Voice AI Compliance Comparison Guide for 2026
Voice AI compliance cannot be reduced to a row of badges. HIPAA does not offer a general product certification. A SOC 2 report covers specified controls, systems, criteria, and a period in time. APRA-regulated entities retain accountability when they use a service provider. An IRAP assessment is not an Australian Government certification or endorsement. Telemarketing obligations depend on the caller, purpose, consent, number, jurisdiction, and workflow.
That makes an evidence-based comparison more useful than a vendor leaderboard. Compare the exact service, deployment, data flow, contract, control evidence, and customer responsibilities that apply to your proposed use case.
This guide explains what to request for HIPAA, SOC 2, GDPR, US TCPA, Australian telemarketing rules, APRA CPS 234, and IRAP. It also distinguishes Trillet’s current platform evidence from engagement-specific commitments.
This is a procurement framework, not legal advice. Ask qualified counsel to assess the laws and regulations that apply to your organization and calls.
The Evidence Hierarchy for Voice AI Procurement
Marketing pages are useful for discovery, but they are not enough for approval. Use this hierarchy:
- Executed contract and addenda: the order form, statement of work, data processing agreement, Business Associate Agreement, service-level agreement, and security addendum that bind the parties.
- Scoped independent evidence: current audit reports, certificates, assessment reports, penetration-test summaries, and remediation evidence covering the service you will use.
- Architecture and data-flow evidence: subprocessors, regions, retention, encryption, access paths, backups, logs, model and speech providers, and support access.
- Configured workflow evidence: consent, disclosures, suppression, identity checks, escalation, human oversight, audit trails, and acceptance tests.
- Public statements: useful leads that must be matched to the contracted service and deployment.
Silence on a public website is not proof that a vendor lacks a control. A logo is not proof that the control applies to your purchased service.
Compliance Comparison Matrix: What Each Item Proves
| Item | Useful evidence | What it can support | What it does not prove |
|---|---|---|---|
| HIPAA | Executed BAA, covered-workflow order form, security documentation, subprocessor terms | Contractual allocation and safeguards for covered PHI processing | “HIPAA certification,” lawful design of every customer workflow, or customer compliance |
| SOC 2 | Current report, system description, criteria, exceptions, complementary user controls | Independent examination of described controls | Coverage of systems outside scope or compliance with every privacy law |
| ISO 27001 | Current certificate, scope statement, certification body | Certified information-security management system within scope | That every product feature or configured workflow has no risk |
| GDPR | DPA, roles, instructions, subprocessor terms, transfer mechanism, data-flow map | Processor obligations and transfer arrangements for covered processing | A universal “GDPR compliant” result regardless of customer purpose and lawful basis |
| TCPA | Counsel-reviewed workflow, consent records, identification, opt-out and suppression controls | Operational support for applicable US calling rules | Permission to call every number or use every artificial/prerecorded voice |
| Australian telemarketing | DNCR screening process, consent/exemption evidence, calling-time and identification controls | Operational support for Australian telemarketing obligations | That platform configuration transfers the caller’s legal responsibility |
| CPS 234 | Provider assessment, control evidence, testing, incident and material-service-provider terms | Customer due diligence and third-party control assessment | “APRA certification” or transfer of an APRA-regulated entity’s accountability |
| IRAP | Assessment report or exact assessment statement, scope, date, assessor, findings and remediation | Independent assessment against the nominated controls and system boundary | IRAP certification, accreditation, endorsement, or approval by ASD |
HIPAA: Look for the BAA and the Covered Workflow
The US Department of Health and Human Services explains that a covered entity or business associate may use a cloud service to store or process electronic protected health information when the parties have an appropriate Business Associate Agreement and comply with the HIPAA Rules. HHS also emphasizes risk analysis and risk management; outsourcing does not remove those duties. See the HHS cloud-computing guidance and HHS sample BAA provisions.
For a voice AI workflow, ask:
- Will the service create, receive, maintain, or transmit PHI?
- Which Trillet and third-party components touch it?
- Is the BAA executed before covered processing begins?
- Does the order form identify the covered workflow and deployment?
- Which safeguards, incident terms, retention settings, and return-or-destruction provisions apply?
- Which responsibilities remain with the covered entity or business associate?
Trillet’s public terms state that customers may not process PHI through the service unless Trillet has executed a BAA and the applicable Order Form identifies the HIPAA-covered workflow. BAAs are available for Agency and Enterprise tiers through Trillet’s BAA process; they are not part of the consumer or Studio offering. This is a contractual and technical arrangement, not a claim of “HIPAA certification.”
SOC 2 and ISO 27001: Verify Scope, Not Just the Logo
The AICPA describes SOC 2 as reporting on controls relevant to security, availability, processing integrity, confidentiality, or privacy. A buyer should review which criteria were included, the system description, examination period, exceptions, subservice-organization treatment, and complementary user-entity controls.
For ISO 27001, request the certificate and its scope. Check the legal entity, sites, services, and expiration, and ask how the certified management system connects to the product and deployment being purchased.
Trillet holds SOC 2 Type II and ISO 27001. Those provide meaningful assurance within their stated scope. They do not replace workflow-specific review, customer configuration, contractual terms, or due diligence on subprocessors and integrations.
GDPR: Compare Roles, Instructions, Transfers, and Data Flows
The GDPR can apply based on establishment and processing activity, not simply because a caller is an “EU resident.” Start by identifying the controller, processor, purpose, lawful basis, data subjects, data categories, and where each service component operates.
The European Commission’s GDPR guidance for organizations explains the controller-processor relationship and the need for a binding contract when a processor acts on a controller’s behalf. The Commission’s obligations guidance also describes security and breach-notification responsibilities.
Ask a voice AI provider for:
- a DPA stating subject matter, duration, nature, purpose, data types, and categories of data subjects;
- documented instructions and confidentiality commitments;
- security measures and assistance obligations;
- subprocessor authorization and change-notice terms;
- the applicable international-transfer mechanism;
- deletion or return terms; and
- a data-flow diagram covering telephony, speech, model, application, monitoring, backup, and support systems.
Trillet can execute applicable enterprise data terms. Any DPA, transfer mechanism, residency commitment, or dedicated deployment must match the contracted workflow. The customer remains responsible for its purposes, lawful basis, notices, consent where required, and data-subject handling.
TCPA: Artificial Voice Technology Does Not Remove Calling Rules
In its 2024 declaratory ruling, the US Federal Communications Commission concluded that AI-generated voices fall within the TCPA restriction on “artificial or prerecorded voice” calls. The ruling discusses prior express consent absent an emergency purpose or exemption, identification requirements, and opt-out requirements for covered telemarketing calls. Read the FCC declaratory ruling.
A procurement review should test the real campaign, not ask only whether the platform is “TCPA compliant.” Examine:
- call purpose and number type;
- consent language, source, scope, and revocation;
- caller identification and required disclosures;
- time-zone and calling-hour controls;
- do-not-call and opt-out handling;
- number reassignment and recordkeeping processes; and
- responsibility for scripts, lists, suppression, and campaign approval.
Platform controls can help implement a reviewed process. They cannot create consent or make an unlawful campaign lawful.
Australia: DNCR and Telemarketing Controls
The Australian Communications and Media Authority explains that organizations generally must not call numbers on the Do Not Call Register without consent or an exemption, and that consent can be withdrawn. See the ACMA Do Not Call Register guidance.
ACMA also maintains and enforces the Telemarketing and Research Calls Industry Standard 2017, which addresses matters including permitted calling times, caller identification, and termination of calls.
For Australian calling, validate the organization’s screening, consent and exemption evidence, identification, calling windows, opt-out process, complaint handling, and records. A voice AI provider can configure agreed controls, but the organization making or authorizing calls remains responsible for its legal obligations.
APRA CPS 234: The Regulated Entity Remains Accountable
APRA Prudential Standard CPS 234 applies to APRA-regulated entities and requires them to maintain information-security capability, implement controls, test control effectiveness, and notify APRA in specified circumstances. It also addresses information assets managed by related or third parties.
CPS 234 is not a vendor certification. An APRA-regulated buyer should assess whether the provider’s capabilities and controls are commensurate with the criticality and sensitivity of the relevant assets, obtain appropriate testing assurance, and put necessary obligations into its arrangements.
Ask how the provider supports:
- identification and classification of relevant information assets;
- evaluation of provider controls and capabilities;
- systematic testing and access to assurance;
- incident notification and investigation;
- material-service-provider governance; and
- remediation of identified control weaknesses.
Trillet can scope controls and contractual support for an APRA-regulated engagement. The exact architecture, assurance access, incident terms, residency, and deployment model must be agreed; Trillet should not be described as “APRA certified.”
IRAP: An Assessment Is Not a Certification
The Australian Signals Directorate’s IRAP brand and marketing guidelines state that IRAP assessors do not accredit, certify, endorse, or register systems on ASD’s behalf.
If a provider refers to IRAP, request the exact system assessed, control baseline, assessment date, assessor, report availability, findings, remediation status, and whether the proposed deployment is inside that boundary. Use precise language such as “underwent an IRAP assessment” only when the evidence supports it.
IRAP support or assessment for a Trillet deployment is engagement-specific. Do not infer an assessment, government approval, or fixed control boundary from the general platform.
Data Residency and On-Premises Deployment
“Hosted in Australia,” “regional storage,” and “all data stays on-premises” are different claims. A voice call can traverse a carrier, speech service, model provider, orchestration layer, monitoring system, integration, backup, and support workflow.
For every component, record:
- data received and produced;
- processing and storage location;
- retention and backup behaviour;
- encryption and key ownership;
- support and administrative access;
- subprocessors and onward transfers; and
- behaviour during failure or support escalation.
Trillet can scope Docker-based on-premises deployment, private deployment, and data-residency requirements by agreement. A container alone does not prove that every byte of audio, transcript, metadata, log, backup, or support data remains inside the customer boundary.
How Trillet Should Be Compared
The accurate current baseline is:
- Trillet holds SOC 2 Type II and ISO 27001.
- HIPAA-covered processing requires an executed BAA and an applicable Order Form identifying the workflow; BAAs are available on Agency and Enterprise tiers.
- GDPR-covered processing may require an applicable DPA and transfer mechanism.
- TCPA and ACMA controls must be configured for the customer’s reviewed calling workflow.
- CPS 234 support, IRAP work, data residency, dedicated infrastructure, on-premises deployment, and special security terms are engagement-specific.
- Service levels, support response times, and credits apply only when defined in the signed agreement.
- Customers remain responsible for lawful use, lists, consent, notices, configuration, testing, and oversight.
These statements are less dramatic than a page of checkmarks, but they are far more useful during diligence.
A 12-Question Vendor Checklist
- Which legal entity provides the service and signs the data terms?
- Which exact product, region, and deployment are within each report or certificate?
- Which subprocessors touch audio, transcripts, metadata, logs, and backups?
- What data is stored, where, for how long, and under whose keys?
- Which contract covers regulated data before processing begins?
- What customer controls and responsibilities are assumed?
- How are consent, disclosure, recording, opt-out, and suppression implemented?
- What happens when telephony, speech, model, or business systems fail?
- What audit, assessment, penetration-test, and remediation evidence is available?
- What incident-notice trigger and time period does the contract define?
- What can the customer export, and how are data and backups handled at exit?
- Which service levels and remedies are actually in the signed agreement?
Frequently Asked Questions
Is a voice AI platform “HIPAA certified”?
HIPAA does not provide a general government certification for voice AI products. Look for an executed BAA, applicable contract scope, safeguards, and evidence that the specific workflow is configured and operated appropriately.
Does SOC 2 Type II mean a platform complies with GDPR or HIPAA?
No. A SOC 2 examination can provide valuable control assurance, but its conclusion depends on the report scope and criteria. GDPR and HIPAA add legal, contractual, and workflow-specific obligations.
Is there an APRA CPS 234 certification?
No. CPS 234 imposes obligations on APRA-regulated entities, including for information assets managed by third parties. Provider evidence can support the entity’s assessment; it does not transfer accountability.
What does “IRAP assessed” mean?
It should refer to a particular system boundary assessed against nominated controls at a particular time. It does not mean ASD has certified, accredited, endorsed, or approved the system.
Does Trillet include every compliance commitment on every plan?
No. Trillet’s SOC 2 Type II and ISO 27001 are current platform evidence. BAAs are available for Agency and Enterprise subject to the required agreement. Other regulated-data, residency, deployment, service-level, and assessment commitments depend on the signed scope.
Compare Evidence, Not Badges
A reliable compliance comparison does not ask which vendor displays the most acronyms. It asks whether the evidence, contract, architecture, and configured workflow cover the organization’s actual risk.
Contact Trillet Enterprise to review a proposed workflow, data boundary, deployment model, and required contractual evidence.
Updated September 2026 to remove unsupported vendor rankings and pricing, correct HIPAA, CPS 234, and IRAP terminology, and align Trillet claims with current public terms.




