Resources
Operations

How to keep lead acquisition compliant (and the tools that prove it)

9 min read

One-to-one consent, do-not-call scrubbing, and provable consent records. A practical checklist for lending teams buying or generating their own leads — plus the services that do the verification work.

Compliance in lead acquisition is not a legal footnote bolted onto a campaign. It is part of the acquisition system itself, and the shops that treat it that way spend less time worrying about demand letters and more time originating. The rules that matter most are federal telemarketing law, state-level calling rules, mortgage advertising rules, and the referral-fee restrictions specific to our industry.

None of what follows is legal advice. It is the operating checklist we use when we build acquisition systems, and every lender should have their own counsel sign off on the specifics before launch.

1. Consent has to be specific, and it has to be yours

The era of buying a lead with a footer disclosure naming two hundred 'marketing partners' is over. Consent under the TCPA is expected to be one-to-one: the consumer agrees to be contacted by a single, clearly named company, for a clearly described purpose, on a page where that agreement is unmistakable. A checkbox buried under a wall of grey 6pt text is the exact fact pattern plaintiffs' firms look for.

  • Name your company — the legal entity — in the consent language, not 'us and our partners'.
  • Describe the contact methods you will actually use: calls, texts, and whether an autodialer or prerecorded message may be involved.
  • Keep the consent unchecked by default and separate from the terms-of-service checkbox.
  • State that consent is not a condition of obtaining a loan or any service. This one is non-negotiable for lenders.
  • Include a clear opt-out instruction and honour it across every channel within the same business day.
If you cannot produce, in under a minute, a timestamped record of exactly what a specific consumer agreed to, you do not have consent. You have a phone number.

2. Scrub before you dial, every time

Consent is the first gate. The second is whether the number is safe to call at all. Numbers get reassigned, consumers register on do-not-call lists, and a small population of serial plaintiffs makes a living from being called. Each of those is a separate check, and each has a service built for it.

  • National Do Not Call Registry (telemarketing.donotcall.gov) — the official government access portal for sellers and telemarketers to download the registry. Registration is required and there is an annual fee per area code.
  • Reassigned Numbers Database (reassigned.us) — the FCC-mandated database that tells you whether a number was disconnected after the date consent was given. Checking it is what earns the safe-harbour defence.
  • State do-not-call lists — several states run their own registries with their own calling-hour restrictions and rules. Check the state regulator's site for each state you originate in.
  • Litigator and serial-plaintiff scrubbing — services such as the Blacklist Alliance and DNC.com maintain known-litigator lists on top of standard DNC data.
  • Internal do-not-call list — you are required to maintain your own suppression list. It must survive CRM migrations, which in practice means storing it outside a single vendor.

3. Capture proof at the moment of consent

The defence in almost every TCPA dispute is documentary. Two independent services dominate this and both are worth the line item if you buy leads from anyone other than yourself.

  • TrustedForm (ActiveProspect) — issues a certificate capturing a session replay of the form, the page as rendered, and the timestamp. Ask every lead vendor for the certificate URL with the lead, and independently verify it rather than taking their word for it.
  • Jornaya LeadiD (Verisk) — a competing consent-capture token widely used across mortgage lead marketplaces, with additional visibility into whether the same consumer is being sold to several buyers at once.
  • Your own record — store the full rendered consent text, the IP address, the user agent, the timestamp, and the form payload in your own database. Vendor certificates expire; your records should not.

4. Mortgage-specific rules the general playbook misses

Generic lead-gen advice stops at the TCPA. Lending has three more layers, and they are the ones that draw regulator attention rather than private lawsuits.

  • RESPA Section 8 — payment for referrals of settlement service business is prohibited. How you compensate a lead source matters as much as the leads themselves; pay-per-closed-loan arrangements with referral partners are the classic problem area. The CFPB's Section 8 FAQs on consumerfinance.gov are the primary reference.
  • Regulation Z advertising rules — quoting a rate, a payment, or a term triggers required disclosures. Ad platforms will not catch this for you.
  • NMLS advertising requirements — your NMLS ID and licensed entity name must appear on advertising, and many states add their own format rules. Check the NMLS Resource Center and each state regulator.
  • UDAAP — 'get approved regardless of credit' style claims in non-QM creative are exactly what examiners flag. Specificity about scenarios you have placed is both more compliant and more persuasive.

5. Platform and privacy rules that quietly kill campaigns

Ad platforms enforce their own overlay of restrictions on financial services, and privacy law adds another. Neither shows up as a legal notice — it shows up as a disabled ad account or a deleted pixel event.

  • Meta and Google both restrict financial-services advertising and, in some regions, require advertiser verification before you can run credit-related creative. Read the current policy pages before writing the ads, not after rejection.
  • State privacy laws (California, Colorado, Texas, Virginia and others) require a privacy policy, disclosure of data sharing, and a working opt-out mechanism. If you run retargeting pixels, you are sharing data.
  • Recording calls requires consent in two-party-consent states. If your dialer records by default, that setting is a compliance decision, not an IT one.

6. The audit you should be able to pass on any Tuesday

Pick five leads at random from the last thirty days and try to produce the following for each within ten minutes: the exact consent text the consumer saw, the timestamp and IP, the consent certificate from the vendor, the DNC and reassigned-number scrub results dated before the first call, the full contact history, and any opt-out and how quickly it was honoured.

If you can do that, the compliance layer of your acquisition system is real. If you cannot, that is the first thing to fix — before more spend, more channels, or more originators. It is far cheaper to build the record-keeping now than to reconstruct it under deadline later.

Want this diagnosed on your own pipeline?

We map the constraint before anyone talks about spend — and it costs nothing to start.