← All postsCompliance & Law

Running a Texting Compliance Self-Audit

The best time to find a compliance gap is before a regulator or a plaintiff's lawyer finds it for you. Most gaps are catchable with a straightforward self-audit that any campaign can run in an afternoon. This isn't legal advice, it's a checklist for spotting the obvious problems while they're still cheap to fix.

Can you prove consent for every number?

Pick ten numbers on your list at random and try to answer, for each: how did this number opt in, and when? If you can produce the consent record, source, timestamp, and what they agreed to, you pass. If you're guessing for even one, you have a records problem, and records are the whole ballgame in a TCPA dispute.

Is STOP actually working?

Text STOP to your own program from a test number and confirm it's honored immediately and stays honored, no further messages, ever. Then check your logs: does a STOP suppress the number across every campaign and list, or just the one it was sent to? An opt-out that doesn't propagate everywhere is a live risk.

Are you respecting quiet hours?

Look at your send timestamps against each recipient's local time, not your own. A send fired at 9pm in your zone can already be past the cutoff for a recipient an hour to the east. Confirm your system enforces quiet hours by the recipient's location, and that nothing has gone out in the restricted window.

Are your messages identified and registered?

Check that your messages identify the sender and include opt-out language, that any required "paid for by" disclaimer is present, and that your 10DLC registration is current and matches the traffic you're actually sending. A registration that no longer matches your real use case is a deliverability and compliance risk.

The point of the exercise

None of this requires a law degree. It requires looking, honestly, at whether you can prove consent, honor opt-outs everywhere, respect the clock, and identify yourself. A platform built for political texting handles most of it automatically, but you should still verify, because on the day it matters, "the tool was supposed to" is not the answer you want to give.

Frequently asked questions

What's the fastest compliance check I can run?

Pick ten random numbers and try to produce a consent record for each, source, timestamp, and what they agreed to. If you can't for even one, you have a records gap worth fixing before it becomes a claim.

How do I test STOP handling?

Text STOP from a test number, confirm you get no further messages, and check that the opt-out propagates across every campaign and list, not just the one it was sent to. An opt-out that doesn't apply everywhere is a live risk.

Do I need a lawyer to self-audit?

No. Verifying consent records, STOP handling, quiet hours, and sender identification is something any campaign can do. A lawyer matters when there's an actual claim; the self-audit is how you avoid one.

The self-audit is the cheap version of the demand-letter defense. See what to do when you get a TCPA demand letter.

Keep reading: The complete TCPA guide and quiet hours by state.

TaggedcompliancerecordsTCPAaudit

Every message runs the compliance checks before it leaves.

Get started