Compliance Checklist for Consumer Finance Texting Programs

Blog, Business, Compliance
Compliance Checklist

In the heavily regulated consumer finance industry, ensuring compliance in business to consumer messaging is crucial – as well as complicated. Solutions by Text (SBT) specializes in providing compliant text messaging solutions that help businesses connect with their customers while adhering to complex regulatory and carrier (T-Mobile, AT&T, Verizon, etc.) standards. This checklist is designed to help businesses, particularly in the finance industry, consider the fundamental requirements when designing their text messaging plan. For businesses to successfully send messages to consumers they must be part of an approved campaign, and they are subject to ongoing compliance and monitoring obligations.  

1. Obtain Consent  

Before sending any business to consumer text messages, the business organization sending messages (the “message sender”) should obtain express consent from the consumer for any informational messaging, and express written consent for any promotional messaging. There are many ways to obtain consent (web, print, verbal), and specific requirements may vary by carrier. At any time, the carrier may request proof of consumer opt-in to the texting program, see below “Compliance Audits.” It is important to note that carrier consent requirements may be different than any required by law, are often more restrictive, and the carriers are the ultimate authority in deciding the rules applicable to their networks.  

2. Clear Opt-In Consent Workflow 

To be approved to begin messaging, the carriers require message senders to provide evidence of a clear and conspicuous opt-in consent workflow with appropriate disclosures to the consumer about the type and purpose of the intended messaging. For example, this can be a link to the message sender’s webpage to collect opt-ins, a screenshot of opt-ins in print, or evidence of a verbal opt-in. This opt-in should ensure that consumers are aware of: the program or product description and the number from where the messaging will originate; the organization that will be sending the initial message; opt-in language and any associated fees and other applicable terms and conditions (e.g., how to opt-out, customer contact info, and any applicable privacy policy). 

3. Honor Opt-Out Requests 

It is critical that the message sending organization honor opt-out requests. If consumers indicate they want to be removed from the message sender’s subscriber list, they must remove them, and they must not be texted by the message sender unless they resubscribe by opting back in. Consumers can opt-out of receiving messages at any time, and the message sender should support multiple mechanisms of opt-out, including phone call, email, or text. The message sender may send one final message to confirm a user has opted out successfully. If sending for multiple purposes, the message sender may clarify what use cases they wish to be opted out of.  

4. Required & Disallowed Message Content 

To minimize spam complaints and ensure compliance, the carriers scan messages for required and disallowed content, and will block delivery of non-compliant messages.  

Include mandatory disclosures in the initial outbound text message. State the purpose of the message, the message frequency (if recurring), a disclaimer that message and data rates may apply, a link to the organization’s Privacy Policy and texting-specific terms and conditions and opt-out and help instructions. Use natural language, non-standard spellings will be subject to blocking as spam. For example, “H! H0w ar3_you do1ng?” is considered non-standard spelling and should be avoided. 

Do not use public link shorteners such as bitly and tinyurl; instead, link directly to the organization’s website using the full domain or use a branded short URL to deliver custom links. Do not send content containing SPAM, fraudulent or misleading messages, endorsements of violence, inappropriate content, profanity or hate speech, or endorsement of illegal drugs. Avoid sending content that could be construed as misleading or deceptive. 

5. Respect Quiet Hours 

Unless otherwise required by applicable law, messaging should be restricted to hours between 8 a.m. and 9 p.m. in the message recipient’s time zone. Be aware that certain states and messaging use cases may have more restrictive rules. Following this guidance helps prevent messaging during hours when consumers are likely to find messages intrusive and thus opt-out or file a complaint. 

6. Keep Subscriber Lists Healthy 

To ensure that messages are sent to the intended recipient, message senders must take steps to keep their subscriber list healthy. As required by the carriers, SBT manages deactivated and recycled mobile numbers through its FinText® platform by performing its Deactivation Logic® process daily. The FinText® platform also helps prevent message senders from sending additional messages to consumers who have opted-out without a subsequent opt-in event through its Stop Safety Net® process. Message senders are responsible for retaining and maintaining all opt-in and opt-out requests and processing mobile deactivation files daily to remove deactivated numbers from any opt-in lists. Message senders should regularly re-confirm consent, especially if there is a meaningful change in the messaging content or frequency. If their subscriber list is healthy, message senders minimize unwanted messages, thereby minimizing opt-outs and complaints. 

7. Maintain Detailed Records 

Keep detailed records of consent opt-ins, messages sent and opt-out requests. In a regulatory audit or consumer complaint, the message sender should be prepared to produce this information and show compliance with applicable requirements.  The TCPA does not include an express record-keeping requirement in connection with the “prior express consent” standard, however the carriers do require that organizations be able to prove consent. 

8. Regular Compliance Audits 

Message senders should conduct regular internal audits of their messaging practices and subscriber lists to ensure ongoing compliance with all relevant regulations and pass compliance audits. Proactive internal audits will help identify and address potential issues before they escalate, maintaining the organization’s integrity and compliance.  

9. Stay Informed About Industry Changes 

The business messaging landscape is constantly evolving, as are the carriers’ use policies and best practices. Stay updated on any changes to regulations and carrier guidelines to ensure practices remain compliant by following SBT on LinkedIn and reading our customer resources.  

Potential Penalties for Non-Compliance 

Non-compliance with carrier guidelines can result in message blocking, blacklisting of sender IDs, and suspension of messaging services. Ignorance of applicable law and regulations, including updates thereto, does not exempt organizations from penalties, which may include substantial fines and protracted legal action.  

Legal Disclaimer 

This checklist is intended for informational purposes only and does not constitute legal advice. Any legal questions should be directed to an attorney licensed in the relevant jurisdiction.  

Additional Resources

TCPA Regulations (Federal Communications Commission) 

CTIA Messaging Principles and Best Practices 

CFPB UDAAP Policy 

FCC Recordkeeping Requirements 

Industry Best Practices (FCC Telemarketing and Robocalls) 

Share this article:
Facebook
Twitter
Pinterest
WhatsApp

Want to learn more? Contact us today!