Written DNC Policy for Insurance Agents: What It Needs
10 min read · August 7, 2026
Ask ten agents whether they scrub against the federal do-not-call registry and most will say yes. Ask the same ten to email you their written do-not-call policy and you will get silence, then a question about whether that is a real thing.
It is a real thing. Federal rules require any person or entity making telemarketing calls to keep written procedures for an internal do-not-call list, and to hand that document over on demand. It is one page. It costs nothing. And it is the difference between having a defense and not having one, because the good-faith safe harbor that gets an accidental registry dial dismissed is conditioned on you having the policy, the training, and the records in the first place.
This is the version I wish someone had walked me through: what the document has to say, what the internal list actually is, the deadlines that apply, and how to build the whole thing in an afternoon.
Three different do-not-call lists, and only one is yours
Half the confusion here comes from agents treating “DNC” as one thing. It is at least three, and they behave differently:
- The National Do Not Call Registry. A government list you scrub against. You do not own it, you do not edit it, you subscribe and check your list against it on a schedule.
- State do-not-call lists. Several states run their own, and a handful of mini-TCPA statutes add requirements the federal rules do not.
- Your internal do-not-call list. The one you build, one name at a time, every time a human being tells you to stop calling. This is the list the written policy is about, and it is the one that gets agents sued.
The internal list is the strictest of the three in one important way: it overrides everything else. An existing business relationship does not let you call someone who asked you not to. Prior express written consent does not survive a revocation. A lead the prospect filled out yesterday does not reopen a door they closed last month. Scrubbing the registry is a separate job that does not touch this at all — the federal list will never know your prospect told you personally to lose their number.
What the written policy has to contain
The federal framework at 47 CFR 64.1200(d) sets out the minimum standards. Translated out of regulation language and into what an agent actually writes down:
| Requirement | What it means on your desk |
|---|---|
| Written procedures | A document that exists before the call, not a policy you describe from memory afterward. |
| Available on demand | If someone asks for it, you produce it. Keep it somewhere you can attach to an email in a minute. |
| Training | Anyone dialing on your behalf — a VA, a setter, a downline agent — is trained on the policy, and you can show when. |
| Record the request | When a prospect says stop, the name and number go on the internal list at the time of the call. |
| Honor it promptly | A reasonable time, not to exceed 30 days, under the internal-list rule. Revocation of consent is tighter — 10 business days. |
| Identify yourself | Every call states your name, the agency on whose behalf you are calling, and a contact number or address. |
| Affiliate scope | Define which related entities a request covers. If it would not be obvious to the consumer, do not assume it extends. |
| Retention | Internal do-not-call entries are honored on a five-year horizon. In practice: never delete one. |
Notice what is not on that list: nothing requires the document to be long, notarized, lawyer-drafted, or filed anywhere. It requires that it exist, that it be honest about what you actually do, and that your behavior match it. A one-page policy you follow beats a twelve-page template you have never read, and the twelve-page template you ignore is worse than useless — it is a written admission of a standard you failed to meet.
Why the safe harbor is the whole point
Here is the mechanic that makes this worth an afternoon. If you dial a number on the national registry by accident, there is a safe harbor available — but it is conditional. The call has to have been an error made in good faith, and you have to be able to show that you maintain written procedures, that you train the people who dial, that you keep records documenting the process, and that you used a version of the registry current enough to satisfy the scrub window.
Read that as a checklist, because that is how it gets read to you. Miss any element and the safe harbor is not weakened — it is unavailable. An agent with a clean scrub log and no written policy is in the same position as an agent with no scrub at all: arguing about damages instead of arguing about liability. At $500 per call, trebled to $1,500 for willful violations, that is not a distinction you want to be on the wrong side of when the plaintiff has a list of 40 dials.
This is also why the policy has to describe what you genuinely do. If it says you scrub weekly and your logs show monthly, you have handed over the evidence yourself.
The part agents get wrong: capturing the request
The written document is the easy half. The failure mode I see most often is procedural — the request gets made, the agent means to write it down, the next call connects, and it never happens.
A do-not-call request does not have to use magic words. “Take me off your list,” “stop calling me,” “I'm not interested, don't call back,” and a flat “lose my number” are all the same event. The FCC has been clear that revocation can be made in any reasonable manner, and it is not on the consumer to phrase it correctly or use your preferred channel. If they text it, email it, or say it to your VA, it counts.
Three rules that make this survivable at volume:
- One disposition, not a note. A free-text note is not a suppression. The request has to land in a field that actually blocks the next dial. If your disposition set does not have a hard DNC code wired to suppression, you are relying on the next person to read the note. They will not.
- Suppress the number, not the record. The same phone number can appear on three lead records from three sources. Suppression that only marks one record will let the other two ring through, which is how agents call the same angry prospect a fourth time and end up on the receiving end of a demand letter.
- Never ask them to confirm.Do not route a stop request into a “let me just verify a few things” conversation, and do not require a written form. Requiring the consumer to jump through a hoop to be left alone is exactly the fact pattern that turns a routine complaint into a willfulness argument.
Building the policy: a one-afternoon version
Open a document. Write these eight sections, in your own words, describing what you actually do. Date it and put a version number on it.
- Who this covers. Your name, your agency name, your callback number, and every person who dials on your behalf.
- How a request gets recorded. The exact disposition or field, and the instruction that it happens during the call, not at end of day.
- How fast it takes effect. State your standard. If your system suppresses immediately, say so — that is a better answer than the regulatory maximum.
- Scope. Which entities and product lines a request covers, and how you handle a number that appears on multiple lead records.
- Scrub cadence. Which lists you check, how often, and before which activity. Cover federal, applicable state lists, your internal list, and litigator screening if you use it.
- Calling hours.Your quiet-hours standard in the prospect's local time, plus any stricter state rules you follow.
- Training. Who gets trained, on what, how often, and where you keep the sign-off.
- Records. What you retain — call logs, consent records, scrub results, DNC entries — and for how long. Pair it with your consent record standard so the two documents do not contradict each other.
Then do the part that matters: read it back and ask whether it is true. Every sentence that describes something you do not actually do gets rewritten to describe what you do, or gets fixed in the workflow before it stays in the document.
If you have a VA, a setter, or a downline
The moment someone else dials on your behalf, two things change. First, the training requirement stops being theoretical — you need to be able to say when they were trained and on what. Second, a do-not-call request made to them is a request made to you, and it has to reach the same suppression list, in real time, from wherever they sit.
That is a systems problem, not a paperwork problem. If your setter keeps their own spreadsheet and sends you a weekly summary, there is a window measured in days where your suppression list is wrong and your dialer does not know it. Everyone dialing your book should be writing into the same records.
The quarterly self-audit
Twenty minutes, four questions. Put it on the calendar next to your pipeline cleanup:
- Pull every contact dispositioned DNC last quarter. Did any of them receive a dial after that date? If yes, the suppression is not wired correctly and nothing else on this list matters.
- Pick five numbers at random from last week's dials. Can you show the scrub result that cleared each one, and the consent record behind it?
- Does the policy document still describe your actual workflow, or has the workflow moved since you wrote it?
- Has anyone new started dialing on your behalf since the last audit? If so, where is their training record?
That audit is also the cheapest litigator defense you have. Professional plaintiffs look for repeat dials after a stated stop request, because that is the pattern that supports willfulness and triples the number. A clean suppression trail makes you a bad target long before it makes you a good defendant.
What software should carry
The policy is yours to write. The enforcement should not be yours to remember at dial 80 on a Friday. Whatever you dial with, it should be doing four things without being asked:
- A DNC disposition that suppresses the number itself, across every record it appears on, instantly.
- A block on the next dial to a suppressed number, rather than a warning you can click past.
- Quiet hours enforced against the prospect's local time zone, not yours.
- A log — dial time, caller ID used, scrub result, disposition — that you can export as a file rather than reconstruct from memory.
That last one is what turns your written policy from a claim into evidence. A policy says what you intended to do. The log says what happened. You want both, and you only get the second one if the tool writes it as a byproduct of dialing.
Make your do-not-call list enforce itself
FEXmagnet is a compliance-first CRM and single-line power dialer for life insurance agents — internal DNC suppression by phone number, registry and litigator scrubbing, quiet hours by prospect time zone, and an exportable call log behind every dial. From $29/mo, no contracts.
See Plans & Pricing