Sign in Start free trial
Industry Focus

How Brands Document Compliance Decisions: FDA & FTC Playbook

Woman reviewing FDA and FTC compliance documents

Every marketing asset at a telehealth or DTC health brand needs a decision record capturing the exact claim text, asset ID, channels, reviewer name and role, timestamp, action taken (approve/edit/block), justification, and evidence links — because both the FTC’s substantiation doctrine and FDA’s risk-disclosure rules treat the absence of pre-launch documentation as evidence of bad faith. Scancompliant is built specifically to automate that capture and produce export-ready audit logs.

Start here:

  • Adopt one decision record template across every channel and campaign — inconsistency is the first thing regulators notice.
  • Require a pre-launch compliance gate: no asset moves to media buying until required fields and evidence links are complete.
  • Attach evidence links to every health claim before publication, not after a complaint arrives.
  • Log every edit, not just final approvals — the version history is often what resolves a platform appeal.

The legal stakes are real. The FTC requires advertisers to possess a reasonable basis before disseminating claims, and post-claim evidence is discretionary, not a reliable defense. FDA applies parallel requirements for prescription drug and device promotion. Both agencies coordinate on overlapping violations.


Table of Contents

What fields does every compliance decision record need?

A complete record does two jobs: it proves the decision was made deliberately, and it gives a regulator or platform reviewer enough context to evaluate it without asking follow-up questions. Every record should capture:

  • Claim text: the exact ad copy, word for word, including implied claims
  • Asset ID and URL: a unique identifier tied to the creative file or page
  • Channel(s) and campaign ID: where the asset ran and under which campaign
  • Creative version: version number or hash so reviewers can distinguish drafts
  • Publication date and expiration date
  • Named reviewer(s) and roles: not just a team name — a specific person with a title
  • Decision: approve, approve with edits, or block
  • Timestamp: date and time of the decision, not just the date
  • Explicit justification: a sentence or two tying the decision to the evidence, not a checkbox
  • Evidence links: specific studies, labeling excerpts, or FDA/FTC guidance pages
  • Keywords flagged: risk terms identified during pre-launch scan
  • Platform-specific risk notes: any channel-specific policy flags
  • Next review date: when this asset or claim should be re-evaluated

Practitioner guidance consistently identifies the compliance log as the primary artifact when responding to platform flags and regulator inquiries. Boards and investors also request it: industry experts advise maintaining a unified substantiation file linking every claim to its underlying evidence as a standard risk-management practice during diligence.

Fields like reviewer name, timestamp, and justification are mandatory. Fields like campaign ID and expiration date can be optional for evergreen content but should default to required for paid media. Enforce mandatory fields at the workflow level — if the field is empty, the asset cannot advance.

Infographic showing essential compliance record fields


What evidence actually meets FTC and FDA standards for health claims?

The answer depends on the claim class. A general wellness statement (“supports healthy sleep”) requires a reasonable basis — meaning credible evidence a qualified expert would find sufficient. A claim that a product treats, cures, or prevents a specific condition requires competent and reliable scientific evidence: randomized, well-controlled, double-blinded clinical trials where that standard is scientifically appropriate.

FDA adds a separate layer for prescription drugs and devices. Naming a drug or describing its effects in an ad triggers FDA advertising rules, including the requirement to present risk information in a clear, conspicuous, and neutral manner. A help-seeking ad that avoids naming a specific drug does not trigger the same obligations — which is why the help-seeking vs. product-claim distinction matters so much for short-form video and social creative.

Evidence summary template — attach one row per study to every decision record for a health claim:

Field What to capture
Study citation Author, title, journal, year, DOI or URL
Population Sample size, demographics, inclusion criteria
Endpoints Primary and secondary outcomes measured
Results Quantitative outcome tied to the claim
Limitations Funding source, sample size, generalizability
Relevance to claim One sentence linking the finding to the specific ad copy
Supporting excerpt Direct quote from the study abstract or conclusion

How does the pre-launch compliance workflow actually run?

The compliance gate belongs to legal or regulatory, not media buying. Media buyers optimize performance, not regulatory risk — and that structural conflict is where most documentation failures start.

  1. Compliance reviewer sign-off: — a named reviewer evaluates the claim against FTC substantiation standards and, where applicable, FDA risk-disclosure requirements, then records the decision and justification.
  2. Platform-specific check: a separate review against channel policies (Meta, Google, TikTok) with any platform-specific risk notes logged. For email, channel-specific compliance requirements add another layer.

Roles: compliance or legal owns triage and sign-off on high-risk claims. Marketing owns draft submission and evidence gathering. Escalate to external counsel when a claim involves a named prescription drug, a device indication, or a prior warning letter category. One person owns the audit export — typically the compliance lead.

For tooling, a compliance documentation system should serve as the single source of truth: timestamped version control, integration with your marketing asset management (MAM) platform, and automated scanning to catch risk terms before human review begins.

Hands collaborating on pre-launch compliance checklist

Pro Tip: Set a hard stop in your workflow tool so that any record missing required fields or evidence links cannot be submitted for sign-off. A missing evidence link is not a minor oversight — it is the gap regulators exploit.


Ready-to-use decision record template and two examples

Use this template for every marketing asset that makes or implies a health claim.

Field Description Required? Example
Asset ID Unique creative identifier Yes AD-2026
Claim text Exact copy, including implied claims Yes “Clinically proven to reduce A1C”
Channels All distribution channels Yes Meta, Google Display
Campaign ID Campaign or flight identifier Yes CAMP-Q2-2026
Creative version Version number Yes v3
Reviewer name and role Full name and title Yes Jane Smith, Regulatory Counsel
Decision Approve / approve with edits / block Yes Approve with edits
Timestamp Date and time of decision Yes April 2026
Justification Rationale tied to evidence Yes Claim supported by RCT (Smith et al.)
Evidence links URLs or file references Yes doi.org/example
Keywords flagged Risk terms identified in scan Yes “clinically proven,” “reduces A1C”
Platform risk notes Channel-specific flags Optional Meta: add risk disclaimer
Next review date Scheduled re-evaluation Yes July 2026

Example A — Approved help-seeking ad: A social ad reads “Struggling with weight? Talk to a licensed provider today.” No drug is named. Reviewer: Sarah Lee, Compliance Manager. Decision: Approved. Justification: Help-seeking format; no product claim; no drug named; no FDA risk-disclosure obligation triggered. Evidence: N/A (no efficacy claim). Keywords flagged: none. Next review: 90 days.

Example B — Flagged and edited product claim: Original copy: “Our GLP-1 program melts fat fast.” Flagged terms: “melts fat,” “fast.” Reviewer: David Kim, Regulatory Director. Decision: Approve with edits. Before: “Our GLP-1 program melts fat fast.” After: “Our GLP-1 program supports medically supervised weight management.” Justification: Original copy made an implied efficacy claim without substantiation and named a drug class, triggering FDA risk-disclosure review. Edited copy is help-seeking in character. Evidence attached: FDA help-seeking ad guidance excerpt.

Export packet: when producing records for a regulator or platform, include the completed decision record, all evidence summary rows, reviewer identities with timestamps, version history showing before/after copy, platform submission confirmations, and any post-publish monitoring logs.


How long should you retain compliance records?

Retain decision records and substantiation files for a minimum of five years from the last date the asset ran — longer if the claim category has active enforcement history or if the brand has received a warning letter. Immutable logs with timestamps are non-negotiable: a log that can be edited after the fact has no evidentiary value.

For legal-hold situations:

  • Flag preserved records immediately when litigation, a regulator inquiry, or a platform dispute is reasonably anticipated.
  • Restrict deletion permissions on flagged records and log every access attempt for chain-of-custody purposes.
  • Notify the compliance lead and legal counsel before any record in a hold set is modified or exported.

Audit packet checklist:

  • Completed decision record for each asset
  • Evidence summary rows with source links
  • Reviewer identities, roles, and timestamps
  • Version history showing all edits and the before/after copy
  • Platform submission confirmations and any rejection notices
  • Post-publish monitoring logs and incident notes
  • Legal-hold flag status and access log

On sensitive data: redact proprietary study data and personally identifiable information before producing records externally, and consult legal counsel before sharing unpublished clinical data with a regulator. Scancompliant’s security and data practices are relevant here for teams storing substantiation files on the platform.


What does a quarterly compliance review actually cover?

Run a formal compliance review every quarter. Industry guidance confirms that enforcement priorities and platform policies shift frequently enough that a strategy compliant three months ago may not be compliant today.

Track these KPIs between reviews: ad rejection rate by channel, average time-to-approval, number of high-risk edits per quarter, and number of regulator or platform inquiries received.

Quarterly agenda:

  1. Policy update review: — check for new FDA guidance, FTC enforcement actions, and platform policy changes since the last review.
  2. Sample audit: pull a random sample of recent approvals and verify that required fields, evidence links, and reviewer sign-offs are complete. A structured audit checklist keeps this consistent.

Triggers for an ad-hoc review outside the quarterly cycle: an FDA warning letter in your product category, a platform policy change affecting your primary channel, a new product launch, a spike in ad rejections, or any incoming regulator inquiry.

Pro Tip: Assign one person to monitor FDA and FTC enforcement feeds weekly. A warning letter in your category is a leading indicator — not a lagging one — of where scrutiny is heading.


Key Takeaways

Reliable compliance documentation requires a named reviewer, a timestamped decision, attached evidence links, and a versioned audit trail on every marketing asset — captured before launch, not after a complaint.

Point Details
Mandatory record fields Every record needs claim text, asset ID, named reviewer, timestamp, decision, justification, and evidence links.
Evidence standard FTC requires competent and reliable scientific evidence for efficacy claims; attach an evidence summary to every health claim record.
Pre-launch gate Compliance sign-off must happen before media buying — missing fields should block submission entirely.
Quarterly review cadence Review policy changes, audit recent approvals, and refresh training every quarter; act immediately on warning letters or platform policy shifts.
Scancompliant Automates pre-launch scanning across 1,000+ risk terms, enforces required record fields, and produces export-ready audit logs for regulator inquiries.

The documentation mistake that keeps showing up

The most common failure in compliance documentation is not a missing field — it is a missing mindset. Teams treat the record as a formality after the real decision has already been made informally in a Slack thread or a creative brief. By the time the formal record is filled out, the evidence link is an afterthought and the justification is a generic sentence that could apply to any asset.

That gap is exactly what regulators look for. An FTC investigator reviewing your substantiation file is not checking whether you have a record — they are checking whether the record was created before the claim ran and whether the evidence actually supports the specific language used.

A few patterns that compound the problem: implied claims left undocumented (a before/after image that implies efficacy without stating it), vague claim descriptions that do not capture the exact copy reviewed, and reviewer roles listed as “marketing team” instead of a named individual. Each of these erodes the record’s value in an appeal or inquiry.

The corrective is structural, not motivational. Enforce mandatory fields at the workflow level. Require a named reviewer, not a team. Make the evidence summary a required attachment, not a suggested one. And run healthcare marketing compliance training that shows reviewers what a complete record looks like — not just what fields to fill in.


Scancompliant gives your team audit-ready documentation from day one

Most telehealth and DTC health teams spend more time reconstructing compliance records after a platform flag than it would have taken to capture them correctly the first time. Scancompliant eliminates that reconstruction problem.

Scancompliant

The platform scans websites, social media, documents, and product listings against a library of over 1,000 risk terms, flags explicit and implied claims, and generates a prioritized findings report in minutes. Every scan produces a timestamped, immutable log that maps directly to the decision record fields covered in this article: flagged terms, reviewer sign-off, evidence links, and version history. For high-risk categories like GLP-1 weight management, the GLP-1 compliance scanner applies the specific FDA and FTC rulesets that apply to compounded and branded drug promotion.

The result is an export-ready audit packet your legal team can produce for a regulator inquiry or platform appeal without manual assembly. Over 200 brands have used Scancompliant to shorten review cycles and build the documented compliance trail that boards, investors, and regulators expect.

Start a free trial at Scancompliant and run your first scan today.


Useful sources

  • FTC Health Products Compliance Guidance — the primary reference for substantiation standards and the “competent and reliable scientific evidence” requirement for health claims.
  • FTC Policy Statement Regarding Advertising Substantiation — establishes the prior-substantiation doctrine and explains when post-claim evidence may be considered.
  • FTC Notice of Penalty Offenses Concerning Substantiation of Product Claims — formal notice of what constitutes an unfair or deceptive act under Section 5(a)(1) of the FTC Act.
  • FDA Presenting Quantitative Efficacy and Risk Information in DTC Promotional Labeling and Advertisements — FDA guidance on how to present benefit and risk data in DTC ads for prescription drugs.
  • FDA Direct-to-Consumer Prescription Drug Advertisements: Major Statement Final Rule — the final rule requiring clear, conspicuous, and neutral presentation of the major statement in TV and radio DTC ads.
  • Telehealth Compliance Review Process — practitioner guidance on building a compliance log and quarterly review cadence for telehealth ad creative.
  • FDA Rules for Telehealth Advertising — explains when naming a drug triggers FDA advertising obligations and how help-seeking ads differ.
  • FTC vs. FDA: The Marketing Rules Every Telehealth CEO Must Follow — covers the unified substantiation file requirement and investor/board expectations for compliance documentation.
  • Scancompliant — Marketing Compliance Made Simple — platform overview covering scanning, templated decision records, and audit-log features.

This article provides general information about U.S. compliance documentation practices and does not constitute legal advice. Confirm current FDA and FTC requirements with primary sources or qualified legal counsel before making compliance decisions.

S

ScanCompliant Team

← Previous
Why Health Writing Carries Legal Risk for DTC Brands
Next →
FDA Compliance for DTC Ecommerce: A Marketing Team Playbook

1 Comment

Leave a Comment

Your email address will not be published. Required fields are marked *