Executive Summary
Credit unions rely on SMS for one-time passcodes, fraud alerts, payment reminders, and occasional marketing. SMS for credit unions usually mixes high-trust informational traffic with optional promotional programs. US local numbers require A2P 10DLC Brand/Campaign registration; dedicated short codes remain a parallel path for some high-volume or branded programs. Consent lanes must keep fraud/OTP traffic reliable while marketing remains optional and revocable.
Short answer: Register 10DLC (or operate an approved short code/toll-free program) for CU messaging. Separate OTP/fraud Campaigns from marketing. Never condition account opening on marketing SMS consent. Confirm fees and throughput with your CSP—do not invent universal figures.
Who This Is For / Who It Is Not For
Who this is for
- Credit union digital and fraud teams
- CUSO/vendors implementing member SMS
- Compliance officers reviewing TCPA + NCUA expectations with counsel
Who this is not for
- Fintechs seeking banking charters via SMS tricks
- Non-US-only wallets
Definitions
| Term | CU context |
|---|---|
| OTP / 2FA | Login or transaction verification codes |
| Fraud alert | Suspected activity notices |
| Short code | 5–6 digit shared/dedicated sender |
| 10DLC | Local long code A2P path |
| Mixed traffic risk | Putting promos on fraud numbers |
10DLC vs Short Code for Credit Unions
| Factor | 10DLC | Short code |
|---|---|---|
| Setup | Brand + Campaign via CSP/TCR | Carrier/program provisioning—longer/heavier |
| Branding | Local number | Memorable short code |
| Typical use | Many CU programs via core/CPaaS | High-volume or legacy branded programs |
| Consent | Still required by purpose | Still required |
Some teams use Twilio Verify–style products for OTP with distinct onboarding—confirm whether that path still needs 10DLC in your architecture.
Use-Case and Consent Matrix
| Message | Lane | Consent posture |
|---|---|---|
| OTP | Auth | Account/security relationship disclosures |
| Fraud alert | Security | Membership + channel preference |
| Payment due | Servicing | Account disclosures; avoid marketing fluff |
| Loan promo | Marketing | PEWC, not required for membership |
Decision Framework
- Inventory all SMS vendors (core, card, fraud, marketing).
- Assign each to 10DLC Campaign or short code program.
- Forbid marketing templates on OTP/fraud senders.
- Centralize STOP for marketing; define security-message exceptions with counsel.
- Register/verify before seasonal lending campaigns.
- Tabletop a STOP vs fraud-alert conflict scenario.
Risk and Failure Modes
| Risk | Mitigation |
|---|---|
| Promo on fraud code | Hard separate services |
| Unregistered 10DLC | Pre-launch registration gate |
| Slow STOP on marketing | Suppression SLA |
| Vendor sprawl | Number/Campaign inventory |
Implementation Checklist
| Step | Owner | Artifact |
|---|---|---|
| Vendor census | Digital | Inventory |
| Lane architecture | Compliance + fraud | Diagram |
| Brand/Campaign or short code | CSP admin | IDs |
| Marketing PEWC UX | Marketing | Screens |
| Quarterly audit | Compliance | Report |
Soft CTA
Preflight 10DLC packaging with MyTCRPlus tools. Not a substitute for financial-services counsel.
FAQ
Do credit unions need 10DLC?
For US local long-code A2P SMS, typically yes unless using another approved path.
Should fraud alerts and promos share a Campaign?
Prefer separation to protect critical traffic and consent clarity.
Are short codes mandatory for CUs?
No—many operate on 10DLC/toll-free; short codes are optional for specific needs.
Does membership agreement equal marketing PEWC?
Usually not—use explicit SMS marketing opt-in.
Key Takeaways
- Separate security and marketing SMS lanes.
- Register 10DLC or provision short codes deliberately.
- Inventory every vendor that can text members.
- Confirm fees/throughput with providers—no invented universals.
- Test STOP vs critical alerts with counsel-designed rules.
Extended Implementation Playbook
This playbook converts the principles in the article into a sequenced project plan your team can execute without guessing.
Phase 0 — Discovery (week 1)
Interview every team that can trigger an SMS. Export template lists from each vendor. Classify each template as marketing, informational, or conversational care. Identify which legal entity owns each sending number. Capture current consent language screenshots. Produce a gap list: unregistered numbers, missing privacy URLs, bundled checkboxes, and vendors without STOP webhooks.
Phase 1 — Foundations (weeks 2–3)
Publish or repair website privacy and SMS terms. Align legal name and tax ID documents for Brand registration. Select Brand type with your CSP based on expected volume—without inventing universal fee or MPS figures. Draft Campaign descriptions using the who/who/why test. Write message flows that narrate the real opt-in path. Prepare sample messages with brand identification and STOP language.
Phase 2 — Registration (weeks 3–5)
Submit Brand; resolve verification issues immediately. Submit Campaign(s); respond to rejection reasons with packaging fixes rather than argument. Associate numbers only after approval. Configure HELP/STOP replies and test from multiple carrier handsets. Confirm CSP-stated throughput for planning.
Phase 3 — Controls (weeks 5–6)
Connect all vendors to a central suppression list. Enforce template governance so production copy cannot drift silently from registered samples. Train staff with send permissions. Stand up weekly metrics: delivery failures, STOP rate, HELP volume, and exception counts. Create an incident severity model for post-STOP sends and unregistered traffic.
Phase 4 — Scale (ongoing)
Expand locations or programs only after soft-launch metrics stabilize. Revisit packaging when adding loyalty vendors, franchise markets, or new promo calendars. Schedule quarterly counsel review for consent language and state overlays. Re-verify Brand data after mergers, rebrands, or address changes.
RACI snapshot
| Activity | Compliance | Marketing | Engineering | Counsel | CSP admin |
|---|---|---|---|---|---|
| Consent copy | A | R | C | C | I |
| Campaign packaging | R | C | I | C | A |
| Number association | C | I | R | I | A |
| STOP propagation | A | I | R | I | C |
| Incident response | A | C | R | C | C |
Evidence you should be able to produce in 24 hours
- Brand ID and Campaign IDs
- Live privacy and SMS terms URLs
- Opt-in screenshot with version date
- Consent record sample with timestamp and disclosure hash
- STOP log showing suppression timestamps across systems
- Current sample message library
If you cannot produce these, you are not ready for aggressive growth sends—regardless of how polished the marketing calendar looks.
Executive talking points
- Registration identifies us to carriers; it does not create recipient consent.
- Throughput and fees are provider-specific; we will not quote invented industry averages.
- STOP must work everywhere we can send, not only in the primary ESP.
- Template drift is a first-class risk and will be gated like a production change.
Adapt timelines to your CSP review queues. This playbook is operational guidance, not a guarantee of approval timelines or legal safe harbor.
Extended Implementation Playbook
This playbook converts the principles in the article into a sequenced project plan your team can execute without guessing.
Phase 0 — Discovery (week 1)
Interview every team that can trigger an SMS. Export template lists from each vendor. Classify each template as marketing, informational, or conversational care. Identify which legal entity owns each sending number. Capture current consent language screenshots. Produce a gap list: unregistered numbers, missing privacy URLs, bundled checkboxes, and vendors without STOP webhooks.
Phase 1 — Foundations (weeks 2–3)
Publish or repair website privacy and SMS terms. Align legal name and tax ID documents for Brand registration. Select Brand type with your CSP based on expected volume—without inventing universal fee or MPS figures. Draft Campaign descriptions using the who/who/why test. Write message flows that narrate the real opt-in path. Prepare sample messages with brand identification and STOP language.
Phase 2 — Registration (weeks 3–5)
Submit Brand; resolve verification issues immediately. Submit Campaign(s); respond to rejection reasons with packaging fixes rather than argument. Associate numbers only after approval. Configure HELP/STOP replies and test from multiple carrier handsets. Confirm CSP-stated throughput for planning.
Phase 3 — Controls (weeks 5–6)
Connect all vendors to a central suppression list. Enforce template governance so production copy cannot drift silently from registered samples. Train staff with send permissions. Stand up weekly metrics: delivery failures, STOP rate, HELP volume, and exception counts. Create an incident severity model for post-STOP sends and unregistered traffic.
Phase 4 — Scale (ongoing)
Expand locations or programs only after soft-launch metrics stabilize. Revisit packaging when adding loyalty vendors, franchise markets, or new promo calendars. Schedule quarterly counsel review for consent language and state overlays. Re-verify Brand data after mergers, rebrands, or address changes.
RACI snapshot
| Activity | Compliance | Marketing | Engineering | Counsel | CSP admin |
|---|---|---|---|---|---|
| Consent copy | A | R | C | C | I |
| Campaign packaging | R | C | I | C | A |
| Number association | C | I | R | I | A |
| STOP propagation | A | I | R | I | C |
| Incident response | A | C | R | C | C |
Evidence you should be able to produce in 24 hours
- Brand ID and Campaign IDs
- Live privacy and SMS terms URLs
- Opt-in screenshot with version date
- Consent record sample with timestamp and disclosure hash
- STOP log showing suppression timestamps across systems
- Current sample message library
If you cannot produce these, you are not ready for aggressive growth sends—regardless of how polished the marketing calendar looks.
Executive talking points
- Registration identifies us to carriers; it does not create recipient consent.
- Throughput and fees are provider-specific; we will not quote invented industry averages.
- STOP must work everywhere we can send, not only in the primary ESP.
- Template drift is a first-class risk and will be gated like a production change.
Adapt timelines to your CSP review queues. This playbook is operational guidance, not a guarantee of approval timelines or legal safe harbor.
Extended Implementation Playbook
This playbook converts the principles in the article into a sequenced project plan your team can execute without guessing.
Phase 0 — Discovery (week 1)
Interview every team that can trigger an SMS. Export template lists from each vendor. Classify each template as marketing, informational, or conversational care. Identify which legal entity owns each sending number. Capture current consent language screenshots. Produce a gap list: unregistered numbers, missing privacy URLs, bundled checkboxes, and vendors without STOP webhooks.
Phase 1 — Foundations (weeks 2–3)
Publish or repair website privacy and SMS terms. Align legal name and tax ID documents for Brand registration. Select Brand type with your CSP based on expected volume—without inventing universal fee or MPS figures. Draft Campaign descriptions using the who/who/why test. Write message flows that narrate the real opt-in path. Prepare sample messages with brand identification and STOP language.
Phase 2 — Registration (weeks 3–5)
Submit Brand; resolve verification issues immediately. Submit Campaign(s); respond to rejection reasons with packaging fixes rather than argument. Associate numbers only after approval. Configure HELP/STOP replies and test from multiple carrier handsets. Confirm CSP-stated throughput for planning.
Phase 3 — Controls (weeks 5–6)
Connect all vendors to a central suppression list. Enforce template governance so production copy cannot drift silently from registered samples. Train staff with send permissions. Stand up weekly metrics: delivery failures, STOP rate, HELP volume, and exception counts. Create an incident severity model for post-STOP sends and unregistered traffic.
Phase 4 — Scale (ongoing)
Expand locations or programs only after soft-launch metrics stabilize. Revisit packaging when adding loyalty vendors, franchise markets, or new promo calendars. Schedule quarterly counsel review for consent language and state overlays. Re-verify Brand data after mergers, rebrands, or address changes.
RACI snapshot
| Activity | Compliance | Marketing | Engineering | Counsel | CSP admin |
|---|---|---|---|---|---|
| Consent copy | A | R | C | C | I |
| Campaign packaging | R | C | I | C | A |
| Number association | C | I | R | I | A |
| STOP propagation | A | I | R | I | C |
| Incident response | A | C | R | C | C |
Evidence you should be able to produce in 24 hours
- Brand ID and Campaign IDs
- Live privacy and SMS terms URLs
- Opt-in screenshot with version date
- Consent record sample with timestamp and disclosure hash
- STOP log showing suppression timestamps across systems
- Current sample message library
If you cannot produce these, you are not ready for aggressive growth sends—regardless of how polished the marketing calendar looks.
Executive talking points
- Registration identifies us to carriers; it does not create recipient consent.
- Throughput and fees are provider-specific; we will not quote invented industry averages.
- STOP must work everywhere we can send, not only in the primary ESP.
- Template drift is a first-class risk and will be gated like a production change.
Adapt timelines to your CSP review queues. This playbook is operational guidance, not a guarantee of approval timelines or legal safe harbor.
Extended Implementation Playbook
This playbook converts the principles in the article into a sequenced project plan your team can execute without guessing.
Phase 0 — Discovery (week 1)
Interview every team that can trigger an SMS. Export template lists from each vendor. Classify each template as marketing, informational, or conversational care. Identify which legal entity owns each sending number. Capture current consent language screenshots. Produce a gap list: unregistered numbers, missing privacy URLs, bundled checkboxes, and vendors without STOP webhooks.
Phase 1 — Foundations (weeks 2–3)
Publish or repair website privacy and SMS terms. Align legal name and tax ID documents for Brand registration. Select Brand type with your CSP based on expected volume—without inventing universal fee or MPS figures. Draft Campaign descriptions using the who/who/why test. Write message flows that narrate the real opt-in path. Prepare sample messages with brand identification and STOP language.
Phase 2 — Registration (weeks 3–5)
Submit Brand; resolve verification issues immediately. Submit Campaign(s); respond to rejection reasons with packaging fixes rather than argument. Associate numbers only after approval. Configure HELP/STOP replies and test from multiple carrier handsets. Confirm CSP-stated throughput for planning.
Phase 3 — Controls (weeks 5–6)
Connect all vendors to a central suppression list. Enforce template governance so production copy cannot drift silently from registered samples. Train staff with send permissions. Stand up weekly metrics: delivery failures, STOP rate, HELP volume, and exception counts. Create an incident severity model for post-STOP sends and unregistered traffic.
Phase 4 — Scale (ongoing)
Expand locations or programs only after soft-launch metrics stabilize. Revisit packaging when adding loyalty vendors, franchise markets, or new promo calendars. Schedule quarterly counsel review for consent language and state overlays. Re-verify Brand data after mergers, rebrands, or address changes.
RACI snapshot
| Activity | Compliance | Marketing | Engineering | Counsel | CSP admin |
|---|---|---|---|---|---|
| Consent copy | A | R | C | C | I |
| Campaign packaging | R | C | I | C | A |
| Number association | C | I | R | I | A |
| STOP propagation | A | I | R | I | C |
| Incident response | A | C | R | C | C |
Evidence you should be able to produce in 24 hours
- Brand ID and Campaign IDs
- Live privacy and SMS terms URLs
- Opt-in screenshot with version date
- Consent record sample with timestamp and disclosure hash
- STOP log showing suppression timestamps across systems
- Current sample message library
If you cannot produce these, you are not ready for aggressive growth sends—regardless of how polished the marketing calendar looks.
Executive talking points
- Registration identifies us to carriers; it does not create recipient consent.
- Throughput and fees are provider-specific; we will not quote invented industry averages.
- STOP must work everywhere we can send, not only in the primary ESP.
- Template drift is a first-class risk and will be gated like a production change.
Adapt timelines to your CSP review queues. This playbook is operational guidance, not a guarantee of approval timelines or legal safe harbor.
Disclaimer
Informational only—not legal, NCUA, or financial advice.