TCPA readiness: A practical checklist for utilities and regulated industries

By Convey News
September 3, 2026 8 min read
Share this post
news icon

The rules around consumer consent and opt-outs are changing. Is your organization ready?

For utilities and other regulated organizations, customer communications often span multiple departments, systems and channels. A single customer may receive texts, calls and other automated communications from different parts of the organization, making consent management and revocation more complex.

As TCPA requirements evolve, organizations need more than an opt-out process for a single communication channel. They need a coordinated approach that respects a customer’s choice across the organization.

This TCPA readiness checklist outlines key steps organizations can take to prepare, from honoring reasonable opt-out requests to maintaining consent records, training employees and vendors, and regularly monitoring compliance.

Important: This checklist is for informational purposes only and does not constitute legal advice. Organizations should consult their legal counsel to ensure full compliance with the TCPA and related regulations.

1. Honor all reasonable opt-out requests

Customers may communicate their desire to stop receiving messages in a variety of ways. Your organization needs to recognize and honor those requests, regardless of how they are submitted.

That can include responding to a text with universal keywords such as “stop,” “revoke,” “quit,” “end,” “cancel,” “opt out,” or “unsubscribe.” It can also include asking an agent to stop communications over the phone or unsubscribing through an online experience.

The key is having processes in place to recognize a clear request to stop receiving communications and act on it.

What to do

Review the ways customers can currently revoke consent and confirm that each method is supported by your communication systems and workflows.

2. Apply opt-outs across the entire organization

An opt-out should not be treated as a department-level preference.

When a customer revokes consent, that choice needs to be reflected across the organization, including relevant channels, departments and business units. Selective opt-outs by program or department can create the risk of continued communications after a customer has asked to stop them.

For organizations with multiple communication programs, this is especially important. Customer preferences need to follow the customer, not remain isolated within the system where the original opt-out was received.

What to do

Review your current systems and determine whether a customer’s revocation is automatically shared across the organization or whether individual teams and systems manage opt-outs separately.

3. Process revocation requests within ten business days

Having an opt-out process is only part of the equation. Organizations also need workflows that acknowledge and fully implement revocation requests within the required timeframe.

The checklist calls for systems and workflows that can process opt-out requests within ten business days.

What to do

Document how a revocation request moves through your organization, from the initial request to the point where the customer’s preference has been fully implemented. Look for manual steps or disconnected systems that could slow the process down.

4. Provide clear unsubscribe instructions in every communication

Customers should not have to search for a way to stop receiving non-emergency communications.

The checklist recommends including prominent opt-out instructions in every non-emergency message so customers can easily understand how to revoke consent.

Clear instructions can reduce confusion and make it easier for customers to exercise their communication preferences.

What to do

Review your existing non-emergency messages across channels. Are the unsubscribe or opt-out instructions easy to find and understand?

5. Maintain comprehensive consent and revocation records

Compliance doesn’t stop when an opt-out has been processed. Organizations also need a reliable record of consent and revocation activity.

The checklist recommends maintaining detailed consent and opt-out records for at least four years. These records can support audits, regulatory reviews and internal compliance tracking.

What to do

Review how your organization captures, stores and retrieves consent and revocation records. Make sure the information is accessible when needed and reflects the customer’s current communication preferences.

6. Distinguish emergency from non-emergency communications

Not every customer communication serves the same purpose, and organizations should clearly distinguish between emergency and non-emergency messages.

The checklist identifies examples of emergency communications such as outage and life-safety alerts, while examples of non-emergency communications include bill reminders and energy efficiency tips. Organizations should define which messages fall into each category and document that approach.

This distinction matters because emergency alerts are treated differently from non-emergency communications under the checklist’s TCPA framework.

What to do

Inventory your communication programs and document which messages are considered emergency communications and which are not.

7. Prepare for cross-channel opt-out logic

As communication programs become more connected, organizations need to think beyond individual channels.

The checklist calls for organizations to update their systems so a single opt-out can automatically apply to future automated communications across calls, texts and other channels. It also recommends testing these workflows ahead of the April 2026 deadline identified in the checklist.

The goal is to eliminate ambiguity and prevent partial opt-outs where a customer stops communications on one channel but continues receiving automated communications through another.

What to do

Test your current opt-out workflows across channels. If a customer revokes consent through one channel, determine what happens to future automated communications through the others.

8. Train staff and coordinate vendors

TCPA readiness isn’t only a technology issue. Employees and third-party vendors also play a role in how customer communication preferences are handled.

Utilities and other organizations may have communication programs spread across multiple business units and systems. Employees need to understand the updated rules and internal processes, while vendors need to support the organization’s cross-channel revocation logic.

What to do

Review employee training, internal procedures and vendor requirements. Confirm that everyone involved in customer communications understands how revocation requests should be handled.

9. Audit and monitor compliance regularly

TCPA readiness shouldn’t be a one-time project.

Regular reviews of communication programs, system logs and revocation handling can help organizations identify gaps and areas for improvement. The checklist recommends ongoing monitoring to support adherence to TCPA requirements and strengthen trust with both customers and regulators.

What to do

Establish a regular review process for communication programs and opt-out activity. Look for recurring issues, gaps between systems and opportunities to improve how revocation requests are handled.

A more connected approach to TCPA readiness

For organizations managing communications across multiple channels, departments and vendors, TCPA readiness requires coordination.

The goal isn’t simply to give customers a way to opt out. It’s to create processes and systems that recognize those requests, apply them across the organization, maintain accurate records and consistently respect customer preferences.

That means looking at the entire communication ecosystem, including the people, processes, technology and vendors involved in customer outreach.

Ready to take a closer look at your TCPA readiness?

Explore how Convey can help organizations enforce compliance across automated communications.

Learn how you can enforce compliance with Convey

Download now

Get your TCPA checklist

Be better prepared for the upcoming TCPA changes. Download the checklist to help your team put compliant communication into practice.

TCPA readiness FAQ

What is TCPA readiness?

TCPA readiness means having the processes, systems and workflows needed to appropriately manage consumer consent and revocation requests. This includes honoring reasonable opt-outs, applying those preferences across the organization, maintaining consent records and regularly monitoring compliance.

What counts as a reasonable opt-out request?

A consumer can communicate their desire to stop receiving communications through a variety of reasonable methods. The checklist specifically identifies text responses using keywords such as “stop,” “revoke,” “quit,” “end,” “cancel,” “opt out,” or “unsubscribe,” as well as requests made through an agent or an online unsubscribe process.

Should an opt-out apply across multiple communication channels?

The checklist recommends applying a customer’s opt-out across the organization and preparing systems to automatically apply a single opt-out to future automated communications across calls, texts and other channels.

How quickly should an organization process a revocation request?

The checklist recommends setting up systems and workflows to acknowledge and fully implement opt-out requests within ten business days.

Do non-emergency communications need opt-out instructions?

The checklist recommends including prominent opt-out instructions in every non-emergency message.

How long should consent and opt-out records be kept?

The checklist recommends keeping detailed consent and opt-out records for at least four years.

How should organizations prepare their employees and vendors?

Organizations should train employees on the applicable rules, update internal processes and confirm that third-party vendors support the organization’s cross-channel revocation logic.

How often should TCPA compliance be reviewed?

TCPA readiness should be monitored regularly. The checklist recommends periodically reviewing communication programs, system logs and revocation handling to identify areas for improvement and support ongoing compliance.

Is this checklist legal advice?

No. The checklist is intended for informational purposes only and does not constitute legal advice. Organizations should consult their legal counsel regarding compliance with the TCPA and related regulations.