Most of that list is not specific to RCS. It is the same TCPA, CTIA and carrier regime that governs any US business texting, and if you already run a compliant SMS programme you have most of it. What changes on RCS is worth separating out, because it is the part teams miss.
What RCS adds on top of SMS compliance
- A second approval, on a different clock. Google and the carriers vet your RCS agent separately from 10DLC brand and campaign registration. Both are required, and RCS verification is usually the longer of the two. Run them in parallel. See 10DLC vs RCS.
- Approval is per use case, and it attaches to the agent. An agent approved for transactional messaging cannot legitimately carry marketing. The consequence is heavier than on SMS: sending outside the approved use case risks suspension of the agent itself, which removes branded treatment from every message that sender carries, not just the offending one.
- Google's RBM policies apply in addition to the carriers'. They are a separate rulebook covering content, agent behaviour, and how the brand is represented.
- Your fallback is still an SMS programme. Anything that cannot be delivered as RCS goes out over your registered 10DLC number under the ordinary SMS rules, so RCS-first does not let you skip any of the SMS obligations.
- Consent is per channel, not per customer. Someone who opted in to SMS has not thereby opted in to a different channel, and your records need to show which they agreed to.
The checklist
- Register your brand (KYC) and get each campaign or use case approved through The Campaign Registry and the carriers.
- Verify your RCS agent so every message carries your name, logo, and checkmark rather than a bare number.
- Publish a clear call to action with brand name, message description, frequency, "msg & data rates may apply," and opt-out instructions.
- Capture explicit opt-in, prior express written consent for marketing and prior express consent for transactional, recording the source, method, and timestamp.
- Send a confirmation message, and include opt-out instructions on recurring programmes.
- Honour opt-outs: treat STOP, QUIT, END, CANCEL, UNSUBSCRIBE, OPT OUT and REVOKE as valid, stop within 10 business days, and send at most one clarification message.
- Link a privacy policy and terms from the opt-in, and use the data only for the disclosed purpose.
- Avoid prohibited SHAFT content (sex, hate, alcohol, firearms, tobacco) and the other restricted categories.
- Keep consent and opt-out audit logs for at least five years (FTC Telemarketing Sales Rule).
- Follow the CTIA Messaging Principles, all four carriers' rules, and Google's RBM policies.
TCPA compliance checklist
The consent layer, which applies to the SMS fallback and to the RCS messages alike:
- Prior express written consent before any marketing message, captured with a disclosure that states the sender, message frequency, that message and data rates may apply, and how to opt out.
- The consent record kept per phone number: timestamp, source, and the exact wording shown.
- Transactional and informational messages sent only to people who gave a number for that purpose, and never used to carry marketing.
- STOP honoured immediately and automatically, HELP answered, and the opt-out persisted across every channel and system that can send.
- Quiet hours respected in the recipient's time zone; no messages to numbers on the National Do Not Call Registry without consent.
- A named owner for complaints, and a record of how each was resolved.
Statutory damages under the TCPA run $500 to $1,500 per message, enforced through private lawsuits, which is why the record-keeping matters as much as the behaviour. What is 10DLC compliance covers the carrier layer that sits beside this one.
Records and the audit trail: what a compliant programme has to produce
Consumer protection in US business messaging is enforced on evidence, not intent. A carrier audit, a Google policy review, a regulator or a plaintiff's lawyer each begins the same way, by asking for records, and the programme that can produce them in minutes is the one that is compliant in practice. Five records cover it:
| Record | What it has to show | Why it exists |
|---|---|---|
| Consent record, per phone number | Timestamp, the mechanism (web form, keyword, paper, verbal), the exact disclosure wording shown, and which channel and message type the person agreed to | Prior express written consent for marketing under the TCPA rules, 47 CFR 64.1200; the sender carries the burden of proof |
| Opt-out log | The keyword or other reasonable means used, the timestamp, when suppression took effect, and the single confirmation sent | The FCC's 2024 revocation order, FCC 24-24: any reasonable means counts, honoured within 10 business days |
| Send log, per message | Sender agent, approved use case, template or content, recipient, whether it delivered as RCS or fell back to SMS or MMS, and the delivery status | Proves each message sat inside the consent and the approved use case, on whichever channel it actually travelled |
| Registration artefacts | Brand ID, campaign IDs and their approved use cases, the RCS agent's verification approval, and the dates of each | Ties every send to a registered brand, an approved campaign and a verified sender, which is what carriers and Google check first |
| Complaint log | Who raised it, when, what was found, how it was resolved, and the named owner | The FTC Telemarketing Sales Rule's record-keeping expectations and the first thing a carrier asks for when a number is flagged |
Keep consent and opt-out records for at least five years, and keep the send log for as long as the consent it relies on, because a message is only defensible next to the consent that authorised it. Retention is a decision to write down, not a default to inherit from the platform.
The rules behind the list are the ordinary US texting regime and apply to RCS and its SMS fallback alike: the TCPA itself, 47 U.S.C. 227, and the FCC's implementing rules on consent, revocation, quiet hours and the Do Not Call Registry; the FTC's Telemarketing Sales Rule on records; the CTIA Messaging Principles and Best Practices, enforced by the carriers rather than a court; each carrier's 10DLC rules, applied through The Campaign Registry; Google's RBM policies on agent content and behaviour; and a growing set of state statutes with their own consent and calling-hour rules. Is RCS regulated walks through how the layers fit together.
What to ask a provider about its audit trail
A compliant provider is one that keeps these records for you and hands them over on demand, so the questions are concrete. Can you export the consent log per phone number, with the disclosure wording as shown? Does every message in the send log say which channel it delivered on and against which campaign and agent? Are STOP and HELP handled above any bot or AI layer, so an opt-out is honoured even when an automation is mid-conversation? Where do the registration artefacts live, and can you see the approval history? And how long is each record kept, and who decides? On SimplyRCS, STOP and HELP are handled above the AI layer, consent records are retained with a full audit trail, and registrations and approvals sit in one queue with their history, which the trust page sets out; ask any provider for the same in writing.
Where programmes actually fail
Rarely on the checklist itself. The two recurring failures are a brand name that does not match public records, which stalls registration and depresses the trust score that governs throughput, and consent records that cannot show which channel someone agreed to. Both are cheap to get right at the start and expensive to reconstruct later.
- Most of RCS compliance is the ordinary US texting regime; the RCS-specific parts are agent verification, per-use-case approval, and Google's RBM policies.
- The two approvals are separate submissions on separate clocks and should run in parallel.
- Sending outside an agent's approved use case risks the agent, not just the message.
- SMS fallback rides your registered 10DLC number, so RCS-first does not remove any SMS obligation.
- A compliant programme can produce five records on demand: consent per number, the opt-out log, the per-message send log with its delivery channel, the registration artefacts, and the complaint log.
- SimplyRCS handles brand registration, 10DLC, and RCS carrier approval, and enforces per-channel consent in the platform.