Hear Stuut chase cash! The agent doing $200M / mo in AI collections wants to chat.

Give Stuut a Ring

FDCPA and B2B dunning: Compliance notes for AR teams

Ben Winter
CPO
Table of contents

See Stuut in action

Get a personalized demo of Stuut and see how it can help with AR automation.

Get started

TL;DR: The FDCPA targets consumer debt and technically exempts commercial collections, but that exemption may be narrowing. California has become the first state to extend consumer-grade protections to commercial debt, and other states may follow. California's Rosenthal Act now applies FDCPA-level rules to commercial debts up to $500,000 (effective July 1, 2025), and Massachusetts and Texas statutes have never covered commercial collections, leaving California as the only state with B2B-specific rules so far. Every B2B AR team needs a timestamped audit trail of all contacts, a process for honoring stop-contact requests, and communications that never misrepresent the debt. Autonomous AR platforms help teams enforce these rules across email, SMS, and voice while logging every interaction in real time.

Most AR teams in manufacturing and distribution assume B2B collections face fewer regulations than consumer debt. That assumption was always incomplete. For businesses with California customers, it's now a direct legal liability, and other states may follow California's lead. Customer relationships in industrial markets depend on repeat business where a single aggressive dunning campaign risks the entire account relationship, not just the unpaid invoice.

Note: This article is general information, not legal advice

Understanding FDCPA: What it covers for B2B debt

FDCPA: Consumer vs. business debt

The Fair Debt Collection Practices Act, codified at 15 U.S.C. §§ 1692 et seq. and enacted in 1977, protects individuals from abusive collection practices. Its scope is deliberately narrow: the statute defines "debt" as obligations arising from transactions "primarily for personal, family, or household purposes." Commercial transactions fall outside that definition entirely because the FDCPA's definitions of "consumer" and "debt" restrict coverage to personal transactions, not business-to-business invoices.

Congress designed the law on the assumption that businesses can negotiate contract terms and protect their interests without federal intervention. The result is a two-track system:

Dimension FDCPA (consumer) B2B debt collection
Governing law 15 U.S.C. § 1692 (federal) Contract law + state statutes
Who is protected Individual consumers Businesses (varies by state)
Contact hour restrictions 8 AM to 9 PM debtor's time No federal rule. Varies by state.
Cease-communication rights Written request mandatory No federal requirement. State rules apply.
Misrepresentation prohibition Explicit, enforceable Contract law and state fraud statutes
Penalties for violations Statutory damages up to $1,000 + attorney fees Varies; Rosenthal Act mirrors FDCPA penalties in CA

FDCPA's B2B exemption explained

Because the statute limits "debt" to personal, family, or household obligations, invoices issued by one business to another for goods, services, or commercial credit fall outside federal FDCPA protection. This applies at the federal level regardless of the debt size or transaction type. A third-party collector contacting your commercial customer at 6 AM, threatening litigation they never intend to file, faces no FDCPA liability under federal law. State law, however, is a different matter.

B2B FDCPA risks: What you need to know

State B2B collection law compliance

The gap between federal exemption and state requirements is where B2B AR teams face real legal exposure. Three states carry the highest risk for teams in manufacturing and distribution:

  • California (Rosenthal Act, SB 1286): Effective July 1, 2025, California's SB 1286 expansion of the Rosenthal Fair Debt Collection Practices Act covers commercial debts up to $500,000 from transactions entered into, renewed, sold, or assigned on or after that date. Critically, the Rosenthal Act covers original creditors pursuing their own invoices, not just third-party collectors. If your company holds the invoice and your customer is in California, your internal AR team is subject to Rosenthal Act requirements.
  • Massachusetts: Chapter 93, Section 49 applies to consumer debt arising from personal, family, or household transactions and does not extend to commercial invoices.
  • Texas: Texas Finance Code Chapter 392 applies to consumer debt and does not extend to commercial collections.

If your accounts receivable portfolio spans multiple states, you're operating under multiple sets of rules simultaneously.

Keeping customer ties during dunning

The legal risk is real, but the relationship risk is often more expensive. Industrial mid-market companies build revenue on repeat purchasing cycles. A distributor receiving monthly shipments won't tolerate repeated aggressive calls from a supplier's collections team. Treating an overdue invoice as a confrontation rather than a coordination problem is the fastest way to lose that account.

The most common mistakes your team makes that damage customer relationships:

  • Wrong contact routing: Sending communications to the wrong person after being told to update your records
  • Empty threats: Referencing legal action or credit reporting you have no process to follow through on
  • Ignoring disputes: Sending escalating language on invoices still within the dispute window
  • Partial payment oversights: Treating an account as fully overdue when partial payment was already received

How to document for FDCPA compliance

Documentation is your primary defense. If a customer claims harassment, a timestamped, complete log of every contact attempt, every response, every promise-to-pay date, and every opt-out request determines whether you can prove your team acted professionally.

Manual logging creates challenges in practice because collectors managing large portfolios don't have time to accurately enter every call note, email sent, and portal submission into a spreadsheet after the fact. Notes get abbreviated, omitted, or entered hours later with imprecise timestamps.

Stuut addresses this by logging communications automatically across email, SMS, and AI voice calls. Every touchpoint writes to a centralized dashboard with a precise timestamp, channel, content, and response. Your AR Director can pull the complete history for any account in real time, and the full record syncs back to SAP, NetSuite, Oracle, or Dynamics via API.

Adapting FDCPA rules for B2B dunning

The FDCPA's core prohibitions are practical standards for any collection process, regardless of whether they technically apply to your receivables. Adopting them protects you under state law and protects the customer relationships your revenue depends on.

Accurate debt disclosure under FDCPA principles

Every dunning communication must contain accurate information about the debt. Under the FDCPA, misrepresenting a debt's character or legal status is explicitly prohibited, and the same standard applies to B2B collections through contract law and state statutes.

A compliant B2B dunning letter includes:

  • Invoice details: Invoice number, invoice date, and original due date
  • Exact amount owed: With any accrued interest or fees itemized separately
  • Original invoice attached: Not just referenced
  • Payment instructions: With accepted methods listed
  • Dispute contact: A clear contact method, whether email, phone, or portal
  • Company letterhead: With complete contact information.

Every one of these elements reduces the "I never received it" or "that's not the amount we agreed to" responses that delay payment and generate disputes. Reducing DSO starts with clean, accurate outreach.

Verifying collection actions under FDCPA principles

Never threaten an action you don't intend to take and aren't positioned to execute. This is one of the clearest FDCPA prohibitions for consumer collections, and it applies equally as a matter of basic credibility in B2B. Telling a customer you'll report them to a credit bureau when you don't have a reporting relationship creates a false statement in writing. Reserve escalation language for accounts where escalation is genuinely the next step.

How to log all dunning interactions

Manual logging often creates gaps because collectors managing large portfolios log calls at the end of the day, by which point the specific language used in each call is gone. Spreadsheets capture that a call happened, not what was said, what was agreed to, or what documentation was requested.

Stuut writes communication logs and dispute cases back to your ERP in real time without any data entry from your team. The ERP stays the system of record, and every promise-to-pay date, every invoice re-send, and every dispute acknowledgment is captured automatically. Your team can't reconstruct a complete account history from email threads and spreadsheets when a customer files a harassment claim or a dispute escalates to legal review.

Honoring 'stop contact' requests immediately

Under the FDCPA, the obligation to stop contact takes effect upon receipt of a written cease-communication request. Communications already sent before receipt do not constitute a violation, but all new outreach must stop from the point of receipt. For B2B teams operating in California, the same standard applies under the Rosenthal Act. In Massachusetts and Texas, the state debt-collection statutes do not reach commercial invoices, but honoring stop-contact requests remains a sound practice. In any jurisdiction, continuing outreach after a customer has asked you to stop can expose you to a harassment or unfair-practices claim.

The operational challenge is timing. A collector manages hundreds of accounts, and stop-contact requests can arrive between scheduled reminder batches. Without a process that connects the request to the contact queue quickly, you risk violating the request.

Stuut's platform triages inbound replies autonomously, flagging accounts with stop-contact or complex requests and routing them directly to your team for human review and action, with no manual spreadsheet update required.

Complying with state B2B collection rules

California's Rosenthal Act: FDCPA rules for B2B debt

California's Rosenthal Act expansion is the most significant recent development in B2B collection law. More importantly for manufacturers and distributors with California customers: The Rosenthal Act covers original creditors, not just third-party collectors. Your internal AR team running collections directly is covered.

Your B2B dunning process for California accounts must follow the same contact standards, cease-communication rules, and accurate representation requirements as a consumer collections workflow.

State-specific B2B collection compliance

California is the most explicit, but it's not alone. For AR teams managing geographically distributed portfolios, the compliance framework varies by state in ways that are difficult to track manually.

Massachusetts Chapter 93, Section 49 and Texas Finance Code Chapter 392 both apply to consumer debt only. Neither statute covers commercial invoices. As of July 2025, California's Rosenthal Act is the only state law that extends FDCPA-level protections to commercial collections.

When your contact queue is managed manually, staying within per-state rules across hundreds of accounts is practically impossible without automation.

How to build compliant B2B dunning workflows

Are your dunning scripts defensible?

Every template your team uses should clear these standards before it goes to customers:

B2B dunning compliance checklist:

  • Invoice number, date, due date, and exact amount on every communication
  • Original invoice attached or linked, not just referenced
  • No threats of legal action or credit reporting unless that action is immediately available and intended
  • Specific named contact for disputes and questions
  • Contact hour standards met for the debtor's state (required for California accounts under the Rosenthal Act; recommended elsewhere as best practice)
  • All outreach paused and flagged when dispute or stop-contact language is received
  • Full timestamped log of every touch stored and searchable

Logging calls for FDCPA defense

AI voice calling is a compliance asset when it's implemented correctly. Stuut's AI call agent contacts customers with full contextual knowledge of their account, including open invoices, payment history, and current collection status. Traditional manual calling leaves compliance to the individual collector's note-taking habits, producing inconsistent records across a portfolio of hundreds of accounts.

AR team dunning dos and don'ts

Do:

  • Cite specifics: Reference the invoice number, amount, and due date in every communication
  • Attach invoices: Link or attach the original invoice on every outreach
  • Log everything: Record every contact attempt with a timestamp and channel
  • Honor opt-outs immediately: Stop all channels simultaneously when a stop-contact request arrives
  • Reserve escalations: Use escalation language only when action is genuinely planned and available

Don't:

  • Threaten empty actions: Don't mention credit reporting or legal action unless those steps are immediately available
  • Contact third parties: Don't reach out to colleagues or supervisors to pressure payment
  • Ignore stop requests: Don't continue outreach after a written request to cease contact
  • Assume exemptions: Don't assume California's Rosenthal Act only applies to consumer-facing businesses

How to respond to harassment claims

When a customer formally complains about your collections process, pull the complete communication log for that account before responding. This log should show every email sent and received, every call attempted and connected, and every timestamp. With Stuut's centralized dashboard, that's a query, not a multi-hour reconstruction from email threads and spreadsheets.

A complete audit means showing contact frequency by week, the language used in each communication, the response history, and whether any opt-out or dispute notification exists in the record.

If a customer sends a written request to stop contact, cease all outreach immediately upon receipt. This applies whether the request accompanies a harassment claim, a litigation threat, or an allegation under California's Rosenthal Act. After receipt, you may only contact the customer to confirm you are complying with the request or to notify them of specific legal action your company is actively taking. In all three scenarios, preserve and document the complete communication record. Where litigation is threatened, consult legal counsel before resuming any contact.

Book a demo to see how Stuut executes compliant multi-channel B2B collections, logs every interaction automatically, and routes complex accounts to your team for human review.

FAQs

Does the FDCPA apply to B2B debt collection?

No, at the federal level. The FDCPA's definitions limit "debt" to obligations from transactions for personal, family, or household purposes, which excludes commercial invoices. In practice, California's Rosenthal Act (effective July 1, 2025) imposes FDCPA-level restrictions on commercial collections within that state. Massachusetts Chapter 93 Section 49 and Texas Finance Code Chapter 392 apply to consumer debt only.

What is California's Rosenthal Act and how does it affect B2B AR?

California's Rosenthal Fair Debt Collection Practices Act was expanded by SB 1286 to cover commercial debts up to $500,000 from transactions entered into, renewed, sold, or assigned on or after July 1, 2025. It applies to original creditors, not just third-party collectors, and willful violations carry penalties from $100 to $1,000 plus actual damages and attorney fees.

What must a compliant B2B dunning letter include?

Every dunning letter needs the invoice number, date, original due date, exact amount owed with fees itemized, a copy of the original invoice, payment instructions, and a named dispute contact. Threatening language must only reference actions your company is immediately prepared and authorized to take.

How long do I need to keep dunning communication records?

No single federal statute mandates a B2B retention period, but many legal teams recommend retaining records for the duration of the applicable statute of limitations for contract disputes in your state, plus additional time if litigation is pending. Consult your legal counsel to confirm the appropriate retention period for your jurisdiction, as timeframes vary. Complete timestamped logs are your primary defense in any harassment claim.

Key terms glossary

Dunning: A structured sequence of communications sent to a customer with an overdue invoice, starting with a polite reminder and escalating through formal notices based on days past due and customer response history.

FDCPA (Fair Debt Collection Practices Act): A federal statute (15 U.S.C. § 1692) enacted in 1977 that prohibits abusive, unfair, and deceptive collection practices. It applies exclusively to consumer debt arising from personal, family, or household transactions and does not cover commercial B2B invoices at the federal level.

Rosenthal Act: California's Fair Debt Collection Practices Act, which mirrors and in some ways exceeds the FDCPA. As of July 1, 2025, it covers commercial debts up to $500,000 and applies to original creditors pursuing their own invoices, not only third-party collection agencies.

DSO (Days Sales Outstanding): The average number of days a company takes to collect payment after completing a sale. Every additional day represents cash sitting in AR rather than funding operations.

Cash application: The process of matching incoming payments to the correct open invoices in the ERP. Manual cash application requires a specialist to reconcile remittance details against the AR subledger, a process Stuut automates at a 95% or higher match rate.

Cease-communication request: A formal request from a business customer that a creditor stop all further contact regarding a specific debt. Under the Rosenthal Act for qualifying California commercial collections, this request must be honored upon receipt. After receiving a cease-communication request, the creditor is permitted to make only two types of contact: first, to confirm receipt of the request and that collection efforts are stopping, and second, to notify the customer of a specific legal action the creditor is actively taking, such as filing a lawsuit.

Ben Winter

CPO

Ben brings over a decade of go-to-market and operations expertise to building AR automation that actually works. He was VP Marketing at Fairmarkit (where he met Tarek) and GTM executive at Waldo before co-founding Stuut. He focuses on operations, product, and marketing—ensuring the platform integrates seamlessly with existing ERP systems and delivers results in days rather than months.

Frequently asked questions  about DSO

Is a higher or lower DSO better?
Lower is better because it means cash reaches your account faster. A DSO of 35 days is better than 55 days if your payment terms are the same.
Does DSO include current AR?
Yes. DSO reflects the total dollar amount you're owed from outstanding invoices, including invoices that aren't yet due.
How does bad debt affect DSO?
Writing off bad debt reduces your AR balance, which artificially lowers DSO even though no cash was collected. Ensure your AR figure is net of bad debt reserves for accurate measurement.
Should I calculate DSO monthly or annually?
Both. Annual DSO tracks long-term trends, while monthly DSO helps you spot process problems quickly and take corrective action before they compound.
What's the difference between DSO and CEI?
DSO measures collection speed in days. CEI measures collection quality as a percentage. A company can have low DSO but poor CEI if they're writing off accounts aggressively.
Can I reduce DSO without upsetting customers?
Yes. Proactive communication before due dates, helpful reminders, and fast dispute resolution improve customer experience while accelerating payment.

Related posts

Setup time to learn more