Most ACA agencies would not pass a CMS documentation audit today, not because they did anything wrong on enrollments, but because they have never assembled the files. A quoting tool like Quotit shows a broker which plan to recommend. A compliant agency file shows CMS that the broker had authorization to act, disclosed their compensation, and kept a record of what they did. The quoting tool does not generate that file. The broker does, or the agency does, or nobody does, and the audit finds out which.

Key Takeaways

  • 45 CFR 155.220 requires Marketplace-registered agents and brokers to maintain records of enrollment assistance and provide them to CMS on request. The regulation does not list a specific retention period, but CMS audit readiness guidance and HIPAA minimums together support a 10-year standard.
  • Annual Marketplace training certificate is not just a compliance checkbox. It is a precondition for FFM registration renewal. An agency that cannot produce training records for its agents is one audit away from losing its Marketplace registration.
  • Consumer written consent to enroll, required under 45 CFR 155.220(d), is the single most commonly missing document when agencies conduct internal file reviews.
  • Commission disclosure requirements vary by state. Federal rules and several state-level regulations require disclosure of compensation to consumers. The disclosure record belongs in the client file.
  • A complaint log with resolution notes is not a regulation-specified requirement in the same way training records are, but it is consistently requested in CMS compliance reviews and protects the agency if a consumer complaint escalates.

What CMS is actually looking for

Under , Marketplace-registered agents and brokers must maintain records sufficient to document their enrollment assistance activities and make those records available to CMS on request. The regulation does not specify a form or format, which gives agencies some flexibility. It does not give agencies permission to have no records.

CMS compliance reviews are not typically surprise inspections with a 24-hour document demand. They usually begin with a data request letter that gives the agency a period of weeks to produce records. Agencies that have organized documentation systems produce the records quickly and close the review. Agencies that have to reconstruct records from memory, email threads, and carrier portals take much longer and often discover gaps they cannot fill. For the timing of annual compliance tasks, see the ACA broker compliance calendar.

The 10-record checklist

#DocumentWhat it isRegulationRetention
1Annual Marketplace training certificateCompletion record from the FFM or SBM annual agent training course. Required to maintain active Marketplace registration for each plan year.45 CFR 155.220(d)(1); CMS annual registration requirementsKeep current year plus prior 3 years minimum. Some agencies retain all training history.
2Consumer written consent to enrollWritten or documented permission from the consumer authorizing the broker to submit a Marketplace application or enrollment on their behalf. This is the single most commonly missing document.45 CFR 155.220(d)(2) — brokers must obtain consumer consent before submitting applicationsKeep for the duration of the client relationship plus at least 6 years after the last activity. CMS audit standard recommends 10 years.
3Agent of Record designation recordDocumentation that a consumer has designated the broker as their AOR on a Marketplace or group enrollment. Relevant for commission disputes and for verifying the broker-client relationship.CMS FFM agent/broker standards; carrier-specific AOR processesDuration of the client relationship plus 6 years. Keep the original AOR submission record.
4Commission disclosureWritten disclosure to the consumer of the broker's compensation for the enrollment. Required by some states and good practice in all. The content, format, and trigger point vary by state.State insurance law varies. Several states require disclosure at or before point of sale. Check each state where the agency operates.6 to 10 years from the date of disclosure. Some state regulations specify longer periods.
5State insurance license (current copies for each state)Current license certificate for each state where the broker is actively writing business. The license number on a client file should correspond to a valid, current license.State department of insurance requirements. Varies by state; all states require licensure.Keep current license plus the prior two renewal cycles. License audit trails document that the broker was licensed at the time of each enrollment.
6CMS NPN registration confirmationDocumentation of the broker's National Producer Number and its registration with the Marketplace. The NPN must be active and registered for the broker to receive commissions on FFM enrollments.45 CFR 155.220; CMS Marketplace registration processKeep current registration plus prior registrations. Registration history may be relevant if a commission dispute involves a prior plan year.
7HIPAA privacy notice provided to clientDocumentation that the broker provided a Notice of Privacy Practices (NPP) to the client before collecting personal health information. Required for brokers who are covered entities or business associates under HIPAA.45 CFR 164.520 (HIPAA Privacy Rule — Notice of Privacy Practices)6 years from the date of creation or the date it was last in effect, whichever is later, per the HIPAA minimum.
8Enrollment application recordsDocumentation of what was submitted to Healthcare.gov or the state exchange on behalf of each client: the application data, the plan selected, and the effective date. This is the primary record of what the broker did.45 CFR 155.220 general record-keeping requirement for enrollment assistance10 years from enrollment date is the recommended standard for CMS audit readiness.
9Plan selection documentationNotes or records showing why a particular plan was recommended or selected, including the factors discussed (premium, network, deductible, APTC, CSR eligibility). Protects the agency if a client later claims the plan was inappropriate.Not explicitly required by CMS rule but expected in compliance reviews and essential for E&O defenseKeep as long as the enrollment application record, minimum 6 to 10 years.
10Complaint log with resolution recordsA running log of consumer complaints received by the agency, the nature of each complaint, and how it was resolved. CMS may request this during audits to assess the agency's consumer protection practices.Not a codified regulation in 45 CFR 155 but consistently requested in CMS compliance reviewsMinimum 6 years. Complaints involving potential fraud or regulatory referrals should be kept longer.

Where most agencies have gaps

Consumer consent records are the most common gap. Many brokers verbally confirm with a client that they are authorized to help, submit the enrollment, and move on. There is no written record that the consumer authorized the broker to act. If a consumer later claims they did not authorize the enrollment, the broker has no documentation to the contrary. Under 45 CFR 155.220(d)(2), the consent is not optional.

The second most common gap is commission disclosure records. Several states require written disclosure of broker compensation at or before the point of sale. Most brokers know the requirement exists. Fewer have a system for retaining the disclosure record as part of the client file rather than just having a disclosure conversation.

Plan selection documentation is the gap that matters most in errors-and-omissions claims, not in CMS audits. A client who enrolls in a Bronze plan in January and then has a major health event in March may later claim the broker put them in the wrong plan. Notes in the client file showing what factors were discussed, what the client said their preferences were, and why the Bronze plan was selected are the only defense the agency has. For the commission disclosure requirements specifically, read how ACA broker commissions work.

How to run a self-audit

Pull 10 client files at random, ideally from across the past three plan years. For each file, check whether all 10 record categories are present and whether the records are dated contemporaneously with the enrollment. A consent form backdated to last week for an enrollment from two years ago is not a compliant consent form.

The gaps the self-audit finds are solvable if discovered during a quarterly file review. Some can be corrected prospectively (add a complaint log going forward, start retaining disclosure records). Others cannot be reconstructed after the fact (a consent record from a 2022 enrollment that was not documented at the time will never exist). The value of the self-audit is knowing which problems are fixable and which are exposures the agency has to manage going forward.

Agencies with 50 or more agents should also verify that annual training completion records exist for every agent, not just the ones who did enrollments during OEP. An agent whose training lapsed in October and who wrote 30 enrollments during AEP without a valid certificate is a compliance problem for the agency principal, not just for the individual agent.

FAQ

Common compliance questions from agency owners and principals about CMS documentation requirements.

How long must ACA brokers retain client enrollment records?

The ACA regulations at 45 CFR 155.220 require Marketplace-registered agents and brokers to maintain records of enrollment assistance and make them available to CMS on request, but do not specify an exact retention period in the regulation text. HIPAA establishes a minimum six-year retention period for privacy-related records under 45 CFR 164.530(j). CMS audit readiness guidance and agency compliance best practices generally support a 10-year standard for all enrollment-related documentation. Agencies with operations in multiple states should also check state-level record retention requirements, which may be longer.

What triggers a CMS audit of an agent or broker?

CMS can conduct proactive compliance reviews of any Marketplace-registered agent or broker without a specific trigger. Audits are also initiated following consumer complaints, reports from state insurance departments, carrier-identified irregularities in enrollment patterns, or OIG referrals. Agents with unusually high volumes of SEP enrollments, a pattern of commission disputes, or consumer complaint records at CMS are more likely to be selected for review. The best preparation is documentation that can be produced quickly and in good order.

Does a quoting platform like Quotit satisfy the documentation requirements?

No. Quoting platforms are designed to generate plan comparisons and facilitate enrollment submissions. They do not generate or store the consumer consent records, privacy notices, commission disclosures, or complaint logs that CMS may request in a compliance review. An agency that uses Quotit or similar tools for quoting still needs a separate documentation system for compliance records. Many agencies maintain a client file in a CRM or document management system that holds all required records alongside the quoting and enrollment history.

Is annual Marketplace training really required for every agent?

Yes. CMS requires each agent who wants to register with the FFM and facilitate Marketplace enrollments to complete annual training and certification. The training must be completed for each plan year. An agent whose training has lapsed is not eligible to receive commissions on FFM enrollments for that plan year and may have their Marketplace registration suspended. Agency principals should verify training completion for every registered agent before the start of each AEP, not after.

What should a consumer consent record include?

The consent record should document that the consumer authorized the broker to submit an enrollment application or make changes on their behalf. At minimum, it should include the consumer's name, the date of the consent, the scope of what the broker is authorized to do, and a signature or equivalent electronic confirmation. For phone enrollments, a recorded verbal consent with a contemporaneous log entry is acceptable. The consent record should be created at the time of the interaction, not reconstructed later.

This is editorial content. Not insurance advice. Verify regulations and figures with primary sources before relying. See our Privacy Policy.

Copyright QualityQuotes 2026

 

QualityQuotes is a software tool. It does not provide insurance advice. Coverage decisions rest with the broker and the consumer.