TCPA Compliance Checklist for B2B Sales Teams (2026)
Calling other businesses doesn't make you TCPA-exempt. Here's the pre-call, on-call and post-call checklist that keeps B2B outreach legal.
Most B2B sales teams run on a quiet assumption: that calling other businesses puts them outside the Telephone Consumer Protection Act (TCPA). It doesn't, and that misread has cost companies a fortune. Under the TCPA, illegal calls carry statutory penalties of $500 to $1,500 each, and plaintiffs' firms have noticed: class-action filings have spiked to record highs.
The exemption B2B teams lean on is far narrower than the folklore suggests. A cell phone gets the same TCPA protection whether it belongs to a consumer or a VP of Sales. And since the FCC's February 2024 ruling that AI-generated voices count as "artificial" under the statute, any team using AI calling is working under rules that didn't exist two years ago.
This guide is the checklist to replace those assumptions: what you can legally do at each stage of a call, how the AI-calling rules actually work and what a single careless campaign can cost.
Key takeaways
- The B2B "exemption" covers manual calls to verified business landlines. The moment an autodialer, a prerecorded message or an AI voice reaches a cell phone, consent rules apply, no matter whose desk the phone sits on.
- Illegal calls run $500 to $1,500 each under the TCPA, and Do Not Call violations can reach roughly $53,000 per violation under separate FTC enforcement.
- AI-voice calls have needed prior express written consent since the FCC's February 2024 ruling, plus disclosure that the call is AI and a clear way to opt out.
- Screening every number before you dial, by phone type, consent and DNC status, is the difference between scaling outreach and scaling legal exposure.
Why "we only call businesses" won't save you
"I only call businesses, so the TCPA doesn't apply" is one of the most expensive sentences in sales. The FCC's wireless rules are agnostic about who owns the line: a cell phone is protected from autodialed and prerecorded calls whether it's a personal number or a work one.
That distinction trips up B2B teams constantly, because so much of the workforce now runs on personal mobiles. Picture a VP of Operations whose number your data vendor has tagged as a "business contact." The label describes her role, not her line. If that's her personal cell and you hit it with an autodialer or a prerecorded message, you've created a violation, even though everything in your CRM said "B2B." The "business contact" flag tells you nothing about the one thing the law cares about: the type of phone and the technology you used to reach it.
The numbers raise the stakes. More than 253 million phone numbers sat on the National Do Not Call Registry at the end of fiscal year 2024, and every one you dial without consent or a valid exemption is a potential claim.
So what can a B2B team do without consent? Manually dial verified business landlines, including live-agent calls and even prerecorded messages to those landlines, which carry a specific B2B carve-out. What needs prior express written consent first is the automated stuff: any autodialer or prerecorded message to a cell phone, any AI-generated voice call to any number, and any marketing text to a mobile. Read those two lists back to back and the real rule falls out. The exemption was never about whether the person is a "business contact." It's about the phone and the dialer.
The TCPA compliance checklist for B2B sales teams
Before you dial
Most TCPA risk is eliminated before a single call connects. Run every campaign list through these checks first:
- Classify the line. Confirm whether each number is a landline, mobile or VoIP line, because the rules change with the answer.
- Scrub against the national DNC registry and your own internal do-not-call list, so a prior opt-out never gets dialed twice.
- Confirm consent for cells. For any mobile number you intend to autodial or text, verify you have documented prior express written consent.
- Check the clock. Outreach has to land between 8 a.m. and 9 p.m. in the recipient's local time zone, not yours.
- Show a real caller ID. Spoofing a number is itself illegal.
- Flag known litigators. Screen against databases of serial TCPA plaintiffs before they screen you.
This is the work AvairAI's built-in TCPA Compliance Check does automatically. One-click phone classification labels every number CAN_CALL_AI (cleared for automated calling), CAN_CALL_MANUAL (a human can call, automation can't) or CANNOT_CALL (off-limits), so the judgment call is made before the dial, not after the lawsuit. For a faster gut-check on a list you already have, run a five-minute compliance check first.
On the call
- Identify yourself and your company in the opening seconds.
- State why you're calling, plainly.
- Honor an opt-out the instant you hear it. If someone asks off the list, acknowledge it on the spot.
- Avoid dead air. Abandoned calls, where the person answers to silence, are their own violation.
- Disclose AI. If the call uses an AI voice, the recipient has to be told.
After the campaign
- Process opt-outs within 10 business days. Under FCC rules effective April 11, 2025, that's the outer limit for honoring a revocation request.
- Suppress immediately. Add every opt-out to your internal DNC list and sync it across email, calls and texts the same day, so a removal in one channel isn't a re-dial in another.
- Keep your consent records for at least four years, matching the TCPA's statute of limitations.
- Log the activity: who called, when and what was said.
AI calling and the 2024 FCC ruling
On February 8, 2024, the FCC issued a declaratory ruling that AI-generated voices are "artificial" under the TCPA. In practice, an AI-voice marketing call now needs prior express written consent regardless of the number, has to disclose that it's AI, and has to give the recipient a clear way to stop future calls. If you're weighing the technology, it's worth understanding whether AI cold calling is legal at all before you build a program around it.
The short version: AI calling stays legal and useful when it's pointed at the right numbers. US law limits automated and AI calling to warm or pre-approved contacts, so it works as a complement to human outreach, not a cold-outbound channel. That's exactly why classification comes first. CAN_CALL_AI numbers are typically business landlines or contacts who have given documented consent. CAN_CALL_MANUAL numbers need a person's judgment. CANNOT_CALL numbers stay untouched: anyone on the DNC registry, known litigators or anyone who has opted out.
This is where Pair Selling fits the compliance problem cleanly. The AI handles the screening and the legwork; your salespeople spend their hours on legally callable contacts, having the conversations that move deals. For a deeper treatment of the consent framework, the TCPA compliance guide for sales leaders walks through it in detail.
State "mini-TCPA" laws
Federal rules are the floor, not the ceiling. A growing list of states have passed their own "mini-TCPA" statutes, and several are stricter than federal law. Florida's Telephone Solicitation Act, Oklahoma's Telephone Solicitation Act and Maryland's Stop the Spam Calls Act each tighten consent requirements, expand what counts as a regulated call or add their own statutory damages on top of the federal exposure.
The practical move is to build your program around the strictest standard that touches your contact list, not the federal baseline. If one state caps daily call attempts or narrows the calling window below 8 a.m. to 9 p.m., that rule effectively governs how you treat contacts there. Our guide to state mini-TCPA laws breaks down the jurisdictions that matter most.
TCPA compliance for financial services and banks
The rules are the same for a bank as for a software company; the stakes are not. Financial services outreach draws heavier scrutiny, both from the plaintiffs' bar and from sector regulators who layer their own marketing rules on top of the TCPA, think UDAAP for banks and lenders, or FINRA's communications rules for broker-dealers. If your team sells into or operates in financial services, treat this checklist as the floor: keep written consent records you can produce on request, screen against the DNC registry on every list refresh, and log the consent source for every contact you dial. An existing banking relationship does not replace prior express written consent for an AI or prerecorded call to a mobile number.
What one careless campaign can cost
The TCPA's private right of action is what makes it dangerous. Each illegal call or text is its own violation at $500, rising to $1,500 for willful or knowing conduct. Run the math on a 1,000-contact campaign where 10% of the numbers shouldn't have been dialed: 100 violations is $50,000 at the low end, $150,000 if a court finds the conduct willful, from one campaign.
Do Not Call violations sit under a separate regime. The FTC can seek civil penalties of up to $53,088 per violation in 2025, a figure it adjusts for inflation every January, and an intentional robocall violation can draw an additional penalty of up to $10,000 per call under the 2019 TRACED Act.
The real exposure, though, is aggregation. With TCPA class-action filings up roughly 95% in the first half of 2025 versus a year earlier, a single bad practice multiplies across thousands of calls fast. A 2017 federal court ordered Dish Network to pay $280 million for tens of millions of illegal telemarketing calls; more recently, Kaiser Permanente agreed to a $10.5 million settlement over unwanted texts and Truist Bank settled robocall claims for $4.1 million. Because the statute of limitations runs four years, every call your team made over the past four years is potentially in scope. That is why your CFO should care about TCPA compliance as much as your sales leader does.
Compliance is the outreach advantage
Treat compliance as a constraint and it feels like a tax on pipeline. Treat it as a filter and it becomes an edge. Teams that screen every number reach verified contacts at appropriate times through appropriate channels, which is also the outreach people don't hang up on. You stop interrupting the share of the country that asked not to be called, and spend that energy on the contacts you can legally and productively reach.
The hardest part is the one no checklist can do for you at scale: knowing, before each dial, which contacts are safe for automation, which need a human and which are off-limits entirely. That is what AvairAI's TCPA Compliance Check settles on every campaign, classifying each number before any call goes out. The AI keeps the outreach clean and surfaces interested leads; your reps book and close. See how it works, and run your next campaign with the screening built in rather than bolted on.
← Back to all articles

