DNC Compliance Certificate: What Auditors Ask For

DNC LATAM · Compliance guides

A DNC compliance certificate is a dated record showing that a specific calling list was checked against a specific release of a Do Not Call registry before it was dialed. It exists to answer one question on demand: for this campaign, on this date, can you prove the numbers were clean? A certificate that can’t answer that — because it’s missing the registry release, the date, or the exact list it covers — won’t hold up when a client or regulator asks for it.

What a certificate actually needs to contain

Teams that build their own scrubbing process often stop at “we ran the check” and don’t keep anything that documents it. A certificate that actually holds up needs four things:

  • Which registry and country the list was checked against — Mexico and Argentina run separate registries from the US National DNC list, so a US-only compliance stack producing a certificate says nothing about LATAM exposure.
  • Which release of the registry was used. Registries update on a cycle, not continuously, so “checked against the DNC registry” is meaningless without saying which version.
  • The date of the scrub, and how close that date is to the actual dial date. A scrub from six weeks ago doesn’t cover a campaign dialing today.
  • Which numbers were suppressed as a result, so the certificate ties back to an identifiable list rather than a general statement that scrubbing happened.

This is the same structure covered in our guide to how DNC scrubbing works — the certificate is the byproduct of that process, not a separate step bolted on afterward.

Why a spreadsheet of “numbers we called” isn’t a certificate

The most common gap we see is a call log with no scrub reference attached to it. A call log shows who was dialed. It doesn’t show that those numbers were checked against anything before the call was placed, on what date, or against which registry release. Auditors distinguish between the two immediately, and the distinction matters most in the moment it’s needed: after a complaint has already been filed, when the campaign that generated it is the one under review.

The other common gap is a scrub that happened, but with no artifact kept from it. A team runs a check, gets a clean list back, dials the campaign, and moves on — without saving anything that documents the check itself. Six months later, when a client’s compliance team asks for evidence, there’s nothing to produce. The scrub may have been done correctly; it just can’t be proven.

The questions auditors actually ask

In practice, an audit of outbound calling compliance doesn’t start with “show me your process.” It starts with specifics tied to a real campaign:

  • Which registry release was this list checked against, and on what date?
  • How many days elapsed between the scrub and the first dial in this campaign?
  • Can you produce the certificate for this specific campaign, not just a general statement that scrubbing is part of your workflow?
  • Who retains this record, and for how long — is it the same team running the campaign, or a separate compliance function?
  • For numbers with prior consent, is there a separate record showing that consent, distinct from the scrub certificate itself?

None of these questions are about whether your process is good in the abstract. They’re about whether you can produce a specific, dated artifact for a specific campaign, on request. Our DNC compliance checklist for nearshore call centers covers the broader set of records — scrub certificates, consent logs, and calling-hours documentation — that a BPO or in-house team needs to keep in parallel, since certificates alone don’t cover consent or calling-window compliance.

Retention: how long to keep certificates

The right retention window is set by the client contract or the applicable audit period, not by convenience — if you don’t already have a defined window, default to keeping certificates at least as long as you’d keep the underlying call records, and confirm the actual requirement with whoever owns compliance for the account. What trips teams up isn’t a written retention policy so much as where the certificates live. A certificate saved to one person’s inbox or a shared drive that gets reorganized every few months is effectively unretrievable, even if it technically still exists somewhere. Centralizing certificates — one system, indexed by campaign and date — is what makes “can you produce it” answerable in minutes instead of a multi-day search.

Where certificates fit for teams calling Mexico and Argentina

US teams that already run a mature TCPA compliance stack sometimes assume the certificate process transfers directly when they start dialing into Mexico or Argentina. It doesn’t, because the underlying registries are different — see TCPA vs. Mexico and Argentina DNC rules for where that assumption breaks down. A certificate covering a US scrub says nothing about whether the same numbers were checked against Mexico’s or Argentina’s registry, and a regulator or client auditor reviewing LATAM campaigns will ask for the LATAM-specific record. If you’re scrubbing lists manually today, our step-by-step guide to scrubbing against Mexico’s DNC registry walks through generating that certificate as part of the process, and covers what to keep alongside it.

The practical fix for teams that don’t want to build and maintain this as a manual step is to make the certificate a byproduct of the scrub itself rather than a separate task someone has to remember to do. DNC LATAM attaches a dated certificate — registry, release, date, and suppressed numbers — to every supported-country scrub through its API or CSV upload, so the record exists automatically instead of depending on someone saving a file correctly every time. That also means the certificate is generated at the same moment as the scrub, closing the gap between “we checked” and “we can prove we checked” that shows up during an actual audit.

The product page for that artifact is DNC Compliance Certificates from Official Registry Checks. This post stays the auditor how-to.