Compliance & Security

Regulated work, done to the letter

Debt recovery is among the most closely regulated activities in financial services. We treat every requirement as a design constraint for how we build our procedures, train our people, and protect data — not as an afterthought.

Regulatory Framework

The laws that govern our work

Each statute below shapes a specific part of our operation. Our written policies map every procedure to the requirement it satisfies.

FDCPA

Fair Debt Collection Practices Act. The foundational federal law for third-party collectors. Prohibits harassment, false or misleading representations, and unfair practices; requires validation of debts and honors cease requests. Governs our scripts, letters, and conduct standards.

Regulation F

12 CFR Part 1006 (CFPB). Implements the FDCPA with detailed rules: model validation-notice content, the 7-in-7 call-frequency presumption, electronic communication opt-outs, limits on social-media contact, and time-barred-debt disclosures. Defines our outreach cadence and notice templates.

FCRA

Fair Credit Reporting Act. Governs how we obtain consumer reports (permissible purpose), how we furnish account data to bureaus (accuracy and integrity), and how we investigate direct and indirect disputes. Drives our furnisher procedures and skip-tracing controls.

TCPA

Telephone Consumer Protection Act. Regulates autodialed and prerecorded calls and text messages to mobile phones, requiring consent and honoring revocation. Governs our dialing technology, consent records, and opt-out handling.

GLBA

Gramm-Leach-Bliley Act. Requires financial institutions and their service providers to safeguard nonpublic personal information under the Safeguards Rule. Underpins our written information security program, vendor oversight, and privacy notices.

HIPAA

Health Insurance Portability and Accountability Act. Where we service medical accounts, we act as a business associate under a written agreement, apply the minimum-necessary standard to protected health information, and follow HIPAA security and breach-notification rules.

State laws

Most states regulate collection agencies through licensing, bonding, disclosure, and conduct statutes, and several — including those with their own consumer-collection acts and medical-debt laws — impose requirements beyond federal law. Our compliance team maintains a state-by-state matrix that governs which accounts may be worked, what notices are required, and which channels may be used in each jurisdiction. Related laws we observe include the Servicemembers Civil Relief Act, the Bankruptcy Code's automatic stay, the Electronic Fund Transfer Act for recurring payments, and the Driver's Privacy Protection Act for location data.

Licensing & Bonding

Licensed and bonded where required

Collection agency licensing is handled state by state, and requirements change frequently. We maintain the licenses, registrations, and surety bonds required in each jurisdiction where we collect, and we do not work accounts in states where our licensing is not current.

Clients may request copies of licenses and bond certificates for their vendor files at any time. Consumers may verify our licensing with their state regulator.

Request licensing documentation

State license table [PLACEHOLDER: state license table]

StateLicense / RegistrationNumberRegulator
[State][Collection Agency License][#][Agency]
[State][Registration][#][Agency]
[State][NMLS][#][Agency]

Surety bond: [PLACEHOLDER: bond amount / surety]. Delete rows or this table if not applicable.

Data Security

Protecting client and consumer data

We handle sensitive financial and, for some clients, health information. Our written information security program is built around the GLBA Safeguards Rule and, where applicable, the HIPAA Security Rule.

Encryption in transit and at rest

Placement files move over encrypted channels (SFTP, HTTPS/TLS). Stored data is encrypted at rest. Email is never used to transmit full account files or sensitive identifiers.

Access controls

Role-based access limits each employee to the data needed for their function. Multi-factor authentication is required for system access. Access is reviewed periodically and revoked immediately on separation.

Retention and disposal

Account data is retained only as long as required by client agreement, law, and regulatory record-keeping rules, then securely destroyed. Retention schedules are documented and applied consistently.

Monitoring and incident response

Systems are monitored for unauthorized access. A written incident-response plan defines investigation, containment, and notification steps, including client and regulatory notification timelines.

Vendor oversight

Third-party vendors with access to data — letter vendors, data providers, telephony, payment processors — are assessed before engagement and bound by contractual security obligations.

Independent assessment

[PLACEHOLDER: SOC 2 / PCI status] — describe any completed SOC 2 examination, PCI DSS attestation, penetration testing cadence, or planned assessments. Do not claim a certification that has not been obtained.

Training & Quality Assurance

Every representative is trained before they touch an account

  • Onboarding curriculum.New representatives complete training on the FDCPA, Regulation F, FCRA, TCPA, state law, data security, and our own conduct standards, and must pass an assessment before handling live accounts.
  • Annual recertification.All staff repeat compliance training at least annually and receive updates whenever the law or our procedures change.
  • Call monitoring and scoring.Calls are recorded [PLACEHOLDER: confirm recording practice and retention] and a sample is reviewed against a compliance scorecard covering disclosures, tone, accuracy, and dispute handling.
  • Letter and template review.Every consumer-facing template is reviewed for compliance before use and re-reviewed when regulations change.
  • Corrective action.Findings from QA reviews lead to coaching, retraining, or removal from accounts, and are tracked to closure.
  • Compliance management system.Policies, training records, monitoring results, and complaint data are maintained in a structured CMS available for client and regulatory review.

Complaint Handling

Every complaint is logged, investigated, and answered

We treat complaints as a source of information about how our processes are working. Whether a concern arrives directly from a consumer, through a client, or via a regulator such as the CFPB or a state attorney general, it follows the same path.

  1. Intake. The complaint is logged the day it is received, with the account placed on hold pending review where appropriate.
  2. Investigation. A compliance team member — not the representative involved — reviews account notes, recordings, and correspondence.
  3. Response. We respond to the consumer in writing, typically within [PLACEHOLDER: response timeframe, e.g., 15 business days], and to regulators within their required timelines.
  4. Root cause and remediation. Findings are classified by cause, corrective action is assigned, and trends are reviewed to identify procedural changes.
  5. Client reporting. Complaints on a client's accounts are summarized in their reporting package, with details available on request.

Consumers: how to raise a concern

Email support@ivyrecoverygroup.com with "Complaint" in the subject line and your reference number. You may also contact the CFPB at consumerfinance.gov/complaint or your state attorney general at any time.

Clients: requesting our compliance package

We provide a compliance package for vendor-management files that includes policy summaries, training outlines, licensing documentation, insurance certificates [PLACEHOLDER: coverage types], and security program overview. Email support@ivyrecoverygroup.com.

Due Diligence

Put us through your vendor review

We welcome questionnaires, audits, and hard questions. Email us to request documentation.

Contact us