The consent-to-represent requirement exists because some brokers' NPNs kept showing up on enrollments they never touched. CMS responded with 45 CFR 155.220(a)(3), which requires written consumer consent before a broker assists with a Marketplace enrollment. The rule has been on the books for years. The compliance gap is not lack of awareness; it is agencies that never built a documented intake workflow and are now one audit away from finding out.
Key Takeaways
- 45 CFR 155.220(a)(3) requires written consumer consent before a broker assists with Marketplace enrollment.
- The Marketplace CTR requirement is federal and separate from Medicare SOA. Satisfying one does not satisfy the other.
- Retention period: 10 years from the date of the consent, not from the end of the plan year.
- Broker NPN on an enrollment without a CTR on file is the primary audit trigger CMS uses in the FFM.
- Carrier agent-of-record systems and the federal CTR requirement are parallel tracks. Both are required.
What 45 CFR 155.220(a)(3) actually requires
The regulation requires that a licensed broker obtain written consent from a consumer before providing assistance with Marketplace plan selection, application, or enrollment. Written means documented and retainable, not just verbal. The consent must be on file before the assistance begins, not collected afterward as a cleanup step. The scope covers assistance on the Federally Facilitated Marketplace and mirrors similar obligations on state-based exchanges, though state rules vary in their specifics.
The retention period is 10 years from the date of consent. This is the number most agencies get wrong. Default CRM data retention often runs 5 to 7 years. An agency that migrated platforms in 2022 and purged the old system on a 5-year cycle may have no records for enrollments from 2017 to 2019, all of which are still within the 10-year window as of 2026. Set retention at implementation, not after the first audit inquiry.
CTR versus Medicare Scope of Appointment
Brokers who write both ACA and Medicare lines run into this distinction regularly. The Medicare Scope of Appointment, governed by CMS Medicare Marketing Guidelines under 42 CFR Part 422, is a pre-appointment form required before discussing Medicare Advantage and Part D products. The ACA Marketplace CTR is a separate requirement under 45 CFR 155.220. Neither satisfies the other.
An agency that uses one form for both lines has a compliance gap in at least one of them. The practical fix is a clear two-form workflow with distinct naming: one form labeled for Medicare appointments, one for Marketplace enrollment assistance. Both forms go into the client record, both are retained to their respective statutory periods, and the two are not interchangeable.
Carrier AOR versus Marketplace CTR
Agent-of-record designation at the carrier level establishes commission routing and links the broker NPN to the policy in the carrier's internal system. This is a commercial relationship between the broker and the carrier. The Marketplace CTR is a federal consumer protection document that governs the relationship between the broker and the consumer. They are parallel tracks. Being an AOR with Aetna or BCBS does not satisfy the federal CTR requirement, and the absence of an AOR with a carrier does not exempt a broker from needing a CTR.
In practice, quoting platforms like Quotit surface carrier AOR status as a workflow field without separately prompting for the federal CTR. The distinction matters during OEP when brokers are moving quickly. Both systems require their own documentation, on their own timeline, stored in their own records.
Common scenarios that create gaps
| Trigger | Risk | Correct action |
|---|---|---|
| Consumer calls, broker assists by phone, enrollment completed same day | No written consent before assistance. Verbal-only consent not documented. | Send electronic CTR form before or immediately after the call. Do not complete the enrollment until signed. |
| Renewal handled by agency staff, not the named broker of record | CTR was signed with the original broker. Staff-assisted renewal may not have a new or valid CTR. | Confirm whether the CTR scope covers renewals and assistance by agency staff. Re-obtain if the scope is narrow. |
| Broker switches agencies; client follows | CTR on file named the prior agency. New enrollment under new NPN has no CTR. | Obtain a new CTR under the new NPN before assisting with plan selection or enrollment in the new agency context. |
| High-volume OEP, CTR forms collected after enrollment to reduce friction | Consent was not obtained before assistance. Post-enrollment forms do not correct the sequence. | CTR must precede assistance. Build the form into the intake flow, not the follow-up workflow. |
What CMS looks for in an audit
The primary audit signal CMS uses in FFM broker oversight is a broker NPN appearing on enrollments at volume without corresponding consumer complaints or without CTR documentation on file. Both patterns raise the same question: did this broker actually assist these consumers? The second signal is consumer complaints that a broker was added to their enrollment without their knowledge, which is the scenario the CTR requirement was designed to prevent.
An agency running 500 enrollments per OEP with no documented CTR process is not operating at 500 times the risk of a single-broker shop with the same gap. It is operating at 500 times the visibility. Volume concentrates audit exposure because it makes the NPN pattern easier to identify in CMS data.
Building a compliant intake workflow
The minimal compliant workflow has three components: a CTR form that covers the consumer, the specific plan year, and the scope of assistance; a delivery mechanism that timestamps the consent before any enrollment assistance; and a storage path that retains the document for 10 years in a retrievable format. Electronic forms with a timestamp satisfy the first two. The storage question is where most agencies underinvest.
If the CTR lives only in a SaaS CRM, the retention policy of that SaaS product governs the record. Review the data retention terms before assuming a 10-year record is on file. Agency migrations, vendor shutdowns, and standard purge cycles all create gaps in records that otherwise looked complete.
Frequently asked questions
Common compliance questions from ACA brokers and agency principals about the consent-to-represent requirement.
What is the ACA broker consent-to-represent requirement?
The consent-to-represent requirement under 45 CFR 155.220(a)(3) obligates a licensed broker or agent to obtain written consent from a consumer before providing assistance with Marketplace plan selection, application, or enrollment. The consent must be documented and retained. It applies to individual and family market enrollment on the Federally Facilitated Marketplace and mirrors state-level rules on state-based exchanges. The federal rule is specific to Marketplace plans; it does not cover off-marketplace or employer-sponsored coverage under the same regulatory section.
Is the ACA consent-to-represent the same as a Medicare Scope of Appointment?
No. The Medicare Scope of Appointment is a CMS requirement under 42 CFR Part 422 and 423 governing Medicare Advantage and Part D plan sales appointments. The ACA Marketplace consent-to-represent is a separate requirement under 45 CFR 155.220. Brokers who work both Medicare and ACA lines need compliant documentation for each product line independently. Using a Medicare SOA form in place of an ACA CTR does not satisfy the Marketplace requirement. An agency compliance checklist should treat these as two separate workflows with two separate form types and two separate retention timelines.
How long must a broker keep the consent-to-represent documentation?
The federal Marketplace CTR retention requirement is 10 years. This is longer than many default CRM retention settings, which often default to 5 or 7 years. Agencies that migrate CRM platforms or purge records on a shorter cycle risk having no documentation to produce in the event of a CMS audit. The 10-year clock runs from the date of the signed consent, not from the end of the plan year or the end of the client relationship. Setting CRM retention to 10 years at initial configuration is the lowest-friction fix.
Does having agent-of-record status with a carrier satisfy the Marketplace CTR?
No. Carrier AOR designation is a carrier-side system that establishes commission routing and links the broker NPN to the policy for the carrier's internal records. The Marketplace CTR is a federal compliance document filed as part of the enrollment process on Healthcare.gov or the state Marketplace system. They operate in parallel. A broker can hold AOR status with a carrier and still lack a compliant CTR for the same enrollment. CMS audits the Marketplace enrollment record, not the carrier's commission system.
What happens if a broker's NPN appears on an enrollment without a consent-to-represent?
A broker NPN on an enrollment without a documented CTR is the most common audit trigger CMS uses when reviewing Marketplace enrollment activity. If CMS determines that a broker assisted with an enrollment without proper consent documentation, the consequences can include loss of Marketplace appointment, fines, and referral to the state insurance department for license review. The pattern CMS looks for is an NPN attached to high enrollment volumes with no corresponding consent documentation or with consumer complaints that the broker was not involved. Both scenarios surface the same regulatory exposure.
Can the consent-to-represent be obtained electronically?
Yes. CMS has accepted electronic consent to satisfy the 45 CFR 155.220(a)(3) requirement provided the record is retained in a retrievable format for the full 10-year period. Common approaches include a signed PDF via DocuSign or similar, a timestamped form submission through the agency's enrollment platform, or a recorded verbal consent in states that permit it with a corresponding written record. The key compliance question is not the format but the retention: the document must exist and be producible on demand. An electronic form that lives only in a SaaS CRM with a 5-year data limit does not satisfy the 10-year obligation.


