Tips & Tricks

Hiring a VA to Dial: TCPA Rules for Insurance Agents

11 min read · August 13, 2026

At some point every agent who works a phone list runs the same math. You can only dial so many hours a day, the list keeps growing, and someone offshore will make dials for a fraction of what your time is worth. So you hire a setter, hand over the list, and start taking warm transfers.

It can work. I have seen agents run good setters for years without an incident. I have also seen an agent get a demand letter for calls he did not make, on a list he did not know his setter had bought, from a phone he had never seen.

The difference was not luck and it was not the setter's character. It was whether the dialing happened inside a system the agent controlled or outside of one. That is the whole post.

The calls are yours whether you dialed them or not

This is the part agents get wrong, and it is worth being blunt about.

The TCPA does not only reach the person holding the phone. It reaches the seller on whose behalf the call was placed. If someone calls a consumer to generate insurance business for you — using your agency name, your caller ID, handing you the appointment — you are the seller, and a plaintiff's attorney will name you.

Agents reach for two defenses here and neither one holds up on its own.

“They're an independent contractor, not my employee.” Vicarious liability does not turn on the label in the agreement. It turns on the relationship in practice: who set the hours, who supplied the list, whose name went on the call, who got the appointments, who could have told them to stop. If you supplied all of that, an independent-contractor clause is not going to do the work you want it to do.

“My contract says they indemnify me.” Indemnification decides who pays between the two of you. It does not decide whether you get sued, and it is worth exactly what the other party can actually pay. An indemnity from a contractor in another country with no US assets is a piece of paper, not a defense.

None of this means do not hire a setter. It means you should hire one the way you would hire someone to sign checks on your account: with the controls set up first.

The setup almost everyone starts with, and why it is the dangerous one

The default arrangement is informal. You export a spreadsheet, email it over, and the setter calls from whatever they have — a mobile phone, a cheap VoIP app, sometimes a dialer they already pay for. They send you a list of appointments at the end of the day, or ping you on WhatsApp when someone is interested.

It is cheap, it is fast, and it puts you in the worst possible legal position: you carry all of the liability and hold none of the evidence.

Question after a complaintVA on their own phoneVA inside your system
Did we call this number?You have to ask themTimestamped in your call log
How many times?UnknownAttempt count on the record
Was it inside legal hours there?Nobody was checkingEnforced before the dial
Where did the record come from?Whatever list they were workingImport source on the contact
Was it scrubbed?You are trusting themScrub date on the record
Did they ask us to stop?Only if it got relayedSuppressed at the moment it was logged

Read the left column again. Every answer is some version of “I would have to ask my contractor.” That is not a position you want to be in when the thing you are answering is a TCPA demand letter. Demands settle on the strength of records. If your records live on somebody else's phone in another country, you do not have records.

The one rule that fixes most of it

The setter dials inside your system, on numbers you own, against records you assigned.

Everything else in this post is a detail hanging off that sentence. When the dialing happens in your CRM and dialer, your compliance rules become their compliance rules automatically — not because the setter is disciplined, but because the software will not let the bad dial happen.

Specifically, running them inside your stack means:

  • Calling hours are enforced in the prospect's time zone, not the setter's. This matters enormously with offshore help. A setter in a time zone twelve hours off yours has no intuition whatsoever about what time it is at the number they are dialing, and the federal and state calling-hour rules are among the easiest violations to prove and the hardest to argue with.
  • Do-not-call suppression is absolute. When a record is on your internal list or comes back from a scrub, the setter never sees it. They cannot dial what is not in the queue.
  • Every attempt is logged under a named user. You can tell which dials were yours and which were theirs, which is the first thing you will need if there is ever a dispute.
  • Attempt ceilings apply per record, so an eager setter cannot hammer one prospect fifteen times because they think this one is close.
  • The caller ID is a number you ownand can be reached on, so callbacks come to you and the number's reputation is yours to manage.
  • Access ends when the relationship does. You revoke a login instead of hoping someone deletes a spreadsheet.

That last one deserves more weight than it usually gets. The moment you email a CSV of your leads, you have permanently lost control of that file. Turnover in offshore setting is high. Assume every list you have ever emailed still exists somewhere.

Where the setter's own lists come from

This is the failure mode that produces the ugliest outcomes, and it rarely comes from bad intent.

Setters are usually paid on appointments. If your assigned list runs dry at 11am, they have a direct financial incentive to find more numbers to dial. Experienced setters often have their own data — from a previous client, from a cheap list broker, from a scraped source — and dialing it feels like initiative rather than a problem.

Then a call goes to a number on the federal registry, or to a serial plaintiff who maintains numbers specifically to catch this, and the caller identified your agency. You now own calls to a list you have never seen, cannot document consent for, and did not scrub. There is no good version of that conversation with a plaintiff's attorney.

Two controls, both cheap:

Write it down explicitly. The agreement says the setter dials only records assigned in your system, and never sources, buys, or imports their own. Say it out loud in onboarding too, because a lot of setters genuinely do not know this is a problem — in plenty of shops it is normal.

Then verify it in the data. Once a week, look at the numbers dialed and confirm they all trace back to a list you imported. A dialed number with no matching contact record is the tell. This is the single highest-value audit in the whole arrangement and it takes about five minutes if your dialer logs properly.

The same discipline you would apply to a lead vendor whose data you cannot trace applies here, with one difference that makes it worse: the vendor's bad data at least arrives through your import, where you can see it and scrub it. The setter's bad data never touches your system at all.

What the setter has to be trained to do, not just told

Software handles the mechanical rules. It cannot handle what happens inside a live conversation. Those parts need actual training, and they need to be checked.

Recognizing a do-not-call request.This is the big one. A revocation does not have to contain the words “do not call.” “Take me off your list,” “stop calling me,” “I'm not interested, don't call back,” and a flat “lose this number” are all requests you must honor. A setter working a second language, paid per appointment, is exactly the person most likely to hear those as objections to overcome rather than instructions to obey. Train it explicitly: this phrase ends the call, and the record gets marked before you dial the next one. No exceptions, no supervisor approval, no “let me try one more angle.”

Identifying honestly. Federal rules require a telemarketing call to identify the caller and the party they are calling for. A setter who invents a name or vaguely implies they are calling from Medicare or Social Security has created a much larger problem than a TCPA count. Give them a fixed opening and require it.

Handling the recording disclosure. If your calls are recorded, someone has to say so, and which states require what does not change because the caller is in a different country. The disclosure belongs in the same fixed opening.

Disposition discipline.A setter paid on appointments will optimize for appointments. If the only outcomes that matter to them are “set” and “not set,” everything else gets logged as whatever requires the fewest clicks, and your disposition data becomes fiction. Make the do-not-call and wrong-number dispositions fast to select and check that they are actually being used — a setter with zero DNC dispositions across a thousand dials is not lucky, they are not logging them.

The weekly audit

Trust is not a control. Set aside fifteen minutes a week and look at four things:

  • Dials outside legal hoursin the prospect's time zone. Should be zero if your system enforces it. If it is not zero, your system is not enforcing it.
  • Dials to numbers with no contact record. This catches outside lists.
  • Repeat dials after a do-not-call disposition. Should be structurally impossible. Verify anyway.
  • Attempt counts above your ceiling on individual records, and any record with a suspicious cluster of attempts in one day.

Then listen to two or three recordings at random. Not to catch anybody — to hear how the opening actually sounds and what happens when someone pushes back. Fifteen minutes a week is a rounding error against what a single serial TCPA plaintiff costs to settle with.

A working setup, end to end

For an agent adding one setter, this is the shape that holds up:

  • The setter gets their own login in your CRM, not a shared one. Named user, revocable, attributable.
  • They see only the records you assign. Not the whole database, and nothing marked suppressed.
  • They dial through your dialer, on a number you own and are reachable on. Never a personal phone, never their own app, never a number you cannot answer.
  • Calling hours, DNC suppression, and attempt limits are enforced by the system, so compliance does not depend on a judgment call made at 3am their time.
  • Recording is on, with the disclosure in the fixed opening.
  • A written agreement covering the scope, the no-outside-lists rule, the DNC-request rule, and the fact that all data and numbers remain yours.
  • Warm transfers or booked appointments land in your queue as normal records, with the setter's call already logged against them.
  • The weekly audit above, actually done.

Notice how little of this is about the setter. Six of the eight are properties of your system. That is the point — a good arrangement is one where the setter would have to work hard to cause a problem, rather than one where they simply happen not to.

Do not hire a setter if…

You do not have a system yet. If you are still working leads out of a spreadsheet, adding a second person to that spreadsheet does not double your output, it doubles your exposure and halves your visibility. Get the system first. It is the cheaper of the two purchases anyway.

You are not sure your own dialing is compliant. A setter scales whatever process you already have. If the process has a hole in it, you have just hired somebody to find that hole faster. Fix your own calling first — hours, scrubbing, internal DNC, consent records — then hand it to someone else.

Your volume does not justify it. If you are working a few dozen fresh leads a week, a setter mostly adds a handoff. Speed to lead is worth more than delegation at that scale, and a lead that gets called by you in five minutes beats one a setter reaches tomorrow.

You want to be hands-off. The agents who get burned are not the ones who hired help, they are the ones who hired help specifically so they would not have to think about the dialing anymore. You are still the seller. You are still the one named in the complaint. Delegating the dials never delegated the liability.

Honest verdict: a virtual assistant or appointment setter is a legitimate way to scale phone prospecting, and the calls they make are legally yours no matter what the contract says. Make it safe by moving the dialing inside a system you control — your CRM login, your numbers, your assigned records, calling hours and DNC enforced by software rather than by trust. Train the two things software cannot enforce, which are recognizing a do-not-call request and identifying honestly. Audit the log weekly for outside lists and out-of-hours dials. And if you do not have that system yet, buy the system before you hire the setter.

Give your setter a seat, not your spreadsheet

Named logins, assigned records, dialing on numbers you own, calling-hour and DNC rules enforced on every attempt, and a call log that tells you exactly who dialed what and when. From $29/mo, no contracts.

See Plans & Pricing