Compliance Resources

Compliance Frameworks

Resources for regulated industries.

Compliance shapes what "good" looks like long before a model is chosen. Use these framework briefs to align your contact center modernization with the rules that actually apply to you.

FedRAMP

Federal Risk and Authorization Management Program

Standardized approach to security assessment, authorization, and continuous monitoring for cloud services used by U.S. federal agencies.

Applies to
Federal agencies and their cloud service providers
Key requirements
  • Authorized cloud service provider (Moderate or High baseline)
  • NIST SP 800-53 control implementation and continuous monitoring
  • US-based data residency and cleared personnel where required
  • Documented SSP, POA&M, and annual assessments by a 3PAO

HIPAA

Health Insurance Portability and Accountability Act

Protects the confidentiality, integrity, and availability of protected health information (PHI) across every channel a contact center touches.

Applies to
Healthcare providers, payers, and business associates
Key requirements
  • Signed BAAs with every vendor that touches PHI
  • Encryption in transit and at rest; audited access controls
  • Minimum-necessary data handling in transcripts and AI prompts
  • Breach notification workflows and 6-year audit log retention

FERPA

Family Educational Rights and Privacy Act

Protects the privacy of student education records and governs how AI tools may process student information in support and registrar workflows.

Applies to
K–12 districts, colleges, and universities receiving federal funding
Key requirements
  • School-official designation and direct-control clauses with vendors
  • Consent workflows for record disclosure beyond directory info
  • COPPA alignment for K–12 users under 13
  • Data minimization and no-training clauses in AI contracts

NERC CIP

North American Electric Reliability Corporation — Critical Infrastructure Protection

Reliability standards protecting the North American power grid, extending to any contact center workflow that can influence operational technology.

Applies to
Bulk electric system operators and their supporting contact centers
Key requirements
  • BES cyber system categorization and access boundaries
  • Electronic and physical security perimeters, incl. supply chain (CIP-013)
  • Personnel risk assessments and role-based training
  • Incident response with 1-hour E-ISAC reporting for reportable events

PCI-DSS

Payment Card Industry Data Security Standard

Baseline controls for cardholder data — critical whenever agents, IVRs, or AI assistants can hear, see, or route a card number.

Applies to
Any organization that stores, processes, or transmits cardholder data
Key requirements
  • DTMF suppression / pause-and-resume recording for card capture
  • Tokenization and scope reduction to keep AI out of the CDE
  • Quarterly ASV scans and annual SAQ or ROC attestation
  • Strict key management and role-based access to cardholder data

GLBA

Gramm-Leach-Bliley Act

Requires financial institutions to safeguard nonpublic personal information (NPI) and explain their information-sharing practices to customers.

Applies to
Banks, credit unions, insurers, and other financial institutions
Key requirements
  • Written Information Security Program with a qualified individual accountable
  • Vendor due diligence and continuous monitoring under the Safeguards Rule
  • Multi-factor authentication and encryption of NPI in transit and at rest
  • 30-day notification to the FTC for qualifying security events

Turn compliance from a blocker into a design input.

We'll map your regulatory profile to a vendor-neutral architecture and a rollout plan your auditors can defend.