{
  "id": "CON-VERBAL-SCRIPT",
  "slug": "con-verbal-script",
  "title": "Verbal opt-in requires the documented script",
  "statement": "A campaign collecting consent by phone must supply the exact script read to the consumer.",
  "rationale": "A verbal opt-in leaves no artifact unless you make one — there is no page to crawl and no box to screenshot. The script IS the consent surface, so it is the only thing a reviewer can inspect to decide whether what your agents say actually obtains consent.",
  "layer": "CONSENT_FLOW",
  "layerSlug": "consent-flow",
  "object": "campaign.message_flow + consent artifact",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_ARTIFACT",
  "artifact": "verbal_script",
  "authorities": [
    "TCR",
    "FCC",
    "Aerialink"
  ],
  "applicability": {
    "consentMethods": [
      "verbal_live",
      "verbal_ivr"
    ]
  },
  "applicabilityText": "Applies when consent was collected by live verbal and IVR.",
  "universal": false,
  "remediation": "Attach the verbatim script your agents read, not a summary of it. We can generate a compliant script covering all eight required elements, which you can adapt and hand to your team.",
  "pitfalls": [
    "\"Agents ask for permission to text\" describes a policy, not a script — a reviewer cannot audit it."
  ],
  "catalogIds": [
    "CMP-108"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/consent-flow/con-verbal-script/",
  "markdown": "https://ekas.io/rules/10dlc/consent-flow/con-verbal-script.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
