TCPA Compliance Audit: A 5-Step Guide for Sales Teams
TCPA class-action suits are surging and penalties run $500 to $1,500 per violation. A quarterly audit catches the gaps before they turn into settlements.
A TCPA compliance audit is a structured review of how your team captures consent, screens phone numbers and handles opt-outs, run on a schedule so you catch violations before a plaintiff's attorney does. Most teams skip it until a demand letter shows up. By then the cheapest fix is long gone.
The risk is not abstract. In 2025, more than three out of four TCPA lawsuits were filed as class actions, upward of 1,800 of them, the kind that aggregate thousands of plaintiffs into a single expensive case. Damages start at $500 per call or text and reach $1,500 when a court finds the violation willful. Multiply that across one campaign and the exposure gets real fast.
This guide walks through a five-step audit any sales leader can run each quarter: what to pull, what should raise a flag and where teams slip most often.
Key takeaways
- B2B calling is not exempt. Calls to mobile numbers need consent and DNC screening whether the phone is personal or work.
- Penalties stack per violation. At $500 to $1,500 each, 1,000 bad numbers in a single campaign is $500,000 to $1.5 million in exposure.
- The opt-out clock runs 10 business days. Since April 11, 2025, a revocation has to be honored within 10 business days, across every channel.
- Audit quarterly. A scheduled review surfaces gaps while they are still cheap to fix.
Why TCPA audits matter now
The rules keep moving
A point-in-time check is not enough because the ground keeps shifting. A few changes worth knowing:
Since April 11, 2025, businesses must honor an opt-out within 10 business days of the request, through any reasonable method the recipient uses. The headline "one-to-one consent" rule that would have forced separate consent for each seller never actually took effect; the Eleventh Circuit struck it down in January 2025, so bundled consent remains legal. The revocation rules are still tightening, though, and a broader version is phasing in under which one opt-out has to stop all of a sender's future automated calls and texts, not just the campaign that triggered it.
Federal law is only the floor. State-level mini-TCPA statutes in Florida, Texas, Oklahoma and Maryland layer their own consent and timing rules on top, for any numbers you dial in those states.
The cost is concrete
When an audit fails, the bill is specific. The statute sets damages at $500 per violation and up to $1,500 when the conduct is willful. Those numbers look small until you multiply them. If 1,000 numbers in a 10,000-contact campaign were dialed without proper consent, that is $500,000 to $1.5 million in exposure from one campaign.
Settlements make the point louder. Keller Williams agreed to pay $40 million to resolve robocall and text claims, one of the largest TCPA settlements on record. Kaiser Permanente settled for $10.5 million over marketing texts sent to people who had already replied "stop", a breakdown in opt-out handling that an audit is built to catch. Courts have also named individual executives personally, not just their companies, so this is not a risk a sales leader can quietly delegate.
Your B2B list is not exempt
"TCPA doesn't apply to B2B" is one of the most expensive assumptions in sales, and it is wrong. When you call a mobile number, the law does not care whether it rings on a personal phone or a work phone, and prerecorded or autodialed calls to cell phones need prior express consent either way.
Consider the scale of it. More than 253 million phone numbers sit on the FTC's National Do Not Call Registry. Your B2B contact list is full of them. Treating business outreach as a compliance-free zone is how a clean-looking campaign turns into a demand letter. For the full set of requirements, our TCPA compliance guide for sales leaders covers them in depth.
The five-step TCPA audit
A useful audit covers five areas that tend to fail together: consent, DNC screening, calling practices, opt-out handling and AI calling. Here is what to pull, and what should make you nervous.
Step 1: Audit your consent records
Start with proof. Pull records for recent campaigns and confirm you can actually produce, on demand:
- the written consent itself, in clear and specific language
- a timestamp for when each consent was captured
- the disclosures shown at sign-up, including message frequency, cost and how to opt out
- consent documentation for any contacts you bought from a third party
Specificity is where most teams come up short. Consent to email is not consent to call. Consent to hear from your company is not consent to hear from its affiliates. If your forms bundle everything into one vague checkbox, or you cannot retrieve a given record within a day, you have a gap a plaintiff's lawyer will find before you do.
Step 2: Verify your DNC screening
Screening means checking several lists, not one. Confirm your process scrubs against the national registry before every campaign launch, not on a monthly cron that lets stale numbers slip through. Layer in the state registries for every state you call into, since several maintain their own. And keep an internal record of everyone who has ever asked you to stop, honored for at least five years; here is how to run an internal do-not-call list that holds up.
One more check teams forget: professional litigators seed their own numbers into purchased lists on purpose, hoping you will dial them. Screen against known-litigator databases before you call any list you did not build yourself.
Step 3: Review your calling practices
Two things matter here, when you call and how you call.
The TCPA limits telemarketing calls to between 8 a.m. and 9 p.m. in the recipient's local time. That means your system has to know each contact's time zone and actually enforce the window, holidays and weekends included. Document how you determine that time zone, because "we assumed from the area code" is not a defense.
If you run any kind of automated dialer, confirm the abandoned-call rate stays under the 3% threshold, that recordings carry the required disclosures, that caller ID shows accurate information and that the dialer is configured to avoid wireless numbers you do not have consent to reach.
Step 4: Test your opt-out process
Reviewing this one on paper is not enough. You have to run it. Submit a real opt-out through every channel you offer, phone, email and SMS, then confirm three things: the request suppresses the contact within the 10-business-day window, the suppression syncs across every active campaign rather than one channel at a time, and the contact stops hearing from you, full stop. Every opt-out should land with a timestamp you can produce later.
This is the exact failure that cost Kaiser its settlement, so it deserves more than a glance.
Step 5: Assess your AI calling
In February 2024 the FCC declared that AI-generated voices count as "artificial" voices under the TCPA, which puts them squarely under the consent, disclosure and opt-out rules that govern any prerecorded call. If AI calling is anywhere in your stack, it is worth understanding the legal rules around AI calling first. Your audit should then verify prior express consent for every AI call, a clear identification disclosure at the top of the call, a working opt-out and an accurate list of which contacts are even eligible.
This is also where the right platform carries the load. AvairAI treats AI calling as a secondary, compliance-gated capability for warm or opted-in contacts, never cold dialing at scale. Its one-click phone classification sorts every number into CAN_CALL_AI, CAN_CALL_MANUAL or CANNOT_CALL before a single call is placed, with a full audit trail behind each decision. For the mechanics, see how AvairAI classifies every number and our ultimate guide to AI cold calling.
Turn audits into a habit
A one-time audit is a snapshot, and compliance is a moving target, so put this on a calendar.
Each quarter, pull a random sample of consent records, re-verify your DNC screening, measure how fast opt-outs are actually processed and review any complaints from the period. Write the findings down and assign an owner to each gap, because an audit with no follow-up is just paperwork. Once a year, bring in an outside reviewer. A third party catches blind spots your team has learned to look past, and their report doubles as evidence of good-faith effort if a complaint ever lands.
The teams that stay out of trouble treat this as culture, not a checkbox. Here is how to build a compliance culture that sticks, and why your CFO already tracks this exposure more closely than you might expect.
The payoff
Done right, a TCPA audit stops being a chore and starts paying for itself. Compliant outreach earns more trust, avoids the settlements that drain a quarter and lets your team prospect without looking over its shoulder.
The five steps are easy to remember: check consent, verify your DNC screening, review your calling windows and dialer, test opt-outs end to end, and confirm your AI calling is consented and disclosed. Run them quarterly and most gaps surface while they are still cheap to fix.
This is also where building compliance in beats bolting it on. AvairAI runs a built-in TCPA Compliance Check, DNC plus calling-window screening, on every campaign, classifies phone numbers in one click and keeps the audit trail for you. The AI handles the prospecting grind and sends the email; your reps make the calls and close the business. That is Pair Selling, and a platform that documents consent is a lot easier to defend than a spreadsheet you hope is current. Start a 14-day free trial, no credit card required, and see what compliant outreach feels like.
← Back to all articles

