Debt Collection Compliance Software: FDCPA, Regulation F and TCPA Guardrails for US Creditors
Most collections platforms sell "compliance" without telling you which rules apply to you. Start from the other end: classify the debt, classify yourself, then let the software hold the line on windows, frequency, consent and the audit log.
Every attempt timestamped and exportable. Flat monthly fee, no percentage of what you recover.
No login, no card. You get a real FDCPA-compliant sequence, not a sample.
Debt collection compliance software enforces the contact rules before a message goes out: calling windows, contact frequency caps, consent and revocation handling, the exact amount you are allowed to demand, and a timestamped record of every attempt. For a US business collecting its own B2B invoices under its own name, the FDCPA and Regulation F generally do not apply, because the FDCPA covers debt incurred primarily for personal, family or household purposes and mainly regulates collectors chasing debts owed to someone else. What does bind you is the TCPA on any call or text to a wireless number, the fee and interest terms in your own contract, a handful of state statutes that reach original creditors directly, and state unfair-practices law. The right software is the one that can prove what it sent, to whom, at what hour, and on whose authority.
Last updated August 2026
Six controls that separate compliance software from a mail merge with a nice dashboard
Anyone can put an FDCPA badge on a pricing page. These are the controls that decide whether you can defend a sequence eighteen months later, when nobody remembers who pressed send.
Contact windows by recipient time zone
Regulation F sets 8am to 9pm in the consumer's local time. The failure mode is not malice, it is a scheduler that runs in the sender's time zone and quietly emails a West Coast customer at 6am Pacific because the queue fired at 9am Eastern. The window has to be resolved per recipient, not per account owner.
Frequency caps counted per debt
Regulation F presumes harassment above seven calls about a particular debt in seven consecutive days, and again inside seven days of a completed phone conversation about that debt. The cap counts per debt, so a customer with four overdue invoices needs four separate counters, not one. Software that caps at the customer level is measuring the wrong thing.
Consent capture and one-word revocation
Since April 11, 2025 a recipient can revoke consent by any reasonable method. The FCC named STOP, QUIT, END, REVOKE, OPT-OUT, CANCEL and UNSUBSCRIBE as reasonable replies to a text, and you cannot force people through a form instead. Revocation crosses channels: a STOP by text also stops the robocalls. You have up to ten business days to honor it.
Identity discipline in the sender name
First-party status is the whole basis for sitting outside the FDCPA, and it is exactly what a careless sender name throws away. Collecting your own invoice under a name that implies an outside agency can pull you into the federal rules, and Illinois bars collecting your own debt under a name conveying that a third party was engaged. Send as your own company, every time.
Only the amounts your contract authorizes
15 U.S.C. 1692f(1) bars collecting any amount, interest and fees included, unless the agreement creating the debt expressly authorizes it or law permits it. Even outside the FDCPA the same logic sinks claims under state unfair-practices law. The system should refuse to demand a late fee that is not in the signed terms, rather than trusting whoever typed the number.
An audit log you can hand to a lawyer
Every attempt, channel, timestamp, recipient time zone, template version, amount demanded and consent state, exported without a support ticket. This is the deliverable in a dispute, a state attorney general inquiry or a due diligence review. Screenshots of an inbox are not a record.
Work out which rules actually bind you, in four questions
Ten minutes with these four questions replaces most of what a vendor will tell you about compliance, and it changes which product you should buy.
-
Step 1
Classify the debt
Was the obligation incurred primarily for personal, family or household purposes? If yes, it is consumer debt and the whole federal apparatus is live. If it is a trade invoice between two businesses, the FDCPA definition at 15 U.S.C. 1692a(5) does not reach it. Mixed books mean you need both paths, split by account, not one policy applied to everything.
-
Step 2
Classify yourself
Are you collecting a debt owed to you, in your own name? That is first-party, and the FDCPA mostly regulates collectors of debts owed to another. Buying delinquent paper flips you into the third-party regime, licensing included. So does trading under a name that sounds like a collection agency.
-
Step 3
Map every channel to a rule
Email is the loosest. A business landline sits outside the federal do-not-call rules. A wireless number does not: an autodialed or prerecorded call or a text to a cell needs prior express consent whether the recipient is a consumer or a purchasing manager, and Florida, Oklahoma, Washington and Maryland mini-TCPA statutes go further than federal law.
-
Step 4
Turn the answers into settings, then log everything
Windows, caps, consent state and permitted amounts should live as enforced configuration, not as a page in an employee handbook. Then keep the log. The value of an audit trail is that it exists before anyone asks for it.
The rules people mean when they say debt collection compliance, and who each one actually binds
This is the table nobody publishes, because most collections vendors sell to agencies and can assume the FDCPA applies. If you collect your own B2B invoices, half of this grid is not your problem, and the half that is gets almost no attention.
| Rule | Who it binds | What it limits | Reaches a US business collecting its own B2B invoices? |
|---|---|---|---|
| FDCPA (15 U.S.C. 1692) | Mainly third-party collectors of debts owed to another | Communications, disclosures, harassment, false representations, unauthorized amounts | Generally no. Consumer debt only, and first-party creditors sit outside it unless they collect under a name implying an agency |
| Regulation F (12 CFR 1006, eff. Nov 30, 2021) | The same covered collectors, as the CFPB's implementing rule | 8am to 9pm local time, 7 calls in 7 days per debt, limited-content messages, email and text opt-out | Generally no, but its numbers are the de facto US standard and the cheapest defensible policy to adopt voluntarily |
| TCPA (47 U.S.C. 227) and FCC rules | Anyone placing calls or texts, B2B included | Autodialed and prerecorded calls and texts to wireless numbers, consent, revocation within 10 business days | Yes. This is the federal rule most B2B creditors actually have to manage |
| Texas Finance Code ch. 392 | "A person who directly or indirectly engages in debt collection", with no owed-to-another limit | Threats, misrepresentation, unfair practices, notice requirements | Only for consumer debt, but then it binds the original creditor too, which the FDCPA usually does not |
| New York GBL art. 29-H (600 to 603) | Any "principal creditor", defined as anyone to whom a consumer claim is owed | Contact conduct, harassment, disclosures | Only for consumer claims against a natural person. B2B invoices are outside it, but a NY business collecting from individuals is inside it |
| California Rosenthal Act, as amended | Debt collectors, and since SB 1286 certain commercial debt of $500,000 or less | Rosenthal conduct standards, private right of action | No, again. AB 1521, operative Jan 1, 2026, defines trade credit and excludes it from covered commercial debt. Most 2025 articles still describe the pre-AB 1521 position |
| State collection agency licensing and bonds | Third-party agencies and buyers of delinquent debt | Registration, surety bond ($5,000 to $300,000 by state), conduct rules | Generally no for your own accounts. Illinois is the outlier: IDFPR has informally told ACA that IL licensing reaches commercial collection |
| FTC Act section 5 and state UDAP statutes | Essentially every business | Unfair or deceptive acts, including inflated balances and fake legal threats | Yes. With the CFPB shrinking, this is where state attorneys general are the practical enforcer in 2026 |
This grid is general information about US law, not legal advice, and it does not create an attorney-client relationship. Statutes and effective dates were read at source on August 24, 2026. Get your own counsel before you change a collections policy, especially if your book mixes consumer and commercial accounts.
What does debt collection compliance software actually enforce?
Five things, and they are checkable in a demo rather than claimed on a pricing page. A contact window resolved in the recipient's time zone. An attempt counter that increments per debt. A consent state that a one-word reply can flip to blocked, instantly and across every channel. A demand amount constrained by the terms your customer actually signed. And an audit log you can export as a file without asking support.
Everything else sold under the compliance heading is either a template library, which every vendor has, or a state rule pack aimed at licensed agencies chasing consumer accounts. If you are a business collecting your own invoices, the rule packs solve a problem you do not have, and you are paying for them.
The reason the five controls above matter more than the badges is that they are the only parts of compliance that survive staff turnover. A collector's calling habits leave with the collector. A scheduler's configuration is still there, versioned and inspectable, eighteen months later when somebody asks what you sent and when. For which vendors do this well and which do not, we keep an honest roundup on the best debt collection software comparison page.
Does the FDCPA apply to a business collecting its own invoices?
Generally no, on two independent grounds. The FDCPA defines "debt" at 15 U.S.C. 1692a(5) as an obligation arising out of a transaction incurred primarily for personal, family or household purposes, so a commercial invoice between two businesses is outside the statute entirely. Separately, the definition of "debt collector" at 1692a(6) turns on collecting debts owed or due another, which is why a creditor collecting its own account in its own name is treated as a first-party creditor.
The exception is the one people trip over. If you collect under a name that suggests a third party is involved, a house agency with an official-sounding name, a letterhead that implies an outside recovery firm, you can lose first-party treatment. That is a naming decision, not a legal one, and it costs nothing to get right. Our page on first-party collections works through what stays in-house and what does not.
Two things this does not mean. It does not mean state law leaves you alone, because Texas and New York both regulate original creditors on consumer accounts. And it does not mean you should ignore Regulation F. Adopting its windows and caps voluntarily is cheap, is what a jury would consider reasonable, and removes the argument entirely.
What is Regulation F and what does it limit?
Regulation F is the CFPB rule at 12 CFR part 1006 that implements the FDCPA. It took effect on November 30, 2021 and replaced decades of informal interpretation with specific numbers, which is why it is the reference point even for creditors it does not legally cover.
The provisions that matter operationally are short. Calls are permitted between 8am and 9pm in the consumer's local time. There is a rebuttable presumption of harassment above seven calls about a particular debt within seven consecutive days, and a second presumption for calling within seven days of a phone conversation about that debt. Electronic messages must carry a clear, reasonable opt-out method. The limited-content message defines what you may leave on a voicemail without it counting as a communication that triggers third-party disclosure problems.
Two details are widely mis-stated. The call frequency limits attach to each individual debt, so a consumer who owes three accounts is subject to three separate counters. And the calling window keys on the consumer's location, so a national book of accounts needs per-recipient time resolution rather than one office-hours setting.
Does the TCPA apply to collection calls and texts to a business?
Yes, and this is the rule most B2B finance teams get wrong. Business-to-business calls and texts are subject to the same TCPA wireless restrictions as consumer ones. An autodialed or prerecorded call, or a text, to a wireless number generally requires prior express consent regardless of whether the person answering is a homeowner or a purchasing manager. Statutory damages start at $500 per call and treble for willful violations, so a modest text campaign to a list of cell numbers is a real exposure.
The federal do-not-call registry rules do carve out business landlines, which is why plain manual dialing to a company's main line is comparatively low risk. That carve-out disappears the moment the number is a mobile, and small business contacts are overwhelmingly mobile numbers that double as personal phones. Several state mini-TCPA statutes, notably Florida, Oklahoma, Washington and Maryland, apply restrictions to B2B contacts without the federal landline exemption at all.
Revocation is the other half. Since April 11, 2025, FCC rules let a recipient revoke consent by any reasonable method, including a one-word text reply, and revocation carries across channels: a STOP sent by text also ends the robocalls. You must honor it within a reasonable time, not exceeding ten business days, and you cannot designate an exclusive revocation method. A further FCC provision extending a single revocation to all future calls and texts from the business was delayed to April 11, 2026.
Is there a solution that can handle voice and text conversations with delinquent accounts while staying compliant with FDCPA?
Yes, and the compliance question for an AI system is the same as for a human one, because the FDCPA, Regulation F and the TCPA regulate the contact, not the technology. There is no separate federal AI collections statute. The CFPB has stated that firms are responsible for the conduct of their AI systems, which is the correct default: an automated voice that misstates a balance is the same violation as an employee who does it.
What changes with automation is that the guardrails become testable. A human collector's calling window is a habit. A scheduler's calling window is a configuration value you can inspect, version and audit. That is genuinely better for compliance, provided three things are true. The system must resolve the recipient's time zone rather than the sender's. It must count attempts per debt. And it must stop instantly on a revocation word rather than at the end of a queued campaign.
The pattern we recommend, and the one DebtAgent uses, is that the agent drafts and schedules and the system enforces, with a human able to inspect the full sequence before anything sends. Our AI debt collection page covers how the sequence is generated, and the collection call script page covers the language side for live calls.
Does the CFPB still enforce debt collection rules in 2026?
Less than it did, and the direction of travel matters for how you plan. Through 2025 and into 2026 the Bureau sharply reduced enforcement, supervision, staffing and rulemaking. A Department of Justice opinion concluded that Federal Reserve losses block the funding transfers the Bureau relies on, and the CFPB has indicated it expects to exhaust available funds in early 2026. Multiple cases, including a challenge to mass layoffs and a multi-state attorney general action, were still live in 2026.
Read that carefully before you relax. The FDCPA and Regulation F remain federal law whatever happens to the agency's budget. What shifts is who enforces them: the FTC, state attorneys general, and the private plaintiffs' bar, which never depended on CFPB funding in the first place. Private FDCPA suits and state unfair-practices claims are the practical risk in 2026, and neither is deterred by a quiet supervision calendar.
The planning conclusion is the boring one. Do not build a collections policy that is calibrated to the probability of a federal exam. Build one calibrated to what a state attorney general or an opposing lawyer would see in your audit log, because that is the audience that is definitely still there.
Do you need a collection agency license to collect your own accounts?
Generally no. Roughly 45 states license or register collection agencies, with surety bonds running from about $5,000 to $300,000, but the statutes are written around collecting for others. New York City's Administrative Code 20-489 is a clean example: it defines a debt collection agency as one whose principal purpose is collecting debts owed to another, includes buyers of delinquent debt, and expressly excludes an officer or employee of a creditor collecting, in the creditor's name, debts for that creditor. Illinois exempts persons whose collection activity is confined to and directly related to operating a business other than a collection agency.
Two situations flip you into the licensed world. Buying delinquent debt makes you a debt buyer, and most modern statutes reach debt buyers explicitly. Collecting under an assumed name that implies an outside agency does the same in practice, and Illinois bars it outright.
Illinois deserves a specific flag for anyone with a national book. The Collection Agency Act at 225 ILCS 425 carries a $25,000 bond through IDFPR, and IDFPR has given ACA informal guidance that Illinois licensing does reach commercial debt collection, which is unusual: California's Debt Collection Licensing Act, by contrast, is limited to consumer debt owed by a natural person. Our commercial debt collection laws pillar has the state-by-state detail, with dedicated pages for Illinois, New York and California.
What should a collections compliance audit log actually record?
Enough to reconstruct any single contact without asking a person what they remember. In practice that is nine fields per attempt: timestamp in UTC, the recipient's resolved local time, channel, recipient address or number, the account and specific invoice the attempt related to, the template or script version used, the amount demanded, the consent state at the moment of sending, and the identity the message was sent under.
The per-invoice field is the one teams skip and then need. Regulation F counts calls per debt, so a log keyed only to the customer cannot demonstrate you stayed under the cap. Template version is the second. Six months after a policy change you will be asked what the message said on a specific date, and "we updated the wording at some point in March" is not an answer.
Retention should outlast the limitation period you are actually exposed to. FDCPA claims carry a one-year limit from the violation, but the underlying contract claim runs four to ten years depending on the state and whether the sale was of goods, and a dispute over the debt often drags the collection history in with it. Keeping the log for the life of the receivable plus a year costs almost nothing and settles arguments quickly.
Compliance settings we would use for a mixed consumer and commercial book
Most US businesses that sell to both individuals and companies end up wanting one policy, because two policies means someone eventually applies the wrong one. The cheapest defensible answer is to run the stricter consumer standard everywhere and accept that you are over-complying on the commercial side.
- Contact window: 8am to 9pm in the recipient's local time, applied to email and text as well as calls, even though Regulation F's window is written for calls.
- Frequency: a hard cap of seven contact attempts per debt per seven days, counted per invoice, with a seven-day pause after any completed phone conversation about that debt.
- Channel default: email first, escalating to text or voice only where you hold recorded consent for that number, and never autodialed or prerecorded to a mobile without it.
- Revocation: honored immediately on any recognizable stop word, across all channels, with a hard system block rather than a note in a CRM field.
- Amounts: interest and late fees demanded only where the signed terms authorize them, at the contracted rate, with the clause reference stored against the demand.
- Identity: every message sent as your own trading name, with a real reply address monitored by a human.
None of this reduces recovery. The evidence runs the other way: accounts worked consistently under 90 days past due recover well above 70 percent, while accounts past 180 days often recover under 15 percent, so the win comes from starting early and staying regular, not from contacting more aggressively. The practical sequence is covered in unpaid invoice collection and, for the escalation point, the demand letter stage.
Debt collection compliance questions people actually ask
What is debt collection compliance software?
Debt collection compliance software enforces contact rules automatically before a message sends: permitted calling hours in the recipient's time zone, attempt caps per debt, consent and revocation state, the amounts your contract authorizes you to demand, and a timestamped audit log of every attempt. It shifts compliance from staff discipline to enforced configuration you can inspect and export.
Does the FDCPA apply to B2B debt collection?
No, in almost all cases. The FDCPA at 15 U.S.C. 1692a(5) defines debt as an obligation incurred primarily for personal, family or household purposes, so a commercial invoice between two businesses falls outside the statute. It also mainly regulates collectors of debts owed to another, so a business collecting its own account in its own name is a first-party creditor.
What is the 7 in 7 rule in debt collection?
Regulation F creates a rebuttable presumption of harassment when a collector places more than seven calls about a particular debt within seven consecutive days, or calls within seven days after a completed telephone conversation about that debt. The count is per debt, not per person, so a consumer with three accounts is subject to three separate counters.
Can I text a business customer about an overdue invoice?
Only with prior express consent if the number is a wireless number, which most business contact numbers are. The TCPA applies to business-to-business texts on the same terms as consumer texts, with statutory damages from $500 per message. Florida, Oklahoma, Washington and Maryland mini-TCPA statutes go further than federal law.
How quickly do I have to honor an opt-out request?
Within a reasonable time not exceeding ten business days, under FCC rules effective April 11, 2025. Consumers may revoke by any reasonable method, including replying STOP, QUIT, END, REVOKE, OPT-OUT, CANCEL or UNSUBSCRIBE to a text, and you cannot require a specific form. A revocation in one channel extends to both robocalls and robotexts.
Is AI debt collection legal in the United States?
Yes. There is no separate federal statute regulating AI in collections, because the FDCPA, Regulation F and the TCPA regulate the contact rather than the technology behind it. The CFPB has stated that firms are responsible for the conduct of their AI systems, so an automated message that misstates a balance is the same violation as a human one.
Do I need a license to collect my own business debts?
Generally no. State collection agency statutes are written around collecting debts owed to another, and typically exempt a creditor collecting its own accounts in its own name. Buying delinquent debt flips you into the licensed regime, and Illinois separately bars collecting your own debts under a name suggesting a third party was engaged.
Is the CFPB still enforcing debt collection rules in 2026?
Its capacity is sharply reduced. Enforcement, supervision and staffing were cut through 2025 and 2026, and the Bureau has signaled it expects to exhaust available funds in early 2026. The FDCPA and Regulation F remain law, with the FTC, state attorneys general and private plaintiffs as the practical enforcers.
You are handing us your customers' names. Here is what happens to them.
Collections data is unusually sensitive, so we treat it that way: TLS in transit, encrypted storage, a full compliance audit log, and debtor records that are never used to train public models. Card details go to Stripe and never touch us. Account deletion means delete, everywhere. We are also honest about where we are not yet: no SOC 2 report yet, no SSO yet, no invented customer logos or testimonials either.
See the exact sequence before a single message leaves your account
Load one overdue invoice and the agent drafts the whole escalation with the windows, caps and consent state already applied. Inspect every step, export the audit log, then decide. Flat monthly fee, no percentage of what you recover.
-
Comparison Best debt collection software compared for US teams Which platforms serve agencies, which serve creditors, and what each one actually publishes about price.
-
Product AI debt collection that drafts and sends the sequence How the agent writes, schedules and escalates, with the guardrails enforced rather than documented.
-
Strategy First-party collections services and what to keep in-house Where first-party status comes from, what it is worth, and the naming decisions that quietly destroy it.
-
Pillar Commercial debt collection laws by state Statutes of limitation, interest, licensing and enforcement, with the traps published tables get wrong.
-
Product B2B collections software and credit and collections tools Built for the business collecting its own invoices, not for an agency working someone else's book.
-
Guide FDCPA compliant collection letters and what to include The language that keeps a written demand defensible, with the disclosures that belong on a consumer account.
-
payment reminder software Payment reminder software: invoice reminder software with automated payment reminders that do not stop at three
-
xero accounts receivable Xero accounts receivable automation: Xero invoice reminders and payment reminders that keep going after Xero stops
-
dunning software Dunning Software: Automated Dunning Management Software for B2B Invoices
-
bill.com pricing Bill.com Pricing: Plans, Per User Cost and What BILL AP and AR Really Costs a US Finance Team