← All articles

Compliance Risks Hiding in Call Recordings: 20-Call Audit

17 August 2026 · 6.7 min read · Written and published by Whizz Scribe

Compliance Risks Hiding in Your Call Recordings: The 20-Call Audit SMB Teams Can Run This Week

The ugly surprise usually shows up by call 7. A sales manager opens a recording for coaching, finds a card number in the audio, the full digits again in the speech-to-text transcript, and an AI call summary pasted into the CRM. The team cannot show the recording notice, does not know the retention policy, and cannot say who downloaded the file last month.

While federal law generally permits one-party consent (18 U.S.C. § 2511(2)(d)), compliance risks hiding in your call recordings rarely stop at the beep. The issue is a workflow problem that includes the audit trail, audio, transcript, summary, access, and deletion. State-by-state consent rules still matter. So does everything that happens after the call.

The Moment This Becomes Your Problem

For most small teams, compliance gets real when a customer asks for deletion. Or when a manager exports a transcript for coaching. Or when finance learns the team has been taking payment details over the phone for months.

A platform may record by default. A transfer may keep recording after the agent thought the sensitive part was over. Five9’s terms state that if a customer subscribes to call recording, calls are recorded at all times, including on hold or during transfers, and the customer is responsible for consents (Five9). NICE CXone assigns a default 100% recording policy when a new tenant is created (NICE CXone).

That’s a familiar SMB tension: the product is already running, but the rules around it never got hired.

Penalties for voice data and access failures are large. The FTC and DOJ alleged Amazon kept children’s Alexa recordings and transcripts indefinitely and ignored deletion requests, proposing a $25 million civil penalty (FTC). The FTC also settled with Ring for $5.8 million over improper employee access to customer videos, showing how small failures involving stored media can become expensive (FTC).

The 8 Failure Points After “Record” Is On

There are eight common points of failure in the call capture and archiving workflow.

1. Recording notice/disclosure Was the caller told, and can you prove it? Some platforms support IVR announcements and consent gating. Genesys Cloud CX supports optional IVR recording announcements and a consent branch so recording starts only if the customer agrees (Genesys). NICE CXone documents that if a customer declines consent in IVR, the system will not record even if a policy says to (NICE CXone).

2. Start-stop behavior Did recording begin too early, run too long, or fail to pause? Genesys supports pause/resume for recordings, including synchronized pause/resume when screen recording is active (Genesys). If that control exists but nobody uses it, PCI and privacy exposure stay live.

3. Routing and capture gaps Transfers, holds, conferences, outbound callbacks, and forwarded lines create weird edges. On some stacks, the call keeps recording across hold and transfer (Five9). That’s exactly where card data, bank details, or private scheduling details get captured by accident.

4. Sensitive data spoken aloud Ordinary calls drift into high-risk domains fast. Full payment card information can trigger PCI DSS, and PCI SSC guidance says audio or voice recordings must not store sensitive authentication data after authorization (PCI SSC). In healthcare, PHI can exist in oral or recorded form in any medium (HHS). In financial services, customer account numbers can trigger GLBA and FTC Safeguards Rule obligations (FTC Safeguards Rule).

5. Transcript exposure AI transcription converts a hard-to-review audio file into searchable text, which helps with coaching but also makes PII in the transcript easy to search, export, paste, and over-retain. Genesys documents that transcription can be enabled, alongside options to retain, archive, delete, or export recordings (Genesys).

6. AI call summaries AI call summaries often leave the platform before the recording does. They get pushed into CRM notes, ticket histories, and chat threads. Even if the original audio was compliant, the summary may carry the same sensitive facts in a looser container with weaker controls.

7. User access Who can open, share, download, or forward the files? The Ring case shows that access control failures are as significant as the recording process itself (FTC).

8. Retention and deletion failures A retention policy must be implemented in the platform, not just documented in a PDF, to be effective. Five9 says VCC audio recordings are purged as soon as possible, or within 30 days or per contract, while GenAI Suite transcripts and summaries are configurable up to 60 days (Five9). NICE CXone provides both Media Deletion and Data Erasure policies that can delete audio, screen recordings, transcripts, and related business data (NICE CXone). Genesys also documents deletion, redaction, and pseudo-anonymization workflows for PII (Genesys GDPR).

A Practical 20-Call Audit

Pull 20 calls from the last 30 days, selecting a representative spread rather than 20 random calls from one queue. Build a small spread:

For each call, inspect six proof items.

Consent evidence Find the timestamped notice or consent trail. In Microsoft Teams, when explicit consent is enabled, each participant’s choice is visible to admins and included in the Purview audit log (Microsoft Teams).

Recording metadata preservation Capture who started the recording, when it started, whether it stopped and restarted, and where the artifact lives. Teams recordings and transcripts can be fetched after the call ends through Microsoft Graph, with recordings as .mp4 and transcripts as .vtt (Microsoft Graph).

Storage location Confirm ownership and file location. For Teams, 1:1 and group call recordings are stored in the OneDrive of the person who selected Record. Meetings go to the organizer’s OneDrive. Channel meetings go to SharePoint (Microsoft Teams storage).

Transcript and summary status Was AI transcription enabled? Does a transcript exist? Was an AI summary generated and copied elsewhere? Note every destination system.

Access history Check who viewed, downloaded, opened, or shared the file. Microsoft 365 audit logs record SharePoint and OneDrive access and sharing activity, including who shared a resource and who used the link (Microsoft Purview).

Retention and deletion evidence Which retention rule applies? What is the purge clock? Can the team produce a deletion record, or only promise one exists?

Score each call red, amber, or green. Red means a missing consent trail, exposed PCI/card data, PHI, bank details, broad sharing, or no deletion path. Amber means the control exists but was inconsistently used. Green means the evidence is complete.

Document the failure type, team, platform, and owner. A systematic, factual approach is the most effective way to fix these issues.

What Hidden Violations Look Like

Small teams typically fail in ordinary, everyday scenarios rather than dramatic ones.

A bookings desk records a customer rescheduling a procedure. The call contains healthcare details, so PHI is now sitting in audio and maybe in text too (HHS).

A support agent takes a card number because the payment link “wasn’t loading.” The recording and transcript may now contain card data that PCI rules treat as sensitive (PCI SSC).

A recruiting team records screening calls where the audio is compliant, but the transcript contains sensitive information like salary history, immigration status, or ID details that get copied into notes.

A collections team verifies account numbers on recorded calls. That can pull customer financial information into a system that now needs stronger safeguarding (FTC Safeguards Rule).

A front-desk team might use telecom TPV or booking confirmations and assume the vendor handles compliance, but the vendor is only responsible for features; the team owns the process.

The Transcript Layer: Compliant Recording, Non-Compliant Outputs

Most teams miss this layer, where a properly disclosed recording can still produce non-compliant outputs. This happens because text travels faster than audio. Speech-to-text transcripts become searchable. AI call summaries become easy to paste. Sentiment tags and coaching notes turn private conversations into structured data that spreads across systems.

The risk profile changes, making retention harder because the data lives in more than one place. Searching a transcript is easier than an .mp4, which expands discoverability. The presence of PII in plain text makes redaction more urgent. If you use compliance redaction, check whether it runs on audio, transcript, summary, or all three.

The Amazon case serves as a warning. The FTC and DOJ alleged both voice recordings and text transcripts were kept indefinitely, and that deletion requests were not fully honored across databases (FTC). That’s the same operational pattern SMBs create when summaries are copied to the CRM but deletion only hits the original recording.

If your stack includes voice biometrics or biometric data, it requires a separate review line distinct from generic call recording compliance.

Fix This Monday Morning

Start with ownership—one ops lead, one security partner, one weekly review.

Then change the defaults. Turn on or verify recording notice/disclosure. Review pause/resume rules for payment moments. Test hold and transfer behavior in live calls. If your platform starts from record-everything, decide whether that is your policy or just a leftover default.

Lock access down with role-based permissions. Supervisors who coach calls may not need download rights. Front-desk staff may not need transcript search. Shared links should expire.

Set one written retention policy for audio, one for transcripts, and one for AI call summaries. These policies do not have to be identical, but they must be implemented in the product itself rather than only existing in a document. Where available, enable deletion and erasure workflows already built into the platform (NICE CXone; Genesys).

Preserve proof, including recording metadata, consent events, access logs, and deletion records.

Then, run a lightweight weekly dashboard to track key metrics, which will serve as your control surface:

This dashboard is the control surface.

Pull 20 calls this week. If the team can prove consent, metadata preservation, controlled access, and deletion on those 20, the rest of the workflow gets easier fast. If it can’t, the risk is already live.

Sources

  1. FTC/DOJ charge Amazon violating children’s privacy law by keeping kids’ Alexa voice recordings forever
  2. FTC says Ring employees illegally surveilled customers; failed to stop hackers taking control
  3. Five9 Agreement Terms
  4. NICE CXone Policies
  5. PCI DSS (PCI Security Standards Council)
  6. HHS: De-identification (PHI in oral or recorded form)
  7. FTC Safeguards Rule
  8. Genesys Cloud CX use case: IVR recording announcements and consent
  9. Genesys Cloud CX use case: pause/resume recording
  10. Five9 Data Retention
  11. NICE CXone Policies (Media Deletion & Data Erasure)
  12. Genesys GDPR documentation
  13. Microsoft Teams: call recording/transcription captions and consent
  14. Microsoft Graph: meeting transcripts overview
  15. Microsoft Teams recording storage (OneDrive/SharePoint)
  16. Microsoft Purview audit log activities