Checklist

AI Calling Compliance Planning Checklist for Brokers

Plan a compliant AI calling campaign for a brokerage: consent, US TCPA setup, MiFID II recording, data retention, cross-border rules and who signs off.

Who it is for
Broker ops leads, compliance officers and DPOs preparing an AI outbound calling campaign to dormant traders or old leads.
Time to complete
60 minutes plus sign-off meetings

This checklist walks a brokerage through the compliance questions that have to be answered before an AI voice agent dials a single dormant trader. It covers consent and lawful basis, US numbers under the TCPA, call recording under MiFID II, data retention and deletion, and what changes when the list spans several countries. Work through it with your compliance officer and you'll finish with a campaign setup, a named approver for each section and a paper trail an auditor can follow. It tells you what to review and who decides, not what the law concludes.

US numbers and TCPA setup

If one +1 number is on the list, this section applies. The FCC has said AI-generated voices count as artificial voices under the TCPA, so plan for the stricter consent rules that apply to prerecorded and artificial-voice calls.

  • Count the +1 numbers on the list and decide whether to call them at all.

    Many CFD brokers aren't permitted to solicit US residents in the first place. If your licence doesn't allow it, suppress the whole segment and skip the rest of this section.

    ____ US numbers

  • Locate prior express written consent for every US number that will hear a marketing message.

    For marketing calls using an artificial or prerecorded voice, the TCPA's consent standard is written consent that identifies the caller and covers automated calls. A generic "I agree to be contacted" line probably doesn't meet it. Counsel decides.

  • Scrub the list against the National Do Not Call Registry and your internal do-not-call list.

    Record the scrub date and the file version you used. Repeat the scrub on the schedule your compliance officer sets, not once at launch and never again.

  • Check numbers against a reassigned numbers source before dialing.

    Consent belongs to the person, not the number. A number that changed hands after consent was collected is a risk, and the FCC runs a database for exactly this check.

  • Restrict call windows to the federal TCPA/TSR calling hours in the called party's local time and confirm the platform derives time zone from the number.

    Counsel confirms the federal window; several states are narrower. The campaign scheduler should enforce it on its own rather than relying on someone remembering.

  • Configure the opt-out path so a spoken request to stop ends the call, logs the number and blocks future dials.

    Test it by saying "stop calling me" mid-sentence on a test call and checking the CRM afterwards. The number should be suppressed before the next dial attempt, not after a nightly sync.

  • Verify caller ID shows a number the trader can call back and that your outbound numbers carry STIR/SHAKEN attestation.

    Unattested or spoofed numbers get labelled as spam by carriers, which cuts connect rates and invites complaints. Topcalls' compliance posture covers TCPA, TSR and DNC, but the numbers and consent are yours.

  • List the state-level calling statutes, state DNC lists and recording consent rules that apply to your numbers, and assign an owner to each.

    Several states have their own telemarketing laws with narrower hours, separate registries or all-party recording consent. Don't summarise them here; name who is checking them and by when.

  • Ask counsel to confirm the TCPA and Telemarketing Sales Rule analysis in writing before the first US dial.

Call recording and MiFID II

Recording and transcription are included in Topcalls' $0.35/min rate, so the question isn't whether you can record. It's whether you must, who has to be told, and where the file lives.

  • Classify each call type as in scope or out of scope for MiFID II recording.

    MiFID II requires firms to record telephone conversations that relate to receiving, transmitting or executing client orders. A reactivation call that stays on account status may be out of scope; one where the trader asks the agent about closing a position isn't. Your compliance officer draws the line.

  • Decide whether to record every AI call regardless, and document the reason.

    One rule (record everything) is easier to defend and to operate than a per-call decision. If you choose not to record some calls, write down the criterion and who approved it.

  • Add the recording notice to the opening line, in the trader's language.

    Under MiFID II clients must be told that conversations may be recorded. Several countries and US states require all-party consent for recording anyway. One approved sentence at the top of the script covers both.

  • Set the retention period for recordings and transcripts to the longest rule that applies.

    MiFID II sets a multi-year minimum for order-related recordings and your national regulator can extend it. Confirm the exact number and the start date with compliance.

    ____ years

  • Confirm recordings sit in a durable store the regulator can retrieve on request, searchable by client, date and phone number.

    A regulator asking for "all calls with client X in Q2" should be a filter, not a project.

  • Confirm the transcript and the audio share the same call ID and land on the same CRM record.

    A transcript without its audio is hard to rely on in a dispute. Test the link on one call before launch.

  • Restrict who can listen to or download recordings and log every access.

    Recordings contain personal data and sometimes ID or card details read aloud. Access should be role-based and reviewed on a schedule.

  • Ask compliance to sign off the recording policy for AI calls specifically, including whether the agent's own words count as firm communications.

Data retention and deletion

Two rules pull in opposite directions. GDPR says keep personal data no longer than needed; MiFID II says keep certain records for years. The plan has to say which data falls under which rule.

  • Inventory every data element the campaign creates: audio, transcript, call summary, outcome, callback time, sentiment tag and the input list itself.

    Retention decisions are made per element, not per campaign. Use the table below and leave nothing blank.

  • Map where each element is stored: calling platform, CRM, data warehouse, email inboxes, chat channels.

    Retention is only real if every copy expires. The transcript someone pasted into a team chat doesn't.

  • Define the deletion process and test it on one record end to end.

    Deleting from the CRM but leaving the recording in the calling platform is the usual failure. Confirm your vendor can delete one trader's audio and transcripts on request, and how fast.

  • Set up handling for access, erasure and objection requests within GDPR's response window.

    GDPR sets a response deadline; confirm the exact window and the extension rules with your DPO. Name who receives the request, who pulls the data from the calling platform and who replies.

  • Sign a data processing agreement with the calling vendor that lists sub-processors (speech-to-text, voice model, telephony) and their locations.

    An AI voice pipeline touches several processors. Each one is a sub-processor under GDPR and the DPA should name them.

  • Decide with your DPO whether a data protection impact assessment is needed for automated voice calls at this scale.

    Large-scale processing with new technology is a common DPIA trigger. Log the decision either way, with the date.

  • Set a suppression-list retention rule that outlasts the marketing data.

    Opt-out records must survive deletion of the rest of the record, or you'll call the same person again next year.

Data retention and deletion
Data elementKeep forLegal reasonOwner
Call audio____________
Transcript____________
Call summary and outcome____________
Input lead list____________
Consent records____Evidence of lawful basis____
Opt-out and suppression recordsLonger than all of the aboveRight to object____

Cross-border jurisdictions

The rules follow the trader, not the broker. A list with 12 country codes needs 12 answers on licensing, consent, DNC registries and calling hours before the first dial. Fill the table for every country on the list.

  • Group the list by country code and count each segment.

    ____ countries

  • Confirm for each country that your licensed entity may solicit residents there.

    Some regulators bar foreign brokers from soliciting their residents or restrict CFD marketing outright. This is a licensing question before it's a calling question, and it removes whole segments.

  • Identify the national do-not-call or opt-out registry for each country and schedule a scrub.

    The UK has the TPS, France has Bloctel, the US has the National DNC Registry, and several EU countries run their own. Some countries require opt-in for marketing calls instead of an opt-out registry, which sends you back to the consent section.

  • Record the permitted calling hours and days per country and set them in the campaign scheduler.

  • Record the recording consent rule per country: one-party, all-party, or notice only.

  • Check whether FCA financial promotion rules apply to calls into the UK and name the approver.

    If the script invites or induces trading, it's likely a financial promotion under FCA rules and needs approval by an appropriately authorised person before use. The FCA also restricts unsolicited real-time promotions for some products. The FCA checklist goes deeper; here you only confirm ownership.

  • Map data transfers: where recordings are stored against where the trader lives, and the transfer mechanism (adequacy decision, standard contractual clauses).

    A trader in Germany whose recording sits on a server outside the EU is a GDPR transfer. Your DPO confirms the mechanism.

  • Choose the language and the outbound number per country, and match caller ID to the licensed entity for that market.

    A local number in the trader's language lifts answer rates and reduces complaints. Topcalls agents cover 32 languages; the entity name on caller ID is your call.

Cross-border jurisdictions
CountryLicensed to solicit?DNC registryCalling hoursSign-off
____Yes / No____________
____Yes / No____________
____Yes / No____________
____Yes / No____________
____Yes / No____________

Sign-off and launch gate

Nothing above counts as done until someone with authority has signed it. Fill in names, not departments.

  • Name the compliance officer who signs the campaign as a whole.

    Name: ____________

  • Name the DPO or privacy lead who signs the retention and data transfer items.

    Name: ____________

  • Name the counsel, internal or external, who reviewed the TCPA and cross-border analysis.

    Name: ____________

  • Attach the approved script, the AI disclosure wording and the recording notice to the sign-off record.

    The version that was approved is the version that runs. If the script changes after sign-off, the sign-off is void until it's re-approved.

  • Run ten test calls to internal numbers and check the recordings against the disclosure, recording notice and opt-out items.

    Listen for the disclosure in the first sentence, say "stop" on at least two calls and confirm the numbers are suppressed in the CRM afterwards.

  • Set the date of the next review: list re-scrub, consent age cut-off and any rule changes in the countries you call.

    Review date: ____________

  • Store the completed checklist with the campaign record so an auditor can find it without asking.

How to use this

  1. 1

    Print it or open it beside the campaign settings before the list goes anywhere near the dialer.

  2. 2

    Work through consent first: it decides which records survive to the other sections.

  3. 3

    Skip the US TCPA section only if the list contains no +1 numbers, and write that down.

  4. 4

    Fill both tables per data element and per country; a blank cell is an open question, not a pass.

  5. 5

    Get a named signature on each section, then run the ten test calls before launch.

  6. 6

    Repeat the list scrubs and the consent age cut-off on the review date, and refile the checklist.

Next step

We go through your list by country, map consent, recording and retention onto the campaign setup, and scope a pilot your compliance officer can sign.

Book a 30-minute compliance scoping call

Read next

Related resources