The Federal Communications Commission has revised its Telephone Consumer Protection Act rules to make consent revocation more specific and to help financial institutions continue sending urgent fraud notifications. The change removes a central implementation risk for credit unions, but it also creates a concrete systems task: consent and revocation records must follow message purpose across calling, texting, service platforms and third-party vendors.

The commission adopted the Report and Order and Further Notice of Proposed Rulemaking at its September 30 meeting. America’s Credit Unions summarized the final action on October 1 and said the commission approved it unanimously.

What the order changes

The final order allows a caller to interpret a revocation request as applying only to the category of informational robocalls to which the request was directed. A member who opts out of one class of messages therefore does not necessarily revoke consent for unrelated categories. The order also permits callers to designate an exclusive revocation method and modifies the financial-institution exemption so fraud-related account alerts can be delivered more readily.

The practical distinction is purpose, not simply phone number or vendor. A marketing message, a service reminder, a collections call and a suspected-fraud alert can share infrastructure while relying on different authority. Credit unions need a message taxonomy that maps each communication to its purpose, consent basis, permitted channel, responsible owner and suppression rule.

Consent must travel with the member and the message

A compliant design cannot leave revocation logic inside one campaign platform. The authoritative record should reconcile contact-center systems, core data, digital banking, fraud platforms, loan servicing, collections, marketing automation and any vendor that initiates calls or texts. The member’s request, the category affected, the time received and the systems updated should remain traceable.

Teams should test ambiguous language as well as explicit commands. “Stop these payment reminders” is different from “stop all calls.” The workflow should preserve the original request, apply the approved interpretation, update every affected system and give employees a clear escalation path when the member’s intent is uncertain.

The member-communications review guide can support message ownership and approval, while the policy-maintenance framework shows how a regulatory change should move from source text into policy, procedures, configuration, training and retained evidence.

The further proposal keeps implementation moving

The accompanying proposal asks about the time allowed to honor revocation, two-way texting, a method for members to revoke all robocalls and texts, and how affiliate communications should be treated. Feedback to America’s Credit Unions is due October 19; FCC comments will be due 30 days after Federal Register publication.

That means credit unions should not treat the September vote as the end state. A useful readiness packet should include the current message inventory, consent sources, category rules, vendor dependencies, fraud-alert exception logic, reconciliation evidence and a change owner for the next rulemaking stage. Final legal text and effective dates should control production changes.

The policy outcome is favorable for timely account-security communication. The operating test is whether a credit union can honor a member’s choice precisely without accidentally silencing a different message that protects the member from harm.

Follow the operating implications. Explore published CreditUnionAI Weekly web briefings for source-backed regulation, risk and member-service coverage.

Browse web briefings