Call recording compliance checklist to run before recordings are licensed

A call recording compliance checklist confirms, year by year, which consent rules applied to the parties on each call, what the IVR notice said, whether agents acknowledged recording, how card payments were paused, how long files are kept and what client contracts allow. Contact centers should run it before any historic recordings are scoped for an AI training license.

Why audit recordings before anyone scopes a license

Historic call recordings can be considered for a license only if each year of them was captured lawfully, belongs to the company and can be cleaned of payment and other sensitive data. A contact center that rewrote its IVR greeting in 2021 effectively has two consent histories, and each needs its own answer.

Two layers of law apply. The federal Wiretap Act, 18 U.S.C. 2511, bars intercepting calls and separately bars knowingly disclosing or using the contents of an unlawfully intercepted call; section 2511(2)(d) allows interception by a party to the call, or with one party's prior consent, unless the purpose is criminal or tortious. Some states demand more. California's Penal Code section 632 prohibits recording a confidential communication without the consent of all parties, and section 632.7 covers cellular and cordless calls. Published state-by-state lists disagree with one another, so counsel should read each relevant statute rather than rely on a vendor chart.

The disclosure point matters most for licensing: if a recording was unlawful when made, licensing it later stacks a disclosure on top of the original problem. The guide to CIPA lawsuits over AI call analytics explains what those claims mean for stored recordings.

This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.

The call recording compliance checklist

Work through each group for every year of recordings you might include. Record the answer and the evidence behind it: a script file, a settings screenshot, a contract clause.

Consent-state mix

  • Pull caller locations by year from billing or service addresses, since area codes on mobile numbers are unreliable.
  • Mark calls involving any party in an all-party consent state, including remote agents working from those states.
  • Write down which rule the center applied to interstate calls, and when that choice was made.

Notice wording by year

  • Collect every IVR greeting script with its live dates.
  • Confirm outbound dialer campaigns gave a recording notice at the start of each call.
  • Check paths that skip the greeting: direct dials, warm transfers, scheduled callbacks and escalations from chat.
  • Note what the greeting said recordings were for, such as quality, coaching or training.

Agent acknowledgments

  • Find signed agent acknowledgments of recording and monitoring, by hire cohort.
  • Check whether internal calls, team huddles and screen sessions were captured, and under which policy.
  • Confirm the workforce privacy notice listed call audio as a collected category.

Payment card pause and resume

  • Record when pause-and-resume or keypad masking went live, queue by queue.
  • Spot-check recordings made before that date for spoken card numbers and security codes.
  • Check transcripts and speech-analytics outputs, which may hold card data even where audio was paused.

Retention and storage

  • Compare the written retention period with the oldest recording actually stored.
  • List every place recordings live: the contact center platform, archives, analytics vendors and backups.
  • Confirm deletion requests were honored across every copy.
  • Note whether calls link to outcomes such as disposition codes, case IDs or CRM records.

Client contract terms

  • Identify whose customers are on each queue: the company's own or a client's.
  • Read ownership, confidentiality and secondary-use clauses in each client agreement and statement of work.
  • Flag clients whose written consent would be needed before any reuse.

A company-wide data map makes the storage questions faster, because it already lists each platform, archive and vendor.

How to read the results

ResultWhat it meansNext action
Consistent notice, own customers, payment pause in placeStrong candidate yearsMove to inventory and redaction scoping
Greeting changed partway through the historyTwo consent storiesScope later years first; counsel reviews earlier ones
Gaps in outbound noticeAffected campaigns are weakExclude those campaigns
Card data captured before masking went liveSensitive segments in audio and textRedact segments or exclude the period
Queues serve a client's customersRecords are not the company's to license aloneOut of scope unless the client agrees in writing
Audio deleted, transcripts and dispositions keptText history may still be usefulAssess transcripts with the same consent questions
Open claims over recording practicesLegal exposure is livePause until counsel clears it

Deletion handling needs its own review; the page on CCPA deletion requests after a data license explains the scoping choice.

Red flags that end the review for a queue or period

  • Recording with no notice while parties were in all-party consent states.
  • Covert recording of employees or customers.
  • Client contracts that prohibit secondary use, with no realistic path to consent.
  • Recordings already licensed to another party for AI training.
  • Calls dominated by medical or financial account details with no lawful route.
  • Archives that nobody can export.

Where partners fit

A partner who knows a contact center owner can make the introduction with a few basic facts: roughly how many years of recordings exist, whether notice has played throughout and whether the queues serve the company's own customers. Never request sample calls, transcripts or exports. SourceX qualifies the company, the company completes its own inventory, the redaction scope is fixed before work begins and nothing is delivered without a signed agreement and the company's authorization.

The company itself must clear the usual bar: a US business with 50+ full-time employees at peak (contractors excluded), an operating history going back several years, the right to license its recordings and an owner or executive able to sponsor the deal. A quick, non-binding first read is available from the company fit checker, and how it works sets out the stages. Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company, paid only after the buyer pays and SourceX receives its fee.

Next step

When a contact center passes the checklist for at least some years, register as a partner and introduce the owner, or send them to sourcex.si/apply with your referral link.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Does a 'calls may be recorded for quality and training' greeting cover AI training?

Not automatically. When most of those greetings were written, training meant coaching agents. Whether the wording, together with the company's privacy notice, reaches licensing recordings or transcripts to an outside developer is a question for counsel, and the answer can differ between raw audio and de-identified text. The audit's job is to record exactly what callers heard in each period.

How far back should a recording audit go?

As far back as any recordings the company might include. Audit year by year, because greetings, dialer settings, payment controls and client contracts all change over time. A center holding recordings from 2016 to today may find later years clean and earlier years uncertain, and it can scope only the clean period instead of giving up on the whole archive.

Do agents need to consent as well as callers?

Agents are parties to the call, so their notice and consent matter alongside the caller's, especially for agents working from all-party consent states. Most centers handle this through hiring paperwork, a monitoring acknowledgment and the workforce privacy notice. The audit should confirm those documents existed for each hire cohort, not only for current staff.

Are transcripts treated differently from audio?

Often, yes. Transcripts can be de-identified more thoroughly than audio, because names, numbers and addresses can be removed from text and the voice itself disappears. But transcripts inherit the consent history of the call they came from, and speech-analytics transcripts sometimes captured card numbers that a late audio pause missed. Audit both and decide scope for each separately.

Who should run the audit inside the company?

Usually a small group: the compliance or quality lead who knows the greeting history, the contact center platform administrator who can pull settings and dates, whoever holds client contracts in finance or legal, and outside counsel for the legal reading. A referral partner should not take part or listen to recordings; their role ends with the introduction.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment