CampaignsHow It WorksIndustriesResultsInsightsPlan My Campaign
Provider Evaluation Criteria

What are the top 10 business rules?

Back to InsightsWhat are the top 10 business rules?

What are the top 10 business rules?

Key Facts

  • TCPA class-action filings increased 95% year over year, signaling heightened regulatory scrutiny.
  • according to industry tracker
  • Aggregate TCPA verdicts exceed $925 million across the docket, reflecting massive financial exposure.
  • per industry analysis
  • A 100,000-call campaign with systemic consent deficiency risks $50–150 million in statutory damages.
  • per risk exposure example
  • TCPA statutory damages range from $500 to $1,500 per violation, with willful violations up to $1,500.
  • per legal analysis
  • Businesses must honor revocation requests within ten business days through any reasonable method.
  • per TCPA Opt-Out Rule
  • Opt-out documentation should be retained for at least four years to defend against TCPA litigation.
  • per legal guidance
  • AI-generated voices are treated as 'artificial voices' under TCPA, requiring prior express consent for U.S. cell calls.
  • per FCC February 2024 Declaratory Ruling

Why Outbound Compliance Failures Are a $10M+ Problem

Outbound compliance failures represent a significant financial threat, with TCPA statutory damages ranging from $500 to $1,500 per violation and class actions routinely exceeding $10 million in settlements. A single 100,000-call campaign with systemic consent deficiency could trigger $50–150 million in potential statutory damages, demonstrating how scale rapidly multiplies exposure when consent management breaks down. This risk is amplified by a 95% year-over-year increase in TCPA class-action filings, signaling heightened regulatory scrutiny and litigation activity.

The root cause of most compliance failures is indiscriminate dialing — calling numbers without verified consent or proper list hygiene. Under the TCPA, AI-generated voices are treated as "artificial voices" requiring the same prior express consent as traditional autodialed calls, meaning any outbound AI call to a U.S. cell phone needs clear authorization before dialing. Businesses must honor revocation requests within ten business days through any reasonable method, including text, email, voicemail, or verbal communication, and send only one clarification message within five minutes if needed — containing no marketing or promotional content. Opt-out documentation should be retained for at least four years to defend against litigation, as the TCPA statute of limitations spans four years (with seven years recommended by defense counsel for retention).

  • Implement tiered consent frameworks distinguishing between marketing (requiring prior express written consent) and informational calls (prior express consent)
  • Track the local time zone of every number dialed, applying the most restrictive applicable rule (e.g., FL, OK, WA: 8 AM–8 PM; OK: max 3 calls per number per 24 hours)
  • Maintain auditable records of consent language, date, capture method, DNC scrub dates, and campaign settings
  • Designate a TCPA compliance officer with authority to halt non-compliant campaigns
  • Verify AI voice compliance requirements and obtain new direct consent for skip-traced or third-party-sourced numbers where provenance cannot be verified

For organizations running managed outbound campaigns, list discipline is non-negotiable. My AI Call Center ensures only approved, permissioned, or reviewed lists are used — checking consent records and list sources before any campaign launches. Bought lists without clear permission records are flagged and typically declined, with plain feedback provided upfront so clients never spend on non-compliant outreach. This approach aligns with the core principle that undisciplined consent management — not the technology itself — creates risk, and that documentation is decisive in TCPA litigation. By focusing on structured, goal-driven calls against verified lists, businesses can scale outreach without scaling exposure.

Compliance is not a suggestion in outbound calling — TCPA class-action filings are up 95% year over year, with aggregate verdicts exceeding $925 million across the docket. If you run outbound campaigns, these ten rules separate structured programs from lawsuits waiting to happen.

1. Call only approved, permissioned, or reviewed lists. Where list provenance cannot be verified, compliance guidance is blunt: consent should not be presumed — obtain new, direct consent before dialing. Providers like My AI Call Center check list source and consent records before any campaign launches for exactly this reason.

2. Match consent tier to call purpose. Marketing calls require prior express written consent; informational and transactional calls need prior express consent. The distinction matters because regulators assess purpose, not your opening sentence.

3. Treat AI voices as artificial voices. The FCC's February 2024 Declaratory Ruling makes no carve-out for conversational AI — any human-sounding generated voice falls under the TCPA and needs the same consent as autodialed calls.

4. Disclose AI on every call. One sentence in the first 30 seconds satisfies most jurisdictions: identify the AI assistant, the company, and the recorded line.

5. Honor opt-outs within 10 business days — by any reasonable method. Under the TCPA's Opt-Out Rule, effective April 11, 2025, consumers may revoke consent via text, email, voicemail, or verbally. The burden of proving a method unreasonable falls on the business.

6. Respect STOP and REVOKE keywords immediately. Any delay between withdrawal and suppression is a risk you are choosing to carry — keywords like stop, quit, and revoke are definitively reasonable.

7. Call only 8 AM–9 PM in the recipient's local time. Track the called party's time zone, not your contact center's, and apply the most restrictive applicable state rule — Florida, Oklahoma, and Washington cap calls at 8 PM, and Oklahoma limits three calls per number per 24 hours.

8. Scrub against DNC and reassigned-number databases. The National DNC Registry holds over 250 million numbers, and the Reassigned Numbers Database requires scrubbing at least every 59 days without right-party contact.

9. Keep auditable records for four-plus years. The TCPA statute of limitations runs four years, and defense counsel recommend seven. In TCPA litigation, documentation is decisive — consent language, capture method, dates, and opt-out logs.

10. One clear goal per campaign. An "account check-in" that pivots to an upsell is marketing — and the FCC assesses purpose, not intent. Never let an informational call drift into promotion.

The stakes scale with volume: a 100,000-call campaign with a systemic consent deficiency represents $50–150 million in potential statutory damages. Structure every campaign around one outcome, verify consent before launch, and log everything.

How to Put the Rules into Practice Before You Dial

Knowing the rules is one thing. Running a campaign that survives a subpoena is another — and the difference comes down to what you verify before the first call goes out.

Start with the list itself. Where did these numbers come from, and can you prove it? As one consent whitepaper puts it bluntly, where any element of consent cannot be verified, consent should not be presumed. A bought list with no permission records isn't a gray area — it's a liability you're choosing to carry. A single 100,000-call campaign with a systemic consent deficiency can expose a business to $50–150 million in statutory damages. Decline lists without clear provenance, and say so before a dollar is spent. That's the standard My AI Call Center applies: list source and consent records are checked before any campaign launches, and lists without clear permission records are flagged — in most cases, declined.

Next, approve the script, disclosures, and escalation path before launch. Under the FCC's February 2024 ruling, AI-generated voices count as "artificial" voices under the TCPA, so the disclosure that the call is AI-assisted — plus opt-out handling and a path to a human — needs sign-off, not improvisation. Nothing should launch until you've approved exactly what will be said.

Once calls run, close the loop:

  • Route every outcome back into your CRM with disposition codes — confirmed, qualified, renewed, opted out, no answer — so follow-ups land with the right team.
  • Log opt-outs immediately and honor them across all campaigns; businesses must process revocations within ten business days, and any delay between withdrawal and suppression is risk you carry.
  • Retain opt-out and DNC documentation for at least four years — in TCPA litigation, documentation is decisive, not intent.

Finally, understand your vendor chain. The entity on whose behalf the calls are made bears liability — regardless of which vendor pressed dial. The $19 million QuoteWizard settlement stands as a reference point for how vendor-chain exposure plays out in court. Hiring a dialer doesn't transfer legal risk; it concentrates it on you.

That's why provider evaluation matters as much as campaign design. Ask any provider what they check before launch, what they log after, and who approves the script. If the answer is "you handle compliance," you've found the wrong vendor — because under the TCPA, you're the one on whose behalf every call is made.

How a Managed Campaign Partner Handles Compliance for You

Outbound campaigns face layered compliance risks that can quickly escalate costs and reputational harm. My AI Call Center manages these complexities by embedding regulatory requirements directly into every campaign launch and execution, so you don’t need to build internal expertise or infrastructure to stay protected.

Before any campaign begins, we conduct a thorough list and consent review to verify that contacts are approved, permissioned, or reviewed — never indiscriminately sourced. This step flags lists lacking clear permission records and prevents launch if compliance gaps exist. We honor state-specific quiet hours by applying the most restrictive applicable rule per dialed number based on the recipient’s state, ensuring calls only occur within legal windows like the federal 8 AM–9 PM standard or stricter state limits. Every call includes an AI disclosure upfront, and keyword opt-outs like STOP or REVOKE are honored immediately and logged into your DNC records across all campaigns.

We also lock rates for the full campaign duration and never invent numbers, testimonials, or metrics — reporting only what actually occurred during the call. These controls align with TCPA requirements for AI-generated voices, which the FCC treats as artificial voices requiring prior express consent, and with opt-out rules mandating revocation processing within ten business days through any reasonable method. By managing compliance end-to-end, we reduce your exposure to statutory damages that can reach $500–$1,500 per violation and help avoid class-action risks that routinely exceed $10 million in settlements.

Plan a compliant campaign from 9¢ per connected minute.

Frequently Asked Questions

Do I really need consent if my AI calls just sound like a normal person?
Yes. The FCC's February 2024 Declaratory Ruling makes no carve-out for conversational AI — any human-sounding generated voice counts as an "artificial voice" under the TCPA and needs the same prior express consent as autodialed calls. Every outbound AI call to a U.S. cell phone requires clear authorization before you dial. Source
How much could a compliance mistake actually cost my business?
TCPA statutory damages run $500 to $1,500 per violation, with class actions routinely exceeding $10 million in settlements — and filings are up 95% year over year. A single 100,000-call campaign with a systemic consent deficiency could represent $50–150 million in potential statutory damages, so scale multiplies exposure as easily as it multiplies efficiency.
Can I keep using a purchased lead list if I'm not sure where the numbers came from?
No — where any element of consent cannot be verified, consent should not be presumed, and you should obtain new, direct consent before dialing. A bought list without permission records isn't a gray area; it's liability you're choosing to carry. That's why My AI Call Center checks list source and consent records before any campaign launches and declines lists without clear provenance. Source
How quickly do I have to honor an opt-out, and does it have to be the word STOP?
Under the TCPA's Opt-Out Rule effective April 11, 2025, consumers may revoke consent in any reasonable manner — text, email, voicemail, or verbally — and you must honor it within ten business days. The burden of proving a method unreasonable falls on the business, so keywords like stop, quit, and revoke are definitively reasonable. If you send a clarification message, it must go out within five minutes, only once, with no marketing content. Source
If I hire a calling vendor or dialer, doesn't the compliance risk shift to them?
No — the entity on whose behalf the calls are made bears liability, regardless of which vendor pressed dial. The $19 million QuoteWizard settlement is a reference point for how vendor-chain exposure plays out in court. Ask any provider what they check before launch, what they log after, and who approves the script — if the answer is "you handle compliance," you've found the wrong vendor.
What records do I need to keep, and for how long?
Keep auditable records of consent language, capture method, dates, opt-out logs, and DNC scrub dates for at least four years — the TCPA statute of limitations runs four years, and defense counsel recommend seven. In TCPA litigation, intent is secondary but documentation is decisive. You should also scrub against the National DNC Registry (over 250 million numbers) and the Reassigned Numbers Database at least every 59 days without right-party contact. Source

Compliance Is the Strategy — Not the Obstacle

The ten rules in this article all trace back to one principle: verify consent before you dial, and document everything after. With TCPA class-action filings up 95% year over year and statutory damages of $500 to $1,500 per violation, a single campaign run against an unverified list can turn a growth channel into an existential liability. The technology isn't the risk — undisciplined consent management is. Your next steps are practical: audit your current lists for provenance, match every campaign to a single clear goal, confirm your opt-out handling meets the ten-business-day standard, and ask any provider you work with what they check before launch and what they log after. If their answer is "you handle compliance," keep looking. My AI Call Center builds these checks into every managed campaign — list and consent review before launch, approved calling windows, immediate opt-out logging, and outcome reports with no invented numbers. If you want outbound calls that confirm, qualify, and retain without scaling your exposure, plan a compliant campaign from 9¢ per connected minute — the first campaign review is free.

Get campaign planning tips