{
  "id": "CON-VERBAL-RECORD",
  "slug": "con-verbal-record",
  "title": "Verbal consent must describe how assent is recorded",
  "statement": "The flow must state how the consumer’s spoken agreement is captured and retained — recording, transcript, IVR log, or timestamped CRM entry.",
  "rationale": "Spoken consent evaporates unless it is written down. If a complaint arrives eighteen months later, the retained record is the only thing standing between you and an unprovable claim, and both the FCC and CTIA expect the record to exist.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "campaign.message_flow",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "FCC",
    "CTIA",
    "TCR"
  ],
  "applicability": {
    "consentMethods": [
      "verbal_live",
      "verbal_ivr"
    ]
  },
  "applicabilityText": "Applies when consent was collected by live verbal and IVR.",
  "universal": false,
  "remediation": "Add a sentence to the message flow describing capture and retention. Name the system of record and what is stored against the customer.",
  "example": "Calls are recorded, and the agent logs the consent timestamp, the script version read, and the number consented against the customer record in our CRM. Records are retained for at least 4 years.",
  "pitfalls": [
    "Two-party consent states constrain call recording — where you cannot record, log the timestamp and script version instead."
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-verbal-record/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-verbal-record.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
