover certain non-marketing autodialed calls, but the moment a call becomes telemarketing, the written standard applies. Don’t rely on a verbal “yes” to justify an autodialed sales campaign.

Established business relationship (EBR) exceptions are narrower than most sales teams assume, and they generally don’t excuse you from PEWC requirements for autodialed marketing. An existing customer relationship might affect Do Not Call registry obligations in limited contexts, but it rarely substitutes for the written consent an autodialer or prerecorded message needs.

A defensible consent record needs specific metadata, not just a checkbox in your CRM:

  • The exact disclosure text the consumer saw or heard at the moment of consent.
  • A timestamp for when consent was captured.
  • The IP address, device identifier, or collection channel (web form, verbal recording, SMS keyword) used.
  • The specific phone number the consent covers.
  • The source URL or campaign ID that generated the lead.

Retention policy should track your state’s statute of limitations for TCPA-adjacent claims, but in practice, most compliance teams keep consent records for the life of the relationship plus several years past the last contact. The record needs to be searchable and exportable in a standard format like CSV, not locked in a static screenshot nobody can query at scale.

Link every consent record to the dialer campaign ID and the call log that used it. When a regulator or plaintiff’s attorney asks for proof of consent on a specific call, retrieval time matters. A program that answers in minutes looks fundamentally different from one that takes days to even locate the right file.

What Documents Should an Audit File Actually Contain?

“Keep good records” is useless advice until you name the files. Auditors and opposing counsel want specific, timestamped artifacts, not a general assurance that your program follows the rules.

1. Dated registry downloads and scrub logs. Each file should show the download date, the operator who ran the scrub, and which campaign the scrub fed. Name your files consistently: something like scrub_2026-03-14_campaignID-4471.csv beats a folder full of files named “final” and “final2.”

2. Signed consent artifacts in exportable format. Every consent record should export to CSV or a similar structured format showing the exact disclosure language, timestamp, and source. If your consent capture tool can’t produce this export on demand, that’s a gap to fix before an audit forces the issue.

3. A written Do Not Call policy, available on request. This isn’t a formality. A documented, consistently enforced DNC policy can function as an affirmative defense in TCPA litigation, but only when it’s backed by training records and evidence you actually follow it. An unsigned policy PDF sitting in a shared drive that nobody can prove agents ever read carries little weight.

4. Agent training rosters with sign-off dates tied to policy versions. When your DNC policy updates, your training records should show which agents completed the updated training and when. A roster from 18 months ago doesn’t cover an agent hired last month.

5. QA sampling notes and call recordings with timestamps. Sampled calls should include reviewer notes on script adherence, disclosure timing, and any remediation triggered by a failed sample.

When you assemble an audit package for counsel or a regulator, organize it in that same order: scrub evidence, consent records, policy documentation, training proof, then QA samples. Auditors expect concrete, timestamped evidence rather than policy assurances, and a package that leads with proof instead of promises moves faster through review.

Pro Tip: Keep a running “audit-ready” folder updated in real time rather than assembling one after a complaint arrives. Reconstructing three months of scrub logs under deadline pressure is how gaps get discovered the hard way.

How Do State Laws Change Your Calling Rules?

Federal rules set the floor, not the ceiling. The TSR generally restricts outbound calls to between 8 a.m. and 9 p.m. in the called party’s local time zone, per the eCFR’s implementing text, but several states narrow that window further, and a handful of municipalities layer on additional restrictions.

Area code is not a reliable proxy for location. Number portability means a consumer with a New York area code might have moved to Arizona years ago and kept the same digits. Determining the called party’s actual location requires matching against address data tied to the lead record, not just parsing the area code prefix.

Watch for these state-level variations as you build campaign rules:

  • Two-party consent states (California, Florida, Illinois, and roughly a half dozen others) require call recording disclosures that go further than the federal one-party standard.
  • Some states impose stricter cell phone contact rules than the federal baseline, particularly around consent revocation timing.
  • Certain municipalities restrict telemarketing entirely on specific dates or holidays.
  • A few states shorten the permitted calling window below the federal 8 a.m. to 9 p.m. standard.

The operational fix is conservative scheduling and geo-targeted campaign rules built directly into your dialer configuration. If your platform can apply time-zone logic based on billing address or verified location data rather than area code alone, use that setting by default. Build script variants for two-party states that include a stronger, more explicit recording disclosure, and route those calls through a distinct campaign flag so agents don’t have to remember state-by-state rules mid-call.

How Often Should You Audit Telesales Compliance?

Quarterly audits catch problems monthly fire drills miss, and they catch them before a regulator does. A reproducible cadence beats a reactive scramble every time.

1. Sample a statistically meaningful set of calls from the quarter. Pull recordings across different agents, campaigns, and times of day, then score them against your script compliance checklist: caller ID, recording disclosure, opt-out language, and overall disclosure timing.

2. Verify scrub evidence for every active campaign. Confirm each campaign’s most recent scrub falls within the 31-day window and that the scrub log ties to the correct campaign ID.

3. Check SAN and fee status against your current area code footprint. Campaigns expand faster than compliance paperwork sometimes catches up, so this check should happen every quarter, not just at renewal time.

4. Run a revocation lifecycle test. Submit a test opt-out request through each active channel (phone, SMS, web form) and time how long it takes to appear in the master suppression file. If it takes longer than 10 business days, you have a process failure to fix immediately.

Track a handful of monitoring KPIs continuously rather than waiting for the quarterly cycle to surface problems:

  • Opt-out closure time: the interval between request and suppression file update. Target well under the 10-business-day ceiling.
  • Scrub lag: days since the last registry scrub for each active campaign. Should never exceed 31.
  • ID misses: the percentage of sampled calls where caller identification wasn’t delivered correctly or in time.
  • Failed QA percentage: the share of sampled calls that fail script compliance review.

When an audit surfaces a gap, document the corrective action with the same rigor you’d want if a regulator asked for it directly: what broke, when it was caught, what changed, and how you verified the fix held on the next sampling cycle.

Pro Tip: Rotate your QA sample across every agent and every active campaign each quarter rather than always pulling from the same easy-to-access recordings. A biased sample tells you your best campaign is compliant while your worst one goes unchecked.

Turning the Checklist Into Dialer and CRM Configuration

A checklist on paper doesn’t stop a noncompliant dial. The controls above only work when they’re built into the systems your agents actually use, not left as a training reminder someone forgets under quota pressure.

Design your master suppression file as a hard gate, not a reference document. Configure campaign imports so a list physically cannot load into an active dial queue unless it has passed a scrub within the required window. If your platform allows a manual override for urgent campaigns, log every override with a name and a reason. A predictive dialer with configurable compliance gates removes the human judgment call from the moment it matters most.

Tag every record with consent status at the time of the call, not after the fact. A record that had valid PEWC in January but received a revocation in February needs its tag updated in real time, and the dialer needs to read that tag before connecting the call, not after. This is where autodialer settings and consent tagging have to work together: an autodialer should never be permitted to dial a record flagged without current PEWC for a marketing campaign.

Automate retention and build a one-click audit export. Your CRM or dialer platform should let a compliance officer pull a complete evidence package, scrub logs, consent records, training rosters, and QA notes, without manually assembling files from five different systems. Consent artifacts linked directly to CRM records and campaign IDs cut retrieval time from days to minutes when a regulator or plaintiff’s counsel asks for proof.

Assign clear ownership across four roles:

  • A compliance owner who maintains the written DNC policy and reviews audit results.
  • A list owner who manages suppression files and consent tagging before any campaign launch.
  • A dialer admin who configures the scrub gates and consent-based dial permissions.
  • A QA lead who runs the quarterly sampling and documents remediation.

Programs that scale agent headcount fast, going from a dozen agents to well over a hundred, tend to lose compliance discipline exactly at the handoff points between these roles. Naming the owner before the growth happens is cheaper than fixing a violation after it does.

What Compliance Officers Get Wrong First

Most telesales compliance programs start with a policy memo. That’s backwards. Policy documents feel productive to write and terrible to defend, because they prove intent without proving execution. What actually holds up under scrutiny is automation: a scrub gate that physically blocks a stale list, a suppression file that updates the moment an opt-out lands, and a consent record that exports in seconds instead of requiring someone to dig through three systems.

The teams I’d trust most run a monthly revocation test, not a quarterly one. Submit a fake opt-out through every channel you use and time how long it takes to surface in suppression. If it’s not near-instant, you have a live liability sitting in your dial queue right now, not a theoretical one. Pair that with a rotating QA sample of call openers, pulled from every agent, not just the easy recordings, and you catch script drift before it becomes a pattern a plaintiff’s attorney can point to across dozens of calls.

The single highest-leverage fix I’d push any compliance officer toward: link consent artifacts to campaign IDs and call logs at the point of capture, not retroactively. Programs that build this from day one answer discovery requests in minutes. Programs that don’t spend weeks reconstructing what should have been a five-minute export.

— Marc

Where to Verify These Rules Yourself

Bookmark these directly. Regulator guidance changes, and vendor summaries (including this one) lag behind official updates.

  • FTC: Complying with the Telemarketing Sales Rule for recordkeeping and seller disclosure obligations.
  • FCC ruling on AI-generated voices and TCPA applicability for AI and prerecorded voice questions.
  • National Do Not Call Registry for scrub operations and registry downloads.
  • Telemarketing portal for SAN registration and fee guidance.
  • eCFR implementing text for calling-hour and procedural TSR rules.

If you want to see how these controls translate into an actual platform rather than a static list, RevRing’s how it works page walks through compliance gating, consent tagging, and audit exports built into the dialer layer. Pricing for the Starter, Scale, and Pro plans starts at $39.99, $59.99, and $89.99 per seat monthly, with a standalone CRM option at $70 per seat monthly for teams that just need the consent and workflow layer without the full dialer stack.

Sources

  • Complying with the Telemarketing Sales Rule
  • FCC confirms TCPA applies to AI technologies that generate human voices
  • National Do Not Call Registry
  • Telemarketing portal (Do Not Call)
  • Electronic Code of Federal Regulations — TSR implementing text

FAQ

How Do You Prepare a Telesales Compliance Checklist?

Start by grouping controls into three phases: pre-campaign (DNC scrub, suppression, consent mapping), per-call (caller ID, recording notice, opt-out capture), and recordkeeping (scrub logs, consent artifacts, training records). Assign an owner and a deadline to each recurring task, then automate the gates you can, particularly list imports and consent tagging, so compliance doesn’t depend entirely on manual checks.

What Are the Major Categories of TCPA Violations?

Common violation categories include calling a number on the National Do Not Call Registry without an applicable exemption, placing autodialed or prerecorded marketing calls without prior express written consent, calling outside permitted hours, failing to honor an opt-out request within a reasonable time, and using an artificial or AI-generated voice for marketing without the consent the FCC requires for prerecorded messages.

What Should a Recordkeeping and Documentation Checklist Include?

A thorough recordkeeping checklist includes dated DNC scrub logs, signed or timestamped consent artifacts with the exact disclosure language shown to the consumer, a written internal Do Not Call policy, agent training rosters tied to policy versions, and quarterly QA sampling notes with documented remediation actions. Auditors and regulators expect these as concrete files, not general policy assurances.

What Are the Core Rules Telemarketers Must Follow?

Telemarketers generally must scrub calling lists against the National Do Not Call Registry within 31 days of dialing, disclose the caller’s identity and the company represented at the start of every call, and obtain prior express written consent before placing autodialed or prerecorded marketing calls, per the FTC’s Telemarketing Sales Rule. Calls must also stay within permitted hours, generally 8 a.m. to 9 p.m. in the called party’s local time, and honor opt-out requests promptly.