Skip to main content

Run a quarterly compliance posture review

Your posture was set deliberately once — at launch, market by market, through the first-run configuration guide. This runbook is the recurring half of that discipline: a four-check quarterly review that re-verifies the per-control surfaces after a quarter of traffic, and closes with evidence. It assumes the controls are set; it asks whether they are still set correctly.
Every control re-verified here is tenant-owned. Orbit provides the surfaces and defaults them open; you configure them and you own the posture. This page is an operational runbook, not legal advice — confirm which obligations apply to your traffic with counsel.

Why posture decays between audits

Compliance configuration behaves like a garden, not a vault. The toggles you set at launch are point-in-time decisions, and four forces move them without touching a toggle:
  • Traffic drift. You launched with one SMS campaign; by Q3 you run WhatsApp, a dialer, and a reactivation flow a teammate added. A 12,000-recipient import quietly lowers consent coverage from 98% to 81% — and the first place that registers is not a carrier throttle, it is your compliance-health score.
  • Jurisdiction drift. A US SMS program expands to Brazil (LGPD, a 15-day DSAR clock) and the UK. Each market re-asks the consent, disclosure, and announcement questions you last answered at launch.
  • Consent staleness. Captured consent ages — the valid_until on a receipt expires, the consent_text_version on an old CSV import no longer matches the policy page a new contact actually saw, and a proof URL nobody archived is a proof you cannot produce.
  • DSAR pipeline decay. An intake portal nobody filed through, an OTP sender no one configured, an export link that expired before anyone downloaded it. The time to find a broken fulfilment path is a drill, not a live request with a statutory clock running.
Quarterly works because it matches how the reference data ages: consent windows expire on 90-day and annual boundaries, carrier score windows top out at 90 days, and a statutory DSAR clock is short enough that discovering a broken pipeline during a live request is a breach you chose.

The quarterly cadence — four checks

An hour-ish per quarter for a single-market tenant; wider portfolios budget proportionally. Run the checks in order — each one narrows the next.

Check 1 — Read the health score (15 minutes)

Open the compliance-health score per organization, sender, and campaign, with the window set to the quarter. The score blends four signals — consent coverage, opt-out velocity, STOP-reply rate, and carrier rejections — and none of them gates a send; a low score is advisory until you act on it. That is the point of the review: it is the early-warning read before a carrier throttle or a rejection spike becomes the message. Flag for Check 2:
  • consent_coverage sliding from ok toward warn while volume grows — a list import or capture path that never wrote consent records.
  • Opt-out velocity climbing on a specific sender or campaign — wording, frequency, or audience drift worth fixing before the carrier notices.
The correct-at-launch pairing decays in specific, checkable places. Work down the list against the markets and channels you actually ran this quarter:
  • Consent records and receipts — confirm capture points still write consent on every collection path, and that the channel mix you now run is covered by the records you hold. For HIPAA-adjacent audiences, confirm the BAA is signed and current. Reference: Consent Management & Receipts.
  • Recording announcement coverage — list the jurisdictions you placed or received calls in this quarter (call logs group by destination), then compare the announcement pairing saved in Voice → Calls → Recording settingssettings.recording.{eligibility_mode, consent_announcement_mode} — against the strictest of them. Dialing into an all-party-consent jurisdiction with announce_caller set, or auto-recording with consent_announcement_mode: none (an in-app warning Orbit surfaces — this check is where a dismissed warning gets caught), is exactly the drift this audit exists to find. Reference: Call Recording Consent.
  • Time-window gates — re-read your quiet hours per channel against current sending patterns, and the US state calling windows against the states you actually dialed. A seasonal override set for one campaign and never lifted is a six-month posture change nobody decided on.
  • STIR/SHAKEN attestation — review the per-number attestation posture of your outbound voice in Attestation posture, not only at onboarding. Numbers provisioned mid-quarter inherit posture separately.
  • Suppression enforcement — confirm opt-out suppression is still enforced, end to end, by running a pre-send check on a sample known-suppressed contact and watching it hold. Reference: Opt-Out & Suppression Lists.

Check 3 — Exercise the DSAR pipeline (15 minutes)

The failure this check catches is not a late request — it is a pipeline you never exercised, discovered live. Once a quarter, against the DSAR surface:
  1. File one request against your own contact record — the fire drill. Verify it enters the operator queue alongside real traffic and that the portal path (or operator intake) marks verification the way you expect.
  2. Read the SLA snapshot. Per-request days_remaining and severity tier are scaled to each jurisdiction’s deadline — GDPR 30 days, CCPA/CPRA 45, LGPD 15. Anything breached, or an approaching count that keeps growing, is a staffing problem surfacing a quarter early.
  3. Download one export. Signed export links expire — open one, confirm the file contains what you would actually hand a data subject, and confirm your team knows where the row counts per table are described.
  4. Re-set the jurisdiction mix at intake. If you launched GDPR-only and now market into California or Brazil, requests arriving under the wrong applicable_jurisdiction grade against the wrong clock. Intake accuracy is part of the review.

Check 4 — Close with evidence (10 minutes)

End the quarter provable, not just done:
  1. Archive the quarter’s consent and suppression exports — both of them, at status=all so revoked rows are preserved and the file proves re-permissioning, not just the active blocklist.
  2. Generate a binderSettings → Compliance → Binder, pick the framework your auditor or buyer asks for (SOC 2 for procurement, GDPR for the privacy file), and the format. The walkthrough is in Assemble and seal an evidence binder; the framework tables in the binder reference. A quarterly generation builds the habit and a comparable archive: two generations over the same data are byte-identical and carry a SHA-256 checksum, so quarter-over-quarter diffs are mechanical and a tamper-flagged generation surfaces while there is still time to investigate.
The binder only assembles what your workspace already produced; if Checks 1–3 found drift, remediate first and regenerate — the row an auditor reads should quote the workspace that moved forward.

Override file + sign-off

Overrides are legitimate posture — a seasonal window lift, a manual-only recording designation, a dialer exemption — as long as someone can name its expiry. Keep them out of memory and in one file; the review then costs minutes.
Quarterly sign-off checklist — attach it to the binder generation record in your audit log:
  • Health score reviewed per org, sender, and campaign; findings logged
  • Overrides above re-confirmed or reverted
  • Consent coverage confirmed for every capture path and channel in use
  • Recording eligibility_mode × consent_announcement_mode pairing confirmed against the quarter’s actual call destinations
  • Quiet hours and state calling windows confirmed against actual traffic
  • Attestation posture reviewed on numbers provisioned this quarter
  • Suppression enforcement verified on a known-suppressed sample contact
  • DSAR fire drill filed, SLA snapshot clean, one export downloaded
  • Consent and suppression exports archived for the quarter
  • Binder generated and checksum recorded
Sign-off: _________ (name) _________ (role) _________ (date) Keep the chain — checklist, override file, binder checksum — in your own records. Orbit’s audit log records generation and remediation; the sign-off artifact is yours.