AI Calling Compliance Planning Checklist for Brokers
Plan a compliant AI calling campaign for a brokerage: consent, US TCPA setup, MiFID II recording, data retention, cross-border rules and who signs off.
- Who it is for
- Broker ops leads, compliance officers and DPOs preparing an AI outbound calling campaign to dormant traders or old leads.
- Time to complete
- 60 minutes plus sign-off meetings
This checklist walks a brokerage through the compliance questions that have to be answered before an AI voice agent dials a single dormant trader. It covers consent and lawful basis, US numbers under the TCPA, call recording under MiFID II, data retention and deletion, and what changes when the list spans several countries. Work through it with your compliance officer and you'll finish with a campaign setup, a named approver for each section and a paper trail an auditor can follow. It tells you what to review and who decides, not what the law concludes.
Consent and lawful basis
Dormant traders signed up months or years ago. Before anyone dials, find out what they agreed to at the time and whether it still covers a marketing call from an automated voice.
Pull the consent record for every account on the list: what was ticked, when, and on which form version.
A checkbox from an old registration form is still your evidence, but only if you can produce the wording. If the CRM stores a yes/no flag and nothing else, get the form text from marketing or the platform vendor and file it with the campaign.
Split the list by lawful basis: explicit marketing consent, existing client relationship, or none found.
Under GDPR a marketing call needs a lawful basis you can name. A funded client and a lead who never passed the deposit page rarely share one, so they shouldn't share one campaign setup either.
Decide with compliance whether a call to a funded but inactive client is marketing or account servicing.
A KYC reminder or a dormancy fee notice is usually servicing. "Come back and trade" is a promotion. The answer changes the consent bar, the script and the opt-out rules, so get it in writing.
Check that consent was given to the legal entity that will make the call.
Brokers move clients between entities when licences change. Consent collected by the old entity may not carry over. Ask counsel before assuming it does.
Remove every account that opted out of marketing on any channel, at any time.
A trader who unsubscribed from email has told you something about phone calls too. GDPR gives an absolute right to object to direct marketing, and the safer reading treats that objection as channel-neutral.
Agree a maximum age for consent and drop every record older than it.
There is no single legal number. Set one with your compliance officer and apply it the same way to every list, so nobody argues about a 2019 lead in the middle of a campaign.
____ months
Confirm the opening line names the brokerage, says the voice is an AI agent and states why it's calling.
Disclosure belongs in the first sentence, not after the pitch. The disclosure checklist covers exact wording; here you only confirm it's in the approved script.
Confirm with your compliance officer or counsel that the consent basis covers an automated voice call as well as a call from a human agent.
Some consent wording covers "calls" in general; some names a channel or a method. The difference matters most for US numbers, which the next section covers.
US numbers and TCPA setup
If one +1 number is on the list, this section applies. The FCC has said AI-generated voices count as artificial voices under the TCPA, so plan for the stricter consent rules that apply to prerecorded and artificial-voice calls.
Count the +1 numbers on the list and decide whether to call them at all.
Many CFD brokers aren't permitted to solicit US residents in the first place. If your licence doesn't allow it, suppress the whole segment and skip the rest of this section.
____ US numbers
Locate prior express written consent for every US number that will hear a marketing message.
For marketing calls using an artificial or prerecorded voice, the TCPA's consent standard is written consent that identifies the caller and covers automated calls. A generic "I agree to be contacted" line probably doesn't meet it. Counsel decides.
Scrub the list against the National Do Not Call Registry and your internal do-not-call list.
Record the scrub date and the file version you used. Repeat the scrub on the schedule your compliance officer sets, not once at launch and never again.
Check numbers against a reassigned numbers source before dialing.
Consent belongs to the person, not the number. A number that changed hands after consent was collected is a risk, and the FCC runs a database for exactly this check.
Restrict call windows to the federal TCPA/TSR calling hours in the called party's local time and confirm the platform derives time zone from the number.
Counsel confirms the federal window; several states are narrower. The campaign scheduler should enforce it on its own rather than relying on someone remembering.
Configure the opt-out path so a spoken request to stop ends the call, logs the number and blocks future dials.
Test it by saying "stop calling me" mid-sentence on a test call and checking the CRM afterwards. The number should be suppressed before the next dial attempt, not after a nightly sync.
Verify caller ID shows a number the trader can call back and that your outbound numbers carry STIR/SHAKEN attestation.
Unattested or spoofed numbers get labelled as spam by carriers, which cuts connect rates and invites complaints. Topcalls' compliance posture covers TCPA, TSR and DNC, but the numbers and consent are yours.
List the state-level calling statutes, state DNC lists and recording consent rules that apply to your numbers, and assign an owner to each.
Several states have their own telemarketing laws with narrower hours, separate registries or all-party recording consent. Don't summarise them here; name who is checking them and by when.
Ask counsel to confirm the TCPA and Telemarketing Sales Rule analysis in writing before the first US dial.
Call recording and MiFID II
Recording and transcription are included in Topcalls' $0.35/min rate, so the question isn't whether you can record. It's whether you must, who has to be told, and where the file lives.
Classify each call type as in scope or out of scope for MiFID II recording.
MiFID II requires firms to record telephone conversations that relate to receiving, transmitting or executing client orders. A reactivation call that stays on account status may be out of scope; one where the trader asks the agent about closing a position isn't. Your compliance officer draws the line.
Decide whether to record every AI call regardless, and document the reason.
One rule (record everything) is easier to defend and to operate than a per-call decision. If you choose not to record some calls, write down the criterion and who approved it.
Add the recording notice to the opening line, in the trader's language.
Under MiFID II clients must be told that conversations may be recorded. Several countries and US states require all-party consent for recording anyway. One approved sentence at the top of the script covers both.
Set the retention period for recordings and transcripts to the longest rule that applies.
MiFID II sets a multi-year minimum for order-related recordings and your national regulator can extend it. Confirm the exact number and the start date with compliance.
____ years
Confirm recordings sit in a durable store the regulator can retrieve on request, searchable by client, date and phone number.
A regulator asking for "all calls with client X in Q2" should be a filter, not a project.
Confirm the transcript and the audio share the same call ID and land on the same CRM record.
A transcript without its audio is hard to rely on in a dispute. Test the link on one call before launch.
Restrict who can listen to or download recordings and log every access.
Recordings contain personal data and sometimes ID or card details read aloud. Access should be role-based and reviewed on a schedule.
Ask compliance to sign off the recording policy for AI calls specifically, including whether the agent's own words count as firm communications.
Data retention and deletion
Two rules pull in opposite directions. GDPR says keep personal data no longer than needed; MiFID II says keep certain records for years. The plan has to say which data falls under which rule.
Inventory every data element the campaign creates: audio, transcript, call summary, outcome, callback time, sentiment tag and the input list itself.
Retention decisions are made per element, not per campaign. Use the table below and leave nothing blank.
Map where each element is stored: calling platform, CRM, data warehouse, email inboxes, chat channels.
Retention is only real if every copy expires. The transcript someone pasted into a team chat doesn't.
Define the deletion process and test it on one record end to end.
Deleting from the CRM but leaving the recording in the calling platform is the usual failure. Confirm your vendor can delete one trader's audio and transcripts on request, and how fast.
Set up handling for access, erasure and objection requests within GDPR's response window.
GDPR sets a response deadline; confirm the exact window and the extension rules with your DPO. Name who receives the request, who pulls the data from the calling platform and who replies.
Sign a data processing agreement with the calling vendor that lists sub-processors (speech-to-text, voice model, telephony) and their locations.
An AI voice pipeline touches several processors. Each one is a sub-processor under GDPR and the DPA should name them.
Decide with your DPO whether a data protection impact assessment is needed for automated voice calls at this scale.
Large-scale processing with new technology is a common DPIA trigger. Log the decision either way, with the date.
Set a suppression-list retention rule that outlasts the marketing data.
Opt-out records must survive deletion of the rest of the record, or you'll call the same person again next year.
| Data element | Keep for | Legal reason | Owner |
|---|---|---|---|
| Call audio | ____ | ____ | ____ |
| Transcript | ____ | ____ | ____ |
| Call summary and outcome | ____ | ____ | ____ |
| Input lead list | ____ | ____ | ____ |
| Consent records | ____ | Evidence of lawful basis | ____ |
| Opt-out and suppression records | Longer than all of the above | Right to object | ____ |
Cross-border jurisdictions
The rules follow the trader, not the broker. A list with 12 country codes needs 12 answers on licensing, consent, DNC registries and calling hours before the first dial. Fill the table for every country on the list.
Group the list by country code and count each segment.
____ countries
Confirm for each country that your licensed entity may solicit residents there.
Some regulators bar foreign brokers from soliciting their residents or restrict CFD marketing outright. This is a licensing question before it's a calling question, and it removes whole segments.
Identify the national do-not-call or opt-out registry for each country and schedule a scrub.
The UK has the TPS, France has Bloctel, the US has the National DNC Registry, and several EU countries run their own. Some countries require opt-in for marketing calls instead of an opt-out registry, which sends you back to the consent section.
Record the permitted calling hours and days per country and set them in the campaign scheduler.
Record the recording consent rule per country: one-party, all-party, or notice only.
Check whether FCA financial promotion rules apply to calls into the UK and name the approver.
If the script invites or induces trading, it's likely a financial promotion under FCA rules and needs approval by an appropriately authorised person before use. The FCA also restricts unsolicited real-time promotions for some products. The FCA checklist goes deeper; here you only confirm ownership.
Map data transfers: where recordings are stored against where the trader lives, and the transfer mechanism (adequacy decision, standard contractual clauses).
A trader in Germany whose recording sits on a server outside the EU is a GDPR transfer. Your DPO confirms the mechanism.
Choose the language and the outbound number per country, and match caller ID to the licensed entity for that market.
A local number in the trader's language lifts answer rates and reduces complaints. Topcalls agents cover 32 languages; the entity name on caller ID is your call.
| Country | Licensed to solicit? | DNC registry | Calling hours | Sign-off |
|---|---|---|---|---|
| ____ | Yes / No | ____ | ____ | ____ |
| ____ | Yes / No | ____ | ____ | ____ |
| ____ | Yes / No | ____ | ____ | ____ |
| ____ | Yes / No | ____ | ____ | ____ |
| ____ | Yes / No | ____ | ____ | ____ |
Sign-off and launch gate
Nothing above counts as done until someone with authority has signed it. Fill in names, not departments.
Name the compliance officer who signs the campaign as a whole.
Name: ____________
Name the DPO or privacy lead who signs the retention and data transfer items.
Name: ____________
Name the counsel, internal or external, who reviewed the TCPA and cross-border analysis.
Name: ____________
Attach the approved script, the AI disclosure wording and the recording notice to the sign-off record.
The version that was approved is the version that runs. If the script changes after sign-off, the sign-off is void until it's re-approved.
Run ten test calls to internal numbers and check the recordings against the disclosure, recording notice and opt-out items.
Listen for the disclosure in the first sentence, say "stop" on at least two calls and confirm the numbers are suppressed in the CRM afterwards.
Set the date of the next review: list re-scrub, consent age cut-off and any rule changes in the countries you call.
Review date: ____________
Store the completed checklist with the campaign record so an auditor can find it without asking.
How to use this
- 1
Print it or open it beside the campaign settings before the list goes anywhere near the dialer.
- 2
Work through consent first: it decides which records survive to the other sections.
- 3
Skip the US TCPA section only if the list contains no +1 numbers, and write that down.
- 4
Fill both tables per data element and per country; a blank cell is an open question, not a pass.
- 5
Get a named signature on each section, then run the ten test calls before launch.
- 6
Repeat the list scrubs and the consent age cut-off on the review date, and refile the checklist.
Next step
We go through your list by country, map consent, recording and retention onto the campaign setup, and scope a pilot your compliance officer can sign.
Book a 30-minute compliance scoping callRead next
Related resources
GDPR Review Checklist for AI Voice Calls
GDPR review checklist for brokerage AI voice campaigns: lawful basis, call-time transparency, DPIA, processor contracts, retention and data subject rights.
Do-Not-Call and Suppression Audit Checklist
Audit how a brokerage screens do-not-call lists and suppresses traders from AI calling campaigns: sources, refresh cadence, opt-outs, exclusions, evidence.
AI Call Disclosure Checklist
Checklist for broker AI calls: when the agent says it's AI, how the recording notice is worded, how opt-outs work and what each country needs reviewed.