Evalgent
Back to Blog
Voice AI Evaluation

A Compliance Officer's Guide to Choosing a Voice Vendor

Deepesh Jayal
12 min read
A Compliance Officer's Guide to Choosing a Voice Vendor

# A compliance officer's guide to choosing a voice agent vendor

Quick answer: A compliance officer chooses a voice agent vendor by mapping every US rule that applies — disclosures, consent, TCPA, HIPAA, FDCPA, PCI, plus PII handling and retention — then demanding independent, pass-or-fail evidence that the agent follows each one on real calls, with change control on model updates.

A voice agent talks to your customers in your name. It makes disclosures, handles payment data, and states things a regulator can later read back to you. When it breaks a rule, the liability lands on your organization, not the vendor. That makes vendor selection a compliance decision, not just a procurement one.

This guide is written for the compliance lens. It covers the US regulations that scope the choice. It covers the disclosures and consent to demand. It covers how PII should be handled and retained. And it covers the auditability and change control that keep the agent compliant after launch. It pairs with our how to evaluate voice agent vendors pillar and the role-specific guides for the CTO, VP of engineering, procurement lead, CX leader, and contact center manager. This is general information, not legal advice.

Why vendor selection is a compliance decision

Most vendor demos are built to impress, not to test the rules. They run clean calls where the agent behaves. Your callers do not. They interrupt, hang up early, and push the agent toward things it should refuse. The gap between the demo and real traffic is where compliance risk lives.

The core problem is evidence. A vendor can claim its agent discloses that it is AI, honors opt-outs, and masks card data. A claim is not proof. You need to see the rule pass on real calls, under the conditions that make it likely to fail. That is the difference between a self-assessment and an audit, a theme our independent voice AI evaluation guide explores.

A second problem is drift. The agent that passed at signing is not the agent running next quarter. Prompts change. Models get swapped. A single update can silently drop a disclosure or loosen a boundary. So the choice is not only about the agent today. It is about whether the vendor can prove compliance on every release.

The US regulations that scope your choice

Which rules apply depends on what the agent does and who it calls. Map them before you score any vendor. Most agents touch several at once.

Outbound calling brings the Telephone Consumer Protection Act into scope, enforced by the FCC. Telemarketing adds the FTC Telemarketing Sales Rule, which governs disclosures, do-not-call, and abandoned calls. An automated voice that dials consumers has to respect both.

Healthcare pulls in HIPAA. If the agent touches protected health information, the HHS Privacy Rule sets minimum-necessary and disclosure limits. You will also need a business associate agreement with the vendor.

Debt collection brings the Fair Debt Collection Practices Act and its implementing rule, Regulation F, overseen by the CFPB. The FDCPA statute restricts what a collection call can say, when it can happen, and how often. A voice agent has to honor the same limits a human collector would.

Payments bring the PCI Data Security Standard. If the agent hears or processes card numbers, that data has to be protected, masked, and scoped. Recording a caller reading a card number without controls is a live exposure.

Call recording brings state consent law. Some states allow one-party consent. Others require all parties to agree first. The NCSL summary of recording consent laws is a useful starting map, though you should confirm the current rule for each state you operate in.

Underpinning all of it, the NIST AI Risk Management Framework gives you a recognized structure for governing AI risk. Ask vendors to map their controls to it.

Required disclosures and consent

Disclosures are the compliance officer's first test. The agent should identify itself as AI where required. It should give a recording notice that matches the caller's state. It should do both before any sensitive exchange. The wording should be approved. And it should fire in the right place every time.

The failure mode is timing, not content. A disclosure can appear on a clean call. Then it drops when the caller interrupts, talks over the agent, or changes the subject. So the question is not whether the prompt contains a disclosure. It is whether the disclosure still fires under stress. That has to be tested on calls designed to break it, not read off a script.

Consent and opt-out sit next to disclosure. If a caller says stop, the agent has to honor it and route correctly. Ask how the agent detects an opt-out, how it confirms one, and what happens to that caller afterward. Our guide to escalation for voice agents covers the handoff paths that keep a stuck or opted-out caller from being trapped.

PII handling, retention, and data residency

Voice agents collect sensitive data by design. Names, dates of birth, account numbers, and health details all pass through the call. A compliance officer has to know where that data goes, how long it lives, and who can reach it.

Start with handling. Ask how PII is captured, masked, and stored, and whether card and health fields are redacted in transcripts and logs. Our PII handling for voice agents guide breaks down what to test. A related risk is prompt injection, where a caller tries to make the agent reveal data or ignore its rules. Our prompt injection guide explains how to probe for it.

Then retention. Get the retention period for recordings, transcripts, and derived data in writing. Confirm you can delete a caller's data on request, and that deletion actually removes it. Retention that no one can enforce is a finding waiting to happen.

Finally, residency and access. Ask where data is processed and stored, whether any of it leaves the US, and which subprocessors touch it. Confirm access is logged and least-privilege. Data residency matters for both regulatory scope and your own contractual commitments to customers.

Auditability, call records, and change control

A compliance program runs on evidence. So the vendor has to produce records you can defend, not just dashboards. Three things matter most.

First, the audit trail. You need the call recording, the transcript, and a record of which rules passed or failed on that call. When a regulator asks what the agent said, you should be able to replay the exact call and show the result.

Second, mandatory rules kept separate from quality scores. A missed disclosure is not a minor quality dip to be averaged away. It is a hard failure. The evidence should treat it that way, so a single violation surfaces as a fail rather than getting buried in a blended score. This is the discipline behind our test policy adherence for voice agents and test guardrails for voice agents guides.

Third, change control. Ask how the vendor notifies you of model swaps, prompt changes, and version updates. Ask whether compliance checks re-run on every change before it reaches production. A vendor that cannot tell you when the model changed cannot tell you when a disclosure broke.

Compliance requirements, vendor questions, and the evidence to require

Use this table to turn each requirement into a concrete question and the proof you should insist on. Do not accept a claim where evidence is available.

Compliance requirementQuestion to ask the vendorEvidence to require
AI and recording disclosureDoes the agent disclose AI identity and recording, in the right place, every call?Recorded calls showing the disclosure firing under interruption and edge cases
Consent and opt-outHow does the agent detect, confirm, and honor an opt-out?Pass or fail results on opt-out scenarios, with call replay
TCPA and calling rulesHow do you enforce calling windows, frequency, and do-not-call?Configuration plus test calls that trigger each limit
HIPAA (if in scope)How is PHI limited, verified, and protected on calls?Signed BAA plus wrong-caller and minimum-necessary test results
FDCPA and Regulation FHow does the agent respect collection limits and required notices?Scenario results across time, frequency, and disclosure rules
PCI (if in scope)How is card data captured, masked, and scoped?Redaction shown in transcripts and logs, plus PCI attestation
PII retention and deletionWhat are retention periods, and can data be deleted on request?Written policy plus proof a deletion request removes the data
Data residency and accessWhere is data processed, and who can reach it?Subprocessor list, residency statement, and access logs
Change controlHow are model and prompt changes tested before release?Release gate showing compliance checks re-run on every change
Independent proofWho verifies compliance, you or a third party?An independent audit report, not a vendor self-assessment

How to run a compliance-led vendor evaluation

Run the same process for every vendor, so the comparison is fair and the decision is defensible.

1. Map the applicable rules. List every US regulation the agent touches — disclosures, TCPA, HIPAA, FDCPA, PCI, state recording consent — before you look at any vendor. This is your requirements baseline.

2. Turn each rule into a pass-or-fail assertion. Write each requirement as a check the agent either passes or fails, such as "recording disclosure fires before any sensitive exchange." Vague criteria produce vague evidence.

3. Build calls that stress the rules. Design scenarios that provoke violations — interruptions, early hang-ups, wrong callers, and tempting requests — not just clean happy paths.

4. Run identical calls on every vendor. Put each vendor through the same scenarios and caller profiles, so differences come from the agent, not the test. Our voice agent evaluation guide details this method.

5. Score mandatory rules independently. Keep compliance checks separate from quality scores, and treat any mandatory failure as a hard gate the vendor must clear.

6. Demand independent evidence. Require an audit report from a third party rather than the vendor's own numbers, following our third-party voice agent audit approach.

7. Verify data handling in the contract. Get retention, deletion, residency, subprocessors, and a BAA where needed committed in writing, not just described on a call.

8. Set the change-control terms. Require notification of model and prompt changes, and compliance re-testing on every release, as a condition of the deal.

9. File the evidence. Keep the audit report, the passing runs, and the signed terms in your compliance record, so the decision holds up under review.

Where independent evidence fits

Evalgent is an independent, third-party platform that audits AI voice agents against your compliance rules. It expresses each rule as an explicit assertion — disclosure present, forbidden promise absent, card data masked, opt-out honored — so every result is a clear pass or fail. Mandatory rules stay separate from quality scores, so a missed disclosure surfaces as a hard failure rather than being averaged away.

The scenarios run your real calls, including the edge cases that provoke violations. Profiles vary accent, pace, interruptions, and caller state, so disclosures are tested where they tend to break. Your compliance team can replay any call behind a failing rule and keep the transcript as an audit record. Because the suite re-runs on every change, compliance guards each release, not just the first. That is evidence you can put in the file, and it pairs with our voice agent compliance audit method.

To evaluate a voice agent vendor against your US compliance rules with independent evidence, book a demo.

The bottom line

A compliance officer chooses a voice vendor on evidence, not claims. Map the rules that apply, demand independent pass-or-fail proof on real calls, and require change control on every update.

Frequently asked questions

How should a compliance officer choose a voice agent vendor?

Map every US rule the agent touches, then turn each into a pass-or-fail check. Require independent evidence that the agent follows each rule on real calls, including edge cases that provoke violations. Confirm PII handling, retention, and data residency in writing. Set change control so compliance re-runs on every model or prompt update before release.

What disclosures does an AI voice agent need?

It usually needs to identify itself as AI where required and give a recording notice that matches the caller's state. Both should appear before any sensitive exchange, in approved wording. The real test is timing: the disclosure must still fire when the caller interrupts or changes the subject, not only on clean calls.

What regulations apply to AI voice agents in the US?

It depends on what the agent does. Outbound calling brings TCPA and FCC rules plus the FTC Telemarketing Sales Rule. Healthcare brings HIPAA. Collections bring the FDCPA and Regulation F. Payments bring PCI DSS. Call recording brings state consent laws. Most agents touch several at once, so map each rule that applies.

How do you audit a voice agent vendor for compliance?

Write each applicable rule as a pass-or-fail assertion. Build calls that stress those rules with interruptions, wrong callers, and tempting requests. Run identical calls on every vendor. Score mandatory rules independently and treat any failure as a hard gate. Keep recordings, transcripts, and results as an audit trail a regulator can review.

What evidence should a compliance officer require from a voice vendor?

Require recorded calls showing disclosures firing under stress, opt-out and consent results, redaction shown in transcripts, a signed BAA where HIPAA applies, and a PCI attestation for payments. Require a written retention and deletion policy, a subprocessor and residency statement, and an independent audit report rather than the vendor's own self-assessment.

Does a voice agent need recording consent?

Usually yes, but the exact rule depends on the state. Some states allow one-party consent, while others require all parties to agree before recording. An agent that records calls should give the correct notice for the caller's location and state it before any sensitive exchange. Confirm the current rule for every state you operate in.

How do you handle PII in a voice agent?

Capture only what the call needs, mask sensitive fields, and redact card and health data in transcripts and logs. Set a written retention period and confirm you can delete a caller's data on request. Restrict access to least-privilege and log it. Confirm where data is processed and whether any of it leaves the US.

How do model updates affect voice agent compliance?

A single model swap or prompt edit can silently drop a disclosure or loosen a boundary. So compliance is not settled at signing. Require the vendor to notify you of changes and re-run compliance checks on every release before it reaches callers. Treat the compliance suite as a release gate the agent must pass to ship.

Related Articles