Skip to main content

TCPA Risk Framework: How to Assess Any Sales Technology

TCPA class action filings jumped about 95% in 2025. Here's a three-tier framework to assess any sales technology's compliance risk before you buy, renew or deploy it.

Tcpa Risk Assessment Sales TechnologyTcpa Compliance Checklist Sales SoftwareTcpa Risk Factors B2B SalesSales Technology Compliance FrameworkTcpa Dialer Compliance
Pintu Kumar
Pintu Kumar 8 min read
Share this post
TCPA Risk Framework: How to Assess Any Sales Technology

TCPA class action filings jumped about 95% year over year in 2025, with 507 of them landing in the first quarter alone. Most sales leaders still have no structured way to judge whether the technology they buy puts their team in that line of fire. They trust the vendor's pitch, assume legal will catch anything dangerous and launch the campaign anyway.

That worked when penalties were rare. It stopped working the moment plaintiffs' attorneys turned outbound calling into a cottage industry. Before you buy, renew or deploy any sales technology that touches the phone, you need a repeatable way to assess its TCPA risk. This article gives you one: a three-tier framework covering dialing technology, consent management and list hygiene, plus the exact questions to put to a vendor before you sign.

Why vendor risk is the decision that matters now

The growth in litigation is not subtle. TCPA class action filings reached 1,052 through the same point in 2025 where 2024 had seen 539, and Q1 2025 alone more than doubled the class action volume of Q1 2024. Counting every TCPA suit, not just class actions, filings ran more than 50% ahead of the prior year.

The regulatory backdrop is tightening in step. Since April 11, 2025, businesses must let consumers revoke consent by any reasonable means and process an opt-out within 10 business days, down from the old 30-day norm. A further provision, effective April 11, 2026, broadens the reach of a revocation so a single opt-out applies to a sender's future messages, not just the campaign that triggered it. The much-discussed "one-to-one consent" rule that would have required separate consent for each seller never took effect, because a federal appeals court vacated it in January 2025. The direction of travel is clear: less room for error, every year.

What a violation actually costs

Damages under the TCPA are statutory, which is what makes them dangerous. A plaintiff can claim $500 per illegal call or text, and up to $1,500 if the violation is willful, with no ceiling on how many calls a class can stack up. Separate from private suits, the FTC enforces the Do Not Call rules under the Telemarketing Sales Rule, where penalties now run up to $53,088 per call.

These are not theoretical numbers reserved for fly-by-night operators. A federal court ordered Dish Network to pay $280 million, the largest Do Not Call penalty on record, for calls its retailers made. Caribbean Cruise Line settled a robocall class action for up to $76 million. Both companies had lawyers. Both lost.

And liability does not stop with whoever places the calls. The FCC and FTC have held dialing-platform vendors directly responsible for violations, and courts have been clear that a provider cannot simply point at its customers. If the technology you license has weak compliance controls, the exposure is shared, which is exactly why the financial and reputational fallout is worth understanding before you commit.

The three-tier TCPA risk framework

Every calling tool carries risk in three places: how it dials, how it captures and proves consent, and how clean its lists are. Score a vendor on all three and the gaps show up fast.

Tier 1: dialing technology

The dialing method sets your baseline risk, and the categories are not interchangeable. An automatic telephone dialing system (ATDS) stores or produces numbers using a random or sequential generator and dials them without a human in the loop; using one to call or text a wireless number without prior express written consent is illegal, and there is no blanket B2B carve-out for it. A sales auto-dialer that walks down a list but waits for a person to start each call is a different animal, lighter on risk, though it still needs disciplined consent and timing controls. AI calling sits in its own category. The FCC ruled in February 2024 that AI-generated voices count as "artificial" voices under the TCPA, so AI cold calling now carries the same consent, disclosure and opt-out obligations as any prerecorded robocall.

Before you trust a platform's dialer, get clear answers on:

  • Does it meet the current FCC definition of an ATDS?
  • If it uses AI voices, does it build in the required identification and disclosure?
  • Does it require a human to initiate each call, or fire automatically?
  • Does it enforce the federal calling window of 8 a.m. to 9 p.m. in the recipient's local time?

Tier 2: consent management

Consent is where most teams discover, too late, that they cannot prove what they claimed. Prior express written consent (PEWC) is the high bar: a written, signed agreement, required for most marketing texts, prerecorded messages and auto-dialed sales calls to mobile numbers. The consent request itself has to name the business, the purpose, the frequency and any charges.

The harder question is documentation. If a plaintiff's lawyer demands proof of consent for one specific number two years from now, can the platform produce it, tied to that individual contact, with a timestamp? A tool that stores consent as a vague account-level flag will not survive that test. Speed matters too. Under the 2025 rules an opt-out has to be processed within 10 business days, and from April 2026 a single revocation reaches all of a sender's future messages. Your technology has to capture, route and honor those requests automatically, because doing it by hand at any volume is how numbers slip through.

Questions worth pressing:

  • How does it document and store consent, and is each record tied to the individual contact?
  • Could you produce proof of consent for any single number if challenged in court?
  • How fast does it process an opt-out, and is that automatic?

Tier 3: list hygiene

Clean dialing technology and airtight consent still will not save you if the underlying data is dirty. More than 258 million phone numbers now sit on the National Do Not Call Registry, and each call to a registered number can draw that FTC penalty of up to $53,088. Any serious platform scrubs against the national registry before a campaign goes out, not as an afterthought.

Reassigned numbers are the quieter trap. People change numbers constantly, and the carrier hands the old one to someone new. Picture a prospect who opted in 18 months ago, then switched carriers and gave up the number; it now belongs to a stranger who never agreed to anything. Call them on the strength of the old consent and you have a fresh violation on your hands. Good tools check for reassignment. Most do not.

There is also your own list to keep. The FCC requires every business to maintain an internal do-not-call list and a written policy for it, so your technology has to let you record, store and enforce an internal do-not-call list across every campaign.

Questions worth pressing:

  • Which DNC sources does it scrub against, and how often, real-time or batch?
  • Does it detect reassigned numbers?
  • Can you maintain and enforce an internal do-not-call list inside the tool?

The AI calling question

AI calling deserves its own scrutiny, because the rules caught up with it fast. In its February 2024 declaratory ruling, the FCC confirmed that an AI-generated voice is an "artificial" voice under the TCPA. In plain terms: every AI voice call to a consumer needs prior express consent, the AI has to identify itself as artificial, and an opt-out path has to be built in. There is no AI exemption. And because US law sharply limits automated calling, AI voice belongs on warm or opted-in contacts, never cold lists. If you are weighing a tool that promises autonomous AI dialing at scale, it pays to understand the compliance gaps that hide inside AI sales platforms before you believe the demo.

A few questions separate a compliant AI calling vendor from a lawsuit waiting to happen:

  • How does it verify consent before each AI call?
  • What disclosure language is written into the scripts, and does the AI identify itself up front?
  • How are opt-outs captured and processed mid-call?
  • What happens to a contact the system flags as unsafe to call with AI?

If a vendor cannot answer those cleanly, assume the gaps are real and priced into your risk, not theirs.

The vendor checklist

Once you understand the three tiers, the buying conversation gets simpler. Treat the questions below as a single pass before any sales technology with calling capability gets near your contacts. It is the same discipline you would bring to evaluating any AI sales platform: make the vendor prove it, do not take the claim at face value.

  • Liability and proof. Does the vendor accept any compliance liability, or is it all shifted to you in the contract? What documentation do they provide? Have they been sued under the TCPA, and how did it end?
  • DNC and scrubbing. Which databases do they scrub against, how often, and is the scrub automatic before a campaign launches?
  • Consent and controls. How is consent stored and proven? Can you flag contacts that carry PEWC? Are calling hours enforced automatically, by day and by holiday?
  • AI specifics, if relevant. Does the AI disclose itself, what disclosure scripts ship by default, and how are AI-unsafe contacts handled?

Some answers should end the conversation. Be wary of any vendor who claims B2B calls are flatly exempt, offers no way to document consent, has no DNC scrubbing, leaves calling hours unenforced, cannot explain its AI disclosure, or shifts every ounce of liability to you while handing over no tools to manage it.

How AvairAI handles each tier

AvairAI was built around this framework rather than bolted onto it. The TCPA Compliance Check runs on every campaign, and the design choice underneath it is simple: make the safe path the default. (The mechanics behind AvairAI's TCPA compliance system go deeper than we can here.)

Before a single call, AvairAI classifies every contact into one of three states: green for safe to call with AI, yellow for human judgment required, red for legally off-limits. That one check runs the contact against the national DNC registry, screens for known TCPA litigators, verifies the line type and looks for reassigned numbers. If you want the full requirements behind each state, our complete TCPA compliance guide for sales leaders walks through them.

Compliance then rides inside the campaign instead of sitting in a separate checklist. Lists are scrubbed automatically before launch and re-screened weekly while a campaign runs. Calls are held to a conservative 10 a.m. to 4 p.m. window in the recipient's local time, tighter than the law's 8 a.m. to 9 p.m. ceiling. AI disclosure is written into the scripts, and any contact that needs a human goes into a Manual Task queue for a rep to handle.

That last point is where Pair Selling meets compliance. The AI does the part that is mechanical and unforgiving, the scrubbing, the classification, the timing and the disclosure. Your reps spend their time on the part that needs a human: working the contacts who engage, building the relationship and closing. AvairAI fills the pipeline with interested leads; your salespeople book and close them. Compliance at scale stops being a tax on selling.

Make the call before the lawyers do

The 95% jump in TCPA class actions is not a blip, and your choice of technology is the first and largest compliance decision you will make. The right tool turns compliance into something that happens automatically in the background. The wrong one turns every dial into a potential filing.

Run your current stack through the three tiers. Check the dialing technology, press hard on consent management and proof, and look closely at list hygiene and DNC scrubbing. Where a vendor cannot show you how it covers each one, you have found your risk, and probably your next vendor search.

The teams that build compliance into their sales technology now are the ones that will keep selling through the litigation wave instead of settling their way through it. That is the quiet advantage of Pair Selling done right: the machine carries the rules, so your people can carry the conversations.


← Back to all articles
Pintu Kumar

About Pintu Kumar

Co-founder & Director of Product Operations, AvairAI

Pintu Kumar is a co-founder and Director of Product Operations at AvairAI, where he turns product vision into reliable execution — designing the operational frameworks, quality processes, and go-to-market readiness that keep the company’s AI-driven prospecting workflows scalable and dependable. He brings 22 years at enterprise-integration company Adeptia, advancing from System Administrator to Senior Manager of Software Quality Assurance and owning QA strategy, release management, and DevOps/Kubernetes practices across mission-critical software. At AvairAI he coordinates cross-functional teams, defines process KPIs, and leads onboarding and adoption strategy. His expertise sits where software quality, DevOps, and product operations meet — ensuring AI agents perform consistently in production. He holds an MCA and BCA in Computer Science and a PGDM in management.

More from Pintu Kumar →

See what AvairAI builds from your website

Never sell alone.

14-day free trial · no credit card · see it in ~3 minutes

Prefer to browse first? Grab a free outreach template Start for free