Compliance at Multi-State Scale
A 50-location HVAC and plumbing platform under Wrench Group, Authority Brands, Apex Service Partners, Sila Services, Path Light Pro, Redwood Services, Leap Partners, or ARS-Rescue Rooter operates across 25-50 states. Each state writes its own contractor-licensing law. Each state writes its own recording-consent statute. The federal frame (TCPA, Reg Z, FCRA, EPA 608) stacks on top. And every AI vendor in the platform stack โ Avoca, Rilla, CallRail, ServiceTitan, Hatch, Podium, Birdeye, Wisetack, GreenSky, Synchrony โ has to be configured to the right rule at the right tenant for the right location. The platform that runs 50 locations on 50 different compliance regimes burns out the General Counsel and the Director of AI Operations within 18 months and absorbs a class-action settlement by month 24. The platform that runs one compliance framework calibrated to 50 states survives. This lesson is the framework: the seven federal regimes that bind every location, the state-law matrix that lays on top, the platform-level configuration discipline that makes one operating system work across the footprint, and the audit cadence that keeps it tight. Board-defendable. Counsel-reviewed. The artifact the platform CEO walks into the next CFPB inquiry, EPA 608 audit, or state-AG complaint with.
Why One Framework for Fifty States
The 2024-2025 multi-state compliance graveyard is full of platforms that wrote 50 separate state policies, hired regional compliance leads to enforce each one, and discovered at month 18 that the framework was unmanageable. The 50-policy approach fails for three reasons. First, state laws drift continuously โ Massachusetts proposes wiretap reform, Illinois amends BIPA, Colorado activates the AI Act, California refines CCPA/CPRA โ and the platform's compliance team chases drift in 50 places instead of one. Second, vendor configurations diverge by tenant in ways the platform cannot audit at scale; a Florida CallRail tenant misconfigured for one-party consent looks identical to a properly configured Texas tenant in the vendor dashboard. Third, training and role discipline fragment โ the CSR onboarded in Phoenix learns a different recording disclosure than the CSR onboarded in Pittsburgh, and the platform's CSR mobility across the portfolio breaks.
The one-framework approach inverts the problem. The platform writes one compliance framework, calibrates it to the strictest applicable rule across the footprint (default to all-party consent on every recorded call, default to FCRA-strict on every adverse-action notice, default to TCPA-strict on every outbound text), and overrides specific elements where a state's rule is materially less burdensome and an override produces operational value. The framework is what every location runs by default; the override is the documented exception. The result: one playbook, one role-card discipline, one audit cadence, one configuration template per vendor with a per-state override schedule.
The framework's premise is simple. The cost of complying with the strictest rule everywhere is small relative to the cost of mis-complying with the strictest rule in one state. The 70% reduction in operational complexity is worth the 5-10% incremental compliance cost. The eight named PE platforms running the framework converge on this discipline; the broader landscape that runs state-by-state burns out on the operational complexity and absorbs the class-action exposure.
The Seven Federal Regimes That Bind Every Location
The federal layer is non-negotiable across all 50 states. Seven regimes hit trades AI directly in 2026. The framework starts with the federal layer and adds the state-law matrix on top.
Regime one: TCPA. Automated calls and texts. $500-$1,500 per violation; treble on willful. Class-action settlements in auto, retail, and lending adjacent industries run seven and eight figures. Active trades surface: Hatch sequence outbound, Avoca outbound recovery, Jobber AI Receptionist follow-up texts, Housecall Pro AI Agent outbound campaigns. Platform discipline: CRM-sourced consent enforcement at send time across every vendor; monthly TCPA audit of opt-outs, DNC, and wrong-number suppression; suppression list propagation across all 50 locations within 24 hours of customer opt-out.
Regime two: Reg Z. APR, term, fee, payment-schedule disclosure. $500-$5,000 per violation plus attorney fees, CFPB, state TILA-analog, state-AG, and loss of Wisetack/GreenSky/Synchrony status. Platform discipline: AI never drafts regulated financing language; portal output verbatim into proposals; literal "[paste portal output here]" placeholder in every AI-drafted advisor talk track.
Regime three: FCRA. Adverse-action notices on soft-pull declines. $100-$1,000 per violation plus actual damages plus attorney fees. Four required components โ action taken, credit-bureau ID with contact, score range with reason codes, dispute-rights notice. Platform discipline: lender's signed template is the only FCRA-compliant artifact; AI never originates adverse-action language.
Regime four: EPA Section 608. Refrigerant handling. Up to $44,539 per day per violation in 2026 plus criminal exposure on willful. Active trades AI surface: hallucinated R-454B charge weights, fabricated venting protocols, wrong recovery procedures. Platform discipline: AI never provides charge weights or venting/recovery without manufacturer-table cross-reference documented on the work order. The compliance binder at every location contains current R-454B manufacturer charge tables.
Regime five: FTC endorsement guidelines on AI-generated commercial content. The 2026 guidance treats AI-drafted review responses, marketing copy, and customer communications as endorsements of the shop's practices. Misrepresentation, fabrication, denial, or omission is deceptive endorsement. Platform discipline: commitment-language ban in every AI review-response system prompt; manager review pre-publication or 24-hour holding window; quarterly system-prompt audit.
Regime six: ADA on AI accessibility. Active 2026 surface as AI voice agents become the front-door experience. Platform discipline: AI voice agents tested against WCAG 2.1 AA; alternative paths (human CSR escalation, text-channel option) maintained; vendor-provided accessibility documentation in the master agreement file.
Regime seven: OSHA on AI-driven dispatch in hazardous work environments. Tech-safety obligations remain the shop's regardless of AI dispatch. Platform discipline: AI dispatch for hazardous work (commercial mechanical rooms, electrical panel rooms, refrigerant handling, confined space) requires a confirmation gate where the dispatcher or service manager verifies tech qualifications and PPE before commit.
The State-Law Matrix and Default-to-Strictest
The state-law layer adds three primary surfaces: contractor licensing, recording consent, and state-specific AI/consumer-data statutes. Each surface has a strictest-rule baseline the platform defaults to.
Contractor licensing varies by state and trade โ California's CSLB, Texas's TDLR, Florida's DBPR, New York's regional authorities, NCBELP for North Carolina electrical, Pennsylvania's HICPA for home improvement, plus county and municipal patchwork. Each board investigates misrepresentation, code violation, unlicensed work, and warranty failures. Platform discipline: every customer-facing AI artifact (proposals, work orders, permit applications, scope-of-work language) gets named licensed-individual signoff documented on the artifact. The licensed individual is the respondent; the signoff trail is the reasonable-care demonstration.
Recording-consent law: twelve all-party jurisdictions โ California (Penal Code ยง 632), Pennsylvania (Wiretap Act), Florida (with caveats โ ยง 934.03 treats electronic communications with reasonable expectation of privacy as all-party), Illinois (720 ILCS 5/14 + BIPA voiceprint stacking), Massachusetts (MGL c. 272 ยง 99), Maryland, Connecticut, Delaware, Montana (ยง 45-8-213), Washington (RCW ยง 9.73.030), New Hampshire (RSA ยง 570-A), DC (ยง 23-542). Per-call exposure $1,000-$10,000 plus civil. Platform discipline: default every CallRail, ServiceTitan, Avoca, Rilla, Jobber AI Receptionist, and Housecall Pro AI Agent tenant to all-party with affirmative-consent disclosure. No location opts out without documented General Counsel approval and a state-specific operational rationale.
State-specific AI and consumer-data statutes are the fastest-moving layer. California (CCPA/CPRA + 2026 AI automated-decision-making rights expansion), Colorado (AI Act effective 2026, high-risk AI disclosure obligations), Illinois (BIPA + HB 3773 amendments), Texas (DPSA + emerging contractor-board AI guidance), Virginia (CDPA), Connecticut (CTDPA), New York (SHIELD + pending AI consumer-disclosure legislation), Washington (My Health My Data Act). Platform discipline: privacy notice meets the strictest state's requirements; opt-out architecture meets CCPA/CPRA/CTDPA/CDPA across the board; automated-decision-making disclosure meets Colorado AI Act; voiceprint disclosure meets BIPA. One privacy posture, calibrated to strictest, deployed everywhere.
The Platform-Level Configuration Discipline Per Vendor
The framework collapses into operational reality at the vendor-configuration layer. Every AI vendor in the platform stack has a configuration matrix the Director of AI Operations and the CISO maintain. Each row is a vendor-state pair; each column is a configuration setting tied to a compliance regime. The matrix is the operational instrument the monthly vendor-configuration audit reviews.
CallRail: per-tracking-number recording-disclosure language defaulted to all-party with counsel-reviewed text. AI-processing disclosure added in the 2026 CallRail product update (consent extends to AI-driven sentiment, transcript classification, lead-source attribution). Per-state overrides require General Counsel approval. Audit: monthly random sample of 5 tracking numbers per location; quarterly sample of 20 calls per location for full-recording compliance.
ServiceTitan call recording: per-territory phone integration configured to all-party with affirmative-consent disclosure as first utterance after greeting on every inbound call. Audit: monthly verification at one random territory per location; quarterly platform-wide 50-call audit.
Avoca: per-state system prompt with disclosure as first utterance after the AI agent's greeting โ "this call is being recorded and processed by an AI assistant for quality, training, and service-improvement purposes; if you do not consent, please advise the agent." Avoca's vendor success manager maintains the per-state template; platform reviews quarterly. Audit: monthly sample of 10 calls per location.
Rilla: per-advisor verbal disclosure script at the kitchen-table door, captured in the recording. Spousal re-disclosure protocol mandatory when the spouse enters mid-conversation: "Quick note โ I'm recording our conversation for follow-up notes and coaching; by continuing, you consent. If you'd rather I not record, I'll pause." Audit: monthly sample of 3 ride-along recordings per advisor; quarterly per-advisor disclosure-completion-rate trend review.
Hatch: CRM-sourced consent enforcement at send time. Hatch reads the authoritative consent log from ServiceTitan / Sera / Housecall Pro at send time; opt-outs propagate from any vendor surface (CSR disposition, AI-call closing, customer "stop" text) to Hatch within 24 hours. Audit: monthly TCPA audit of outbound volume vs. opt-out propagation latency.
Wisetack, GreenSky, Synchrony: portal output is the regulated artifact; AI does not touch APR, term, payment schedule, or adverse-action language. Master proposal templates carry the literal "[paste portal output here]" placeholder; AI drafts surrounding talk-track only. Audit: monthly sample of 5 financed jobs per location verifying portal output pasted verbatim, not paraphrased.
Podium AI Employee, Birdeye AI Employee, NiceJob, Yelp AI: review-response system prompts carry the platform-wide commitment-language ban (forbidden patterns: "we will refund," "we guarantee," "this won't happen again," "we'll be there tomorrow," and the full forbidden list). 24-hour holding window before publication; manager review above the AI-confidence threshold. Audit: quarterly sample of 10 published responses per location.
The Strictest-State Defaults and the Documented Overrides
The default-to-strictest framework establishes platform-wide settings calibrated to the most restrictive applicable rule. Some platform operators question whether the operational cost of strictest-everywhere is worth the simplicity; the math says yes. The override mechanism handles the narrow cases where a less-strict state's rule produces operational value.
The strictest defaults: all-party consent on every recorded call across all 50 locations regardless of state; CRM-sourced TCPA opt-out enforcement at send time with 24-hour propagation SLA; FCRA-strict adverse-action notice with all four required components on every soft-pull decline; FTC commitment-language ban in every AI review-response system prompt platform-wide; EPA 608 manufacturer-table cross-reference documented on every work order; Colorado AI Act automated-decision-making disclosure included in every customer-facing AI interaction (even in states without that requirement). The defaults are the platform's baseline; every location runs them by default; the framework is what the GM signs in the per-location operating procedure.
The override mechanism: any location-specific or state-specific deviation from the default requires a written override request to the Director of AI Operations and General Counsel. The request documents the deviation, the operational rationale, the state-law basis, and the proposed control. The review SLA is 14 days. Approved overrides go into the per-vendor configuration matrix with an effective date, expiration date, and renewal review. Unapproved deviations are policy breaches surfaced in the failure log.
Most platforms maintain fewer than 15 active overrides across 50 locations. The overrides typically cluster around specific contractor-licensing language at the state-board level (Texas TDLR requires certain disclosure language that conflicts with the default), state-specific commercial-customer disclosures (Pennsylvania's home improvement act has specific commercial-vs-residential language requirements), and certain financing-portal state-specific disclosures that the lender adds to portal output (which the AI must not modify). The override discipline is what makes the strictest-everywhere framework practical at scale.
The Audit Cadence That Keeps Fifty Locations Tight
The framework survives at scale only if the audit cadence catches drift before it materializes. Monthly vendor-configuration audit is the heartbeat โ Director of AI Operations pulls the per-vendor configuration matrix and verifies, at every tenant, that configuration matches the strictest default plus any approved override. Automated where possible (CallRail and ServiceTitan API access; Avoca and Rilla vendor dashboards), manual where required (Rilla audio sampling for verbal disclosure).
Quarterly compliance committee (General Counsel lead, Director of AI Operations, CISO, Chief Procurement Officer, rotating regional director) reviews state-law changes (new statutes, court decisions, regulatory guidance) and assesses framework updates; reviews flagged failure-log items with multi-state implications; reviews override approvals and renewals; assesses platform-wide TCPA, two-party-consent, Reg Z/FCRA, and EPA 608 exposure trends.
Annual external counsel review: an independent firm with multi-state trades and PE-portfolio experience reviews the framework, override schedule, audit cadence, and failure log. External review surfaces gaps the internal team has acclimated to. Output is a memo to CEO and PE partner documenting defensibility posture โ lives in the LP reporting package and is referenced in any subsequent regulatory inquiry.
Incident response cadence: any compliance incident (TCPA complaint, two-party-consent challenge, Reg Z dispute, FCRA gap, EPA 608 audit notification, state contractor board complaint) triggers a 24-hour incident memo to Director of AI Operations and General Counsel; 72-hour response plan; 30-day failure-log entry with remediation and root-cause attribution; 90-day framework update if the incident reveals systemic gap. The cadence converts incidents into framework refinement rather than recurring exposure.
How the Eight Platforms Actually Run This in 2026
Wrench Group runs the framework with consolidated General Counsel oversight at HQ. CallRail, ServiceTitan recording, and Avoca tenants configured platform-wide to all-party consent with annual external counsel review. Override schedule maintains roughly 8 active overrides, primarily clustered around state contractor-board disclosure language requirements.
Authority Brands runs the framework across One Hour Heating & Air, Benjamin Franklin, and Mister Sparky franchise networks. The complexity layer is franchise structure โ franchisees are independently licensed. The framework includes a franchisee compliance kit with strictest-default settings, override request process, and audit obligation; franchisees sign the kit as part of franchise-agreement compliance. Override process scales across franchise structure with franchisor-counsel review.
Apex Service Partners runs the framework with the 90-day post-acquisition integration plan including framework deployment. New acquisitions inherit strictest-default configuration at vendor onboarding; pre-existing state-specific configurations migrate to default or get filed as overrides during integration. The acquisition cadence absorbs into the framework rather than bypassing it.
Sila Services has standardized on the framework across the Northeast HVAC portfolio with particular attention to the all-party consent jurisdictions concentrated there (MA, CT, PA, DE). Path Light Pro runs it across the electrical platform with attention to state-board electrical licensing variations. Redwood Services and ARS-Rescue Rooter run portfolio-specific variations. Names differ; framework converges. The eight platforms' compliance frameworks are the LP-capital signal of durable operational advantage.
Key Takeaways
- One framework calibrated to 50 states. The 50-policy approach burns out the compliance team and absorbs class-action exposure. The one-framework approach defaults to the strictest applicable rule across the footprint and overrides specific elements where less-strict rules produce operational value. Cost of strictest-everywhere is small relative to mis-complying in one state.
- Seven federal regimes bind every location. TCPA (automated calls/texts, $500-$1,500 per violation, treble on willful, class-action exposure); Reg Z (financing disclosures, $500-$5,000 per violation, CFPB plus state TILA-analog); FCRA (adverse-action notices, $100-$1,000 per violation, four required components, lender template only); EPA 608 (refrigerant handling, up to $44,539 per day per violation, manufacturer-table cross-reference required); FTC endorsement (AI review responses, commitment-language ban); ADA (AI accessibility, WCAG 2.1 AA standard); OSHA (AI dispatch in hazardous environments, dispatcher confirmation gate).
- State-law matrix adds three surfaces. Contractor licensing (CSLB, TDLR, DBPR, NCBELP, HICPA, plus county/municipal patchwork; named licensed-individual signoff on every customer-facing artifact). Recording consent (twelve all-party jurisdictions: CA, PA, FL with caveats, IL with BIPA stacking, MA, MD, CT, DE, MT, WA, NH, DC; default to all-party everywhere). State-specific AI/consumer-data statutes (CCPA/CPRA, Colorado AI Act, BIPA, Texas DPSA, Virginia CDPA, Connecticut CTDPA, NY SHIELD; default to strictest privacy posture).
- Vendor-configuration matrix is the operational instrument. Each row is a vendor-state pair; each column is a configuration setting tied to a compliance regime. Maintained by the Director of AI Operations and platform CISO. Reviewed monthly. Audit cadence is automated where possible (CallRail/ServiceTitan API access) and manual where required (Rilla audio sampling).
- Per-vendor configuration discipline at platform scale. CallRail per-tracking-number all-party defaults; ServiceTitan per-territory all-party; Avoca per-state system prompt with AI-processing disclosure; Rilla per-advisor verbal disclosure with spousal re-disclosure protocol; Hatch CRM-sourced TCPA enforcement with 24-hour opt-out propagation; Wisetack/GreenSky/Synchrony portal-output verbatim; Podium/Birdeye/NiceJob commitment-language ban with 24-hour holding window.
- Override mechanism is the documented exception. Any deviation from strictest-everywhere requires written override request, Director of AI Operations and General Counsel review (14-day SLA), and per-vendor configuration matrix entry with effective date, expiration date, and renewal review. Most platforms maintain fewer than 15 active overrides across 50 locations.
- Audit cadence catches drift. Monthly vendor-configuration audit; quarterly compliance committee (General Counsel, Director of AI Operations, CISO, CPO, rotating regional director) reviewing state-law changes, override approvals, exposure trends; annual external counsel review documenting framework defensibility posture in a memo that lives in LP reporting; incident response within 24 / 72 / 30 / 90-day cadence converting incidents into framework refinement.
- How the eight platforms run this. Wrench Group: consolidated GC oversight, roughly 8 active overrides. Authority Brands: franchisee compliance kit with override process scaled across franchise structure. Apex Service Partners: 90-day post-acquisition integration includes framework deployment. Sila Services: Northeast all-party-consent focus. Path Light Pro: state contractor-board electrical licensing variations. Redwood and ARS: portfolio-specific variations of same framework. Names differ; framework converges.
- Strictest-default settings calibrated platform-wide. All-party consent on every recorded call regardless of state; CRM-sourced TCPA opt-out with 24-hour propagation SLA; FCRA-strict adverse-action with all four components; FTC commitment-language ban in every review-response system prompt; EPA 608 manufacturer-table cross-reference on every work order; Colorado AI Act automated-decision-making disclosure included in every customer-facing AI interaction.
- The asymmetric architecture holds. Framework cost is small relative to single-incident exposure. A misconfigured Massachusetts CallRail tenant in a 30-location portfolio: 5K calls/month ร 12 months ร $1K-$10K per call statutory = $60M-$600M potential class-action exposure. Framework cost: roughly $200K-$400K annual compliance overhead at platform scale. Framework pays back in the first prevented incident.
- The framework is the LP capital signal. PE capital reads compliance discipline at the framework level rather than the state-policy level. The eight platforms running the framework demonstrate operating maturity; the broader landscape running state-by-state demonstrates operational fragmentation. The framework is part of the structural moat that concentrates ~60% of 2026 trades PE deal flow.
Skill.re