A Broker Consent Review Checklist to Run Before Open Enrollment
Test whether your team can retrieve the two distinct records behind an assisted Marketplace enrollment: consumer consent and confirmation of application information.
A consumer says an agent changed her Marketplace plan without permission. Your team can see the new plan in its transaction history, but the broker's CRM only says "consent on file." That note does not answer which action the consumer approved or whether the application information was reviewed with her before submission.
CMS Marketplace guidance treats consent for assistance and review of application information as separate records. It also discusses how to document changes submitted on a consumer's behalf [1][2]. A retrieval test should identify the record that supports each step of the sampled transaction.
The useful pre-season question is operational: Can you retrieve both records for a specific assisted transaction, in the form they were captured, and show which application or change they cover? This checklist turns that question into a sample test. Apply it to the federal-platform transactions in your book, and identify any state-run Marketplace requirements that also govern your organization [2].
Start With the Two Records
Consent authorizes assistance within a documented scope. Application review confirms that the consumer or authorized representative reviewed the accuracy of the information the agent will submit. One record does not automatically establish the other [1][2].
| Check | Review focus | Evidence to retrieve | Operational question |
|---|---|---|---|
| Consent | Identify the authorization associated with the assistance [1][2] | Original consent record, including scope, purpose, duration, date, consumer identity, named agent or agency, and rescission process [2] | Does this record cover the person and activity in the sampled transaction? |
| Application review | Find evidence of the consumer's review of application information [1][2] | Original review record with review date, consumer name, explanation of application attestations, and assisting agent or broker [2] | Can the reviewer match it to the information actually submitted? |
| Application change | Check the records associated with the change [2] | Applicable authorization, review record, and change history | Does the evidence cover this update, rather than only the original enrollment? |
| Retrieval | Test whether the source record can be exported | Storage location, retention setting, retrieval owner, and a successful sample export | Can the organization retrieve the record after a consumer or agent relationship ends? |
The consent record can take more than one form if it satisfies the governing requirements. CMS describes recordings, signed documents, and other maintainable records; its FAQ also describes acceptable ways to document application review [2]. Do not treat a CRM summary as the original record merely because it mentions a call. Preserve the recording, written response, or signed artifact that demonstrates what the consumer did and when.
CMS provides a model consent form that can help teams design their collection process [3]. Check the form against the current rule and the separate application-review requirement. If one workflow captures both, your reviewer still needs to identify the evidence for each obligation.
Run One Sample Pull Before the Season Starts
Select a small sample of assisted enrollments and application changes. Include at least one transaction handled by an agent who has since left, and one transaction where another agent in the agency handled a later update. This is a recommended quality-control sample, not a federal sample-size rule.
For each transaction:
- Record the Marketplace platform, plan year, transaction identifier, consumer or authorized representative, and agent or agency involved.
- Retrieve the original consent artifact and identify its scope, date, duration, named recipient, and rescission process [1][2].
- Retrieve the separate application-review evidence and compare its date and content with the information submitted [1][2].
- For an update, find the authorization and review record applicable to that update. An existing consent may still cover later assistance if its scope and duration allow it; check the actual record before demanding or assuming a new one [2].
- Record the storage location, retrieval owner, elapsed retrieval time, and any missing or mismatched evidence. Set an internal response target and check the applicable retention instructions in current CMS materials [1][2].
Use three clear dispositions: complete, documentation gap, and consumer-disputed activity. A missing consent or review artifact is a documentation gap. It does not, by itself, establish unauthorized activity. When the consumer disputes the transaction, preserve the original evidence and give a named reviewer the case. Do not let a late CRM note replace the underlying artifact.
Keep Form Versions Visible
A mixed book of business can include signed forms, audio records, agency-wide consent, and application updates. Label each sample with its plan year and document type. Ask whether the record fits the transaction and the applicable CMS instructions for that plan year [2][3][5]. Keep later form changes on a separate implementation track so reviewers can assess older transactions using the materials that applied when they occurred.
When a Consumer Disputes a Transaction
CMS has described steps to limit unauthorized agent and broker activity and directs consumers who suspect an unauthorized enrollment or plan switch to the Marketplace Call Center [4]. Give the consumer that route for coverage assistance while your organization preserves and reviews its own records.
An internal review can use this sequence:
| First question | Record to inspect | Next action |
|---|---|---|
| What action is disputed? | Enrollment and application-change history | Identify the exact transaction and timing. |
| Who performed it? | Agent or agency identity attached to the transaction | Confirm the responsible organization and reviewer. |
| What did the consumer authorize? | Original consent record and its scope | Record whether the action is within the documented authorization. |
| What application information did the consumer review? | Original review and confirmation record | Compare the record with the submitted application or update. |
| Is evidence absent or inconsistent? | Source artifacts and system timestamps | Log a documentation gap or route a disputed action for further human review. |
Avoid fixed fraud labels based on a single missing field. A missing recording may reflect a retrieval failure. A consumer's denial of contact, a plan switch outside the documented scope, or inconsistent source timestamps needs a deeper review. Preserve the records as received, record the reviewer's reasoning, and follow the applicable CMS and organizational escalation processes [2][4].
Questions Teams Ask
How long must these records be kept?
Check the current CMS Marketplace guidance for the transactions and plan years in scope [1][2]. Then test that the responsible storage system and export process support the applicable period even when an agent leaves.
Does a recorded call count?
It can, if the recording captures the required consent or review information and can be maintained and produced. An unrecorded verbal assertion alone does not establish the application-review documentation CMS describes [2].
Does an automatic renewal always require new consent?
CMS distinguishes an automatic renewal with no agent action from an agent-assisted change. Check what action occurred and the scope of existing consent before treating a renewal as a new assistance event [2].
Is the CMS model form mandatory now?
Review the CMS model form and the current instructions for the transaction's plan year [2][3][5]. Keep form versions and effective dates visible in training and system configuration.
What should we do first?
Pull one assisted enrollment and one application change from your own records. Use the table above to identify the two required artifacts, their owner, their source system, and any gap. Repeat with a wider sample once the retrieval path works. If a consumer disputes an action, direct them to the Marketplace Call Center for coverage help and route the preserved case to a named reviewer [4].
Detectory can help teams organize transaction histories, source artifacts, and review queues when the records are spread across systems. Start with the evidence map above; it tells you what the workflow must retrieve and what a human reviewer must decide.
References
[1] eCFR, 45 CFR 155.220, current text. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-B/part-155/subpart-C/section-155.220
[2] CMS, Frequently Asked Questions: Consumer Consent and Application Review Requirements. https://www.cms.gov/marketplace/agents-brokers/files/frequently-asked-questions-consumer-consent-application-review-requirements.pdf
[3] CMS, Model Consent Form for Marketplace Agents, Brokers, Web-brokers, and Agencies. https://www.cms.gov/marketplace/agents-brokers/files/cms-model-consent-form-marketplace-agents-brokers.pdf
[4] CMS, Statement on System Changes to Stop Unauthorized Agent and Broker Marketplace Activity. https://www.cms.gov/newsroom/press-releases/cms-statement-system-changes-stop-unauthorized-agent-broker-marketplace-activity
[5] Federal Register, May 20, 2026, Marketplace rule. https://www.govinfo.gov/content/pkg/FR-2026-05-20/pdf/2026-10050.pdf