DNC Playbook for Loan Officers: 31 Day Scrubs, 10 Day Revoca

Step by step DNC playbook for loan officers: automate 31 day scrubs, honor revocations in 10 business days, and keep audit ready records.

Step by step DNC playbook for loan officers: automate 31 day scrubs, honor revocations in 10 business days, and keep audit ready records.

DNC Playbook for Loan Officers: 31 Day Scrubs, 10 Day Revocations

Decorative DNC compliance playbook title card

Mortgage originators must comply with both the Federal Trade Commission’s Telemarketing Sales Rule and the Federal Communications Commission’s TCPA rules before making a single outbound call. The immediate next step is to subscribe to the National Do Not Call Registry, scrub calling lists every 31 days, centralize opt-out capture in one system, and honor revocation requests within about two weeks or less. If you buy leads or use a vendor, confirm the consent chain before anyone dials.


TL;DR:

  • Mortgage originators must maintain a scrub list from the National Do Not Call Registry that is no more than 31 days old before each call.
  • Consent for calls must be fully documented, including timestamp, source, channel, and when revocation requests are honored within 10 business days.
  • Internal suppression lists should flag all consumer requests not to be contacted, regardless of how the request was made, and should be automatically integrated into calling workflows.
  • A mortgage-specific CRM can automate list scrubbing, consent management, and revocation propagation, reducing compliance risks.
  • Oversight of third-party vendors, including audit rights and strict contract requirements, is essential to prevent violations and liability.

Loan Officer AI
Keep Mortgage Follow Up Organized
LoanOfficer.ai centralizes follow ups, opportunity detection, and pipeline management for mortgage professionals using AI technology.
Explore LoanOfficer.ai

Table of Contents

Which federal rules and agencies govern mortgage calling

Two federal frameworks apply to every outbound mortgage call, text, or voicemail drop. The TCPA, enforced by the FCC, governs autodialed and prerecorded calls and texts, and its recent report and order tightened how consent can be revoked and how quickly callers must act on it. The FTC’s Telemarketing Sales Rule works alongside it, and it is the rule that ties directly to the National Do Not Call Registry, which the FTC manages and enforces against sellers who call numbers they had no right to call.

For mortgage originators specifically, the Consumer Financial Protection Bureau adds another layer. Its examination procedures expect a compliance management system that covers outbound calling, staff training, and oversight of any third party making calls on the lender’s behalf. State attorneys general can pursue parallel claims, so a program built only around federal minimums often misses state-level exposure.

Turning the rules into a marketing automation checklist: step-by-step guide for SMBs

Once you know which rules apply, the work becomes operational. Scrubbing, list maintenance, and timing restrictions are not optional housekeeping, they are the tasks that determine whether a violation is a paperwork fix or a lawsuit.

Access to the registry requires a subscription account and, per the FTC’s guidance, a Subscription Account Number tied to the specific area codes you call, or a nationwide subscription if your calling footprint is broad. The Telemarketing Sales Rule requires using a registry file no more than 31 days old at the time of any call, so a scrub scheduled on a calendar reminder rather than a fixed system trigger tends to slip past that window during busy months.

Beyond the federal list, every mortgage team needs its own internal do-not-call list built from every consumer who has ever asked not to be contacted, regardless of whether that request came by phone, text, email, or a website form. Calling hours are also fixed: telemarketing calls to residential numbers cannot happen before 8 a.m. or after 9 p.m. in the recipient’s local time zone, and callers must identify themselves and their company at the start of the call.

Before any campaign launches, confirm these items:

  • The calling list reflects a DNC scrub completed within the last 31 days.
  • Every record carries a consent provenance field showing where and when consent was captured.
  • Numbers on the internal suppression list are flagged and excluded automatically.
  • Any established business relationship or written consent exemption is documented, not assumed.

How to capture, verify, and honor consent and revocation

Consent comes in two forms, and mixing them up is one of the most common mortgage compliance failures. Prior express consent covers some non-telemarketing calls, but telemarketing robocalls and texts generally require prior express written consent, a distinction the FCC’s one-to-one consent FAQs walk through in detail, including when a signature or clear digital agreement tied to a single seller is required rather than a blanket opt-in shared across multiple companies.

A checkbox alone rarely proves consent later. Capture the full record instead:

  1. Log the exact consent language shown to the consumer at the moment they agreed.
  2. Timestamp the agreement and store the source, such as a landing page URL or form ID.
  3. Record the phone number and channel the consent covers, since consent for calls does not automatically cover texts.
  4. Save this record in a system every calling agent and vendor can query before dialing.

Revocation has to move just as fast in the other direction. Under the FCC’s FCC-24-24 order, a consumer can revoke consent through any reasonable method, a text of “stop,” a verbal request mid-call, or an email, and the caller must honor it within 10 business days across every system that might otherwise dial that number.

Pro Tip:Send an automated confirmation text or email the moment a revocation is logged, timestamped separately from the internal suppression update, so you have two independent records if the request is ever challenged.

Why vendor and lead-generator oversight cannot be an afterthought

Sellers have been held responsible for what their telemarketing vendors do on their behalf, and mortgage lead generation is a frequent source of these disputes. A 2013 FTC settlement against a mortgage broker built on telemarketer misconduct, resulting in a $7.5 million payment, is the kind of fact pattern that keeps repeating when oversight is thin.

Contracts with lead vendors should require, at minimum:

  • A documented consent chain showing exactly how and where each lead opted in.
  • The vendor’s own SAN and scrub cadence, not just yours.
  • Audit rights letting you sample lead files and consent records on demand.
  • Indemnity language that shifts liability back to the vendor when its consent claims prove false.

Sampling a portion of purchased leads each month and pulling proof-of-consent metadata on demand should be standard practice, and a vendor who cannot produce that metadata quickly is a termination trigger, not a negotiation point.

What a defensible, audit-ready compliance file looks like

Safe harbor under the TSR depends on being able to show your process, not just claim it. That means maintaining a written DNC policy, employee training records, scrub receipts, an internal suppression list, and review documentation.

For each outbound contact, record:

  • Consent metadata, including source, timestamp, and channel.
  • The date of the most recent registry scrub applied to that number.
  • Any opt-out or revocation flag and when it was applied.
  • A note on call recording or transcript status where state law allows recording.

TCPA violations can carry statutory damages of $500 to $1,500 per call, a figure private plaintiffs’ attorneys cite directly from the statute, which is why a single mishandled list can turn into thousands of exposed calls before anyone notices.

Where enforcement actually lands and what to fix first

Exposure comes from four directions: FTC actions under the TSR, FCC enforcement under the TCPA, state attorney general suits, and private TCPA litigation, which has become the most frequent path because the statute allows individual consumers to sue directly.

The fact patterns that repeat are predictable: mass calls to numbers never scrubbed against the registry, opt-out requests logged but never propagated to every system, thin vendor oversight, and autodialed texts sent without proper written consent. If an audit turns up a gap, fix the suppression list synchronization first, then the vendor contracts, then the training records, since those three account for most of the exposure mortgage teams carry.

How a mortgage-specific CRM closes these gaps automatically

Manual scrub schedules and spreadsheet suppression lists are where most gaps start. A CRM built for mortgage compliance workflows can close them by design rather than by reminder.

  • A centralized suppression list that every campaign, agent, and integrated dialer checks before a call goes out.
  • Scheduled scrub automation that refreshes against the registry inside the 31-day window without manual tracking.
  • Single-source consent metadata attached to each contact record instead of scattered across forms and spreadsheets.
  • Automated revocation workflows that propagate an opt-out to every channel the moment it is logged.

Pro Tip:When evaluating any CRM for compliance fit, ask vendors to demonstrate the audit export directly, a real suppression list report with timestamps, not a slide describing the feature.

What the rules get wrong and where teams should actually focus

Most mortgage compliance advice treats the Do Not Call Registry as the finish line, and that misses where the real risk sits. The registry scrub is the easiest part to automate and the easiest part regulators can verify, so it gets disproportionate attention relative to the damage it actually prevents.

What the rules get wrong and where teams should actually focus — overview diagram

The bigger exposure lives in consent documentation and revocation propagation, the parts that require a system, not a one-time task. A team that scrubs perfectly every 31 days but stores consent as a checked box with no timestamp or source is still one lawsuit away from a costly outcome, because a plaintiff’s attorney will ask for the provenance record, not the scrub log.

If you take one thing from this, prioritize the plumbing that connects opt-outs across every channel over the plumbing that connects to the registry. The registry rewards you for compliance on paper. Revocation handling and consent metadata are what a court or the FCC actually examines when something goes wrong, and they are the parts a manual process is most likely to fail.

— Jared Hart

Putting these controls into practice with LoanOfficer.ai

Building this infrastructure by hand across spreadsheets, dialers, and a separate CRM is exactly the kind of fragmented setup that creates compliance gaps in the first place. LoanOfficer.ai centralizes the pieces this guide describes into one system built for mortgage teams.

Loan Officer AI

  • A built-in suppression list that syncs across every automated campaign and the smart dialer.
  • Consent and revocation metadata stored on the contact record, not buried in a separate form tool.
  • Audit-ready exports you can hand to a compliance officer or regulator without rebuilding the report.

Plans start with Starter at $197 per month, with Team and Brokerage tiers available as your outbound volume grows. If you want to see the suppression and audit workflow firsthand, you can start a trial and walk through it on your own list.

Key regulator pages and rule texts to bookmark

Bookmark Donotcall, the FCC’s revocation rule extension notice, and current FTC fee guidance for quick reference.

Sources

FAQ

Is there a federal Do Not Call list?

Yes, the National Do Not Call Registry is a federal list managed by the FTC at donotcall.gov, where consumers register their numbers and sellers subscribe to download and scrub against them. Telemarketers must use a copy of the registry no more than 31 days old before calling.

What does DNC mean in real estate and mortgage marketing?

DNC stands for Do Not Call, referring to a consumer’s registration on the national registry or a company’s internal suppression list requesting no telemarketing contact. In mortgage and real estate marketing, it applies to any outbound call, text, or voicemail drop used to solicit business.

Is it illegal to call someone on the DNC list?

Calling a number on the National Do Not Call Registry for telemarketing purposes is prohibited unless an exemption applies, such as an established business relationship or documented prior express written consent, as described in the FCC’s one-to-one consent guidance. Violations can trigger FTC or FCC enforcement as well as private lawsuits.

What does DNC stand for in the mortgage and finance industry?

DNC stands for Do Not Call, the same designation used across telemarketing law generally, and it governs outbound calls, texts, and prerecorded messages from mortgage originators and lenders. Mortgage teams must track both the federal registry and their own internal DNC list built from direct consumer requests.

How quickly must a mortgage company honor a revocation request?

Under the FCC’s consent revocation order, a caller must implement a revocation request within a reasonable time not to exceed 10 business days, regardless of which channel the consumer used to revoke. That requirement applies across every system the number appears in, not just the one where the request was received.

Recommended

One email. Everything that matters in mortgage.

Rate movement, industry news, new wholesale programs, upcoming conferences and compliance updates — every weekday morning.

No spam. Unsubscribe anytime.

See it in action

Reading about it is step one. Watch it run.

See the tactics from this article running inside a real loan officer CRM — follow-up, campaigns and pipeline in one place.

  • AI-written campaigns and follow-up
  • Every lead answered 24/7
  • Pipeline, dialer and calendar built in
LoanOfficer.ai demo — full walkthrough

See the real software — no signup needed

Start 14-Day Trial — $1Watch the full demo →

$1 for 14 days.