← All articles
Product UpdatesSep 28, 2026 13 min read

The Audit Question You Want to Answer in Minutes, Not Weeks

When a regulator or client asks why each person was or was not connected, per-call detection logs turn weeks of scrambling into minutes. Plain-English guide for owners.

The Audit Question You Want to Answer in Minutes, Not Weeks

Can you show, call by call, why each person was or was not connected to an agent?

Read that again and answer honestly. If a regulator, a carrier, or your biggest client asked you that this morning, how long would it take to produce the answer? For most outbound shops, the honest answer is weeks. For some, it is "we cannot, fully." This piece is about closing that gap before someone else opens it for you.

I am not a lawyer and this is not legal advice. I am an operator who has been in the room when the question was asked, and I know which way the room leans depending on how fast the answer comes.

The nightmare scenario

It unfolds the same way every time.

A complaint lands, or a client's compliance team gets nervous, or a state regulator opens a routine inquiry. The email is polite and short. It asks for records: which calls were answered by a person, which were classified as machines, which were dropped before an agent joined, over what period. Then a deadline.

What happens next at a typical shop is archaeology. The detection decisions live inside the dialer, buried in logs that were configured years ago by someone who may no longer work there. Recordings exist, but scattered across storage servers with no index that ties a recording to a classification decision. Somebody starts pulling CSVs at midnight. Managers forward spreadsheets to each other with filenames like "final_v3_REAL.xlsx." Two weeks in, you still cannot say, for a specific call at a specific timestamp, why the caller never reached a person.

Here is the part that stings. The information existed. Your dialer made a decision on every single call. It simply was not captured in a form anyone could defend. An auditor does not accept "that is how the dialer works." Neither does a client's lawyer. The gap between what you know and what you can prove is where penalties and lost contracts live.

And the exposure is not theoretical. Under the FTC's Telemarketing Sales Rule, abandoned live answers are capped at 3 percent per campaign over a 30-day window (16 CFR 310.4(b)(4)). The rule is public; you can read the exact text in the Code of Federal Regulations. A dialer that mistakes live humans for voicemail and hangs up on them produces outcomes that sit uncomfortably close to that line. If you cannot measure your misclassification rate, you cannot manage your abandonment exposure either. They are the same recordings.

What a defensible answer looks like

Defensible is a specific thing, not a vibe.

A defensible answer to "why was this caller not connected" has three properties. It is per call, not statistical. "Our accuracy is 95 percent" is marketing; "here is the record for that call" is evidence. It is contemporaneous, meaning it was recorded at the time by the system that made the decision, not reconstructed afterward from a manager's memory. And it is complete: every call has a record, not just the ones that went well.

When you can produce that, the conversation changes character. I have watched it happen. The auditor's posture softens not because you charmed them but because their job got easier. They came to reconstruct events; you handed them the reconstruction. Requests shrink from "explain your entire operation" to "walk me through these four calls." Deadlines stop slipping. The meeting ends on time.

When you cannot produce it, the opposite happens. Every gap invites a broader request. Every "we think so" earns a follow-up. The audit is not just slower; it gets bigger, because uncertainty is the one thing an auditor cannot close out.

What a per-call detection log actually contains

Let me make this concrete. Every AMDY classification is logged, per call, and exportable. For each call, the record answers the questions an auditor will ask.

The timestamp

When the call was answered and when the classification happened. Not "that afternoon." To the second. This is what lets you align your detection log against a complainant's phone bill, which is often the exact alignment an investigation needs.

The decision

What the classifier concluded: person, machine, or inconclusive. In plain words, recorded by the system that made the call. Nobody typed it in later. That distinction, system-recorded versus reconstructed, is worth a great deal when credibility is the currency.

The outcome

What actually happened next: connected to an agent, sent to voicemail flow, or dropped. Timestamp and decision tell half the story; outcome completes it. The pairing is what separates "we classified correctly" from "we handled the call correctly," and auditors care about both.

Put together, a single row answers the audit question for one call. A month of rows answers it for a campaign. The difference between a shop with these logs and a shop without them is the difference between running a query and running an archaeology project.

Who actually asks this question

The phrase "audit" conjures regulators, and they do ask. But in my experience the question arrives from four directions, and the records answer all four the same way.

Regulators and state attorneys general

Complaint-driven inquiries usually reference specific numbers and dates. They want the call-by-call story for those numbers. A per-call log with timestamps turns "we believe the call was properly handled" into "here is the call."

Enterprise clients

If you dial for insurance, debt, solar, or home services brands, your contract probably already contains an audit clause. Brand owners are terrified of being named alongside their vendors, and their compliance teams increasingly ask for detection records, not just call recordings. Being able to hand over a clean export has won renewals. Fumbling for three weeks has lost them.

Carriers

Carriers enforce their own acceptable-use thresholds, and when traffic looks wrong they ask questions before they route elsewhere. Fast, factual answers keep routes alive. Silence or vagueness gets you moved to the expensive tier or off the platform entirely.

Your own board and finance team

Internally, the same records answer a different question: is the money we spend on dialing producing conversations? An audit trail and an operations instrument are the same dataset read two ways. The shop that can answer the regulator in minutes can also answer the CFO in minutes.

The morning the email arrives

Let me make the minutes-vs-weeks difference concrete. Picture the polite email landing at 9:40 on a Tuesday, asking for call records covering a six-week window for three campaigns.

At a shop with per-call detection logs, the sequence looks like this. By 9:55, someone has filtered the export to the named campaigns and window. By 10:30, the summary exists: total calls, live-answer classifications, machine classifications, outcome counts, abandonment rate compared against the FTC's 3 percent cap. Before lunch, counsel has reviewed it. The reply goes out the same day with attachments, and the shop goes back to selling. Total management time burned: a couple of hours.

At a shop without logs, the same email starts a two-week scramble through dialer internals, storage servers, and three people's recollections. The reply goes out late, incomplete, and hedged. Every gap invites a follow-up request, and each follow-up restarts the archaeology. Nobody sells anything for a fortnight. Both shops may well be innocent. Only one of them can prove it before the story writes itself.

That asymmetry is the entire argument. It is not about guilt. It is about whether evidence is a query or a project.

Retention and export, in plain terms

Logs only defend you if they still exist when the question arrives, and if you can get them out.

Complaints and inquiries often arrive months after the calls in question. A log you purge after two weeks is a log that was never there, as far as the audit is concerned. So retention policy is a business decision the owner should make consciously, with counsel, not a default the dialer admin stumbles into. Write down how long you keep detection records. Write down why. Review it yearly. That one-page policy has saved more owners than any dashboard.

Export matters just as much. "The data is in there somewhere" does not survive contact with a deadline. Every AMDY classification is exportable, so when the polite email arrives, your answer is a file, not a project. Whoever receives it, regulator, client, or your own lawyer, gets the same complete record you see. If you want the longer treatment of how these logs hold up under scrutiny, I wrote about detection logs as a compliance defense, including the failure modes I have personally watched sink otherwise defensible shops.

One related trap: logs prove what happened, not that your detector was right. Auditors and clients increasingly ask the second question too. Two honest safeguards help. Our honeypot detection reporting surfaces known test numbers and traps in your traffic, so you can demonstrate measured behavior rather than promised behavior. And because no classifier is static forever, monitoring for AMD model drift is how you avoid confidently presenting stale numbers as current truth. A record that shows you were watching is worth more than a claim that nothing changed.

The auditor's question, and the record that answers it

This is the table I would put in front of my own board. Left column is what gets asked. Right column is what answers it.

The question an auditor asks The record that answers it
"Why did this caller not reach an agent?" Per-call log: timestamp, classification decision, and outcome for that exact call.
"How do you know it was an answering machine?" System-recorded decision made at call time by the classifier, not reconstructed afterward.
"What is your abandoned-call rate for this campaign over 30 days?" Export of outcome fields across the window, compared against the FTC TSR 3% cap (16 CFR 310.4(b)(4)).
"Show me every call to this number." Queryable log filtered by number, covering the full retention period.
"How do you know your detector still performs?" Ongoing honeypot reporting and drift monitoring, in the same export as the call records.
"Who reviewed this and when?" Retention and review policy, applied consistently, supported by the logs themselves.

Notice that none of these answers is an opinion. They are all records. That is the entire strategy: convert questions that require judgment under deadline into questions that require a query.

Building the answer into the floor

Records do not maintain themselves. Three habits keep the audit answer at minutes, permanently.

One: name an owner

Someone owns the log. Not a committee, a person. Their weekly routine includes a glance at the dashboard and a monthly export filed somewhere sensible. When the polite email arrives, nobody debates whose job it was. Small shops can give this to the dialer admin; bigger shops give it to compliance. The title matters less than the existence.

Two: rehearse once a quarter

Run your own mini-audit. Pick a random week from two months ago, pull the records, and answer the audit question for that week as if a stranger asked. Time yourself. If the drill takes an afternoon, fix the friction now, while it is cheap. Teams that rehearse are calm during the real thing because the real thing is the same drill with higher stakes. Teams that do not rehearse discover their gaps while someone else watches.

Three: align recording retention with log retention

A detection log without the matching recording is only half an answer, and a recording you cannot tie to a classification decision is the other half. Whatever retention period counsel sets, apply it to both, and make sure the linkage between them stays intact. The log says what the system decided; the recording is what a skeptical reviewer checks the decision against. Together they close the loop.

None of this is heavy. It is the difference between an operation with a filing system and an operation with piles.

Why speed changes the outcome

There is a subtler reason minutes beat weeks, beyond saving management time. Audits are conversations, and early answers shape them.

The first substantive thing you hand an auditor sets the frame. Hand them a complete, timestamped, per-call record in day one, and the frame becomes "this shop runs tight; let us verify." Hand them a hedge, and the frame becomes "this shop does not know what it does; let us find out." Same facts underneath, different conversations on top, and the second kind always costs more.

Speed also compounds internally. The team that answers in an afternoon stays focused on selling. The team that spends two weeks in the audit cave makes mistakes elsewhere, and morale takes a hit precisely when you need steady hands. Owners who have lived through a slow audit know it is not a paperwork problem. It is a quarter-long tax on attention.

What this is worth in money

Compliance spending is insurance until the day it is a refund.

Work the downside first. A single botched audit response consumes weeks of management time, and that assumes it ends well. Client contracts with audit clauses, common in insurance, debt, and healthcare-adjacent outbound, can terminate on failure to produce records. I will not quote you fine numbers, because invented numbers are how this industry lies. The rules are public at the FTC; read the penalties yourself and decide what exposure feels acceptable. The point is not the size of any one fine. The point is that the cost of not having records is always larger than it looks, because it is paid in time, contracts, and standing, not just dollars.

Now the upside, which most owners undervalue. The same per-call logs that satisfy auditors are an operations instrument. They show you contact rates, error direction, and per-carrier behavior. The discipline that makes you auditable also makes you better at the thing you are audited for. If you want the framework for turning detection data into a cost-per-conversation number your CFO will respect, see our piece on cost per number as a life metric.

And the cost of getting there is small. The Sandbox plan is free: 50,000 detections per month, no card, hard cap. Every plan, free or paid, ships with the logging described above. Paid tiers are flat and simple, Starter at $79 a month through Scale at $999, details on the pricing page. There is no compliance surcharge for the audit trail. It is not an add-on; it is the product.

Start before you need it

Here is the pattern that repeats, and I say this as someone who has taken the call: shops adopt logging after the bad email arrives, then spend the first painful weeks wishing they had history from before the inquiry. The logs only defend calls made after they started running. You cannot backfill a record that was never written.

Install is one command your dialer admin runs, about five minutes, and during the trial it can run alongside your current setup without touching live routing. So the practical move is simple: start logging now, while nobody is asking, so that when somebody asks, the answer takes minutes.

Begin here: amdy.io/auth/signup.

The best day to start keeping records is the day nothing is wrong. The second best is the day something is. Pick the first one.