Playbook

Why Your Insurance Agency's Review Funnel Could Get Fined

The CRM feature that quietly filters unhappy customers away from Google is now a federal problem, not just a Google one.

Mike Moore, founder of Strategic AI Architects, looking at a phone showing a post-policy review request text with a five-star rating scale, representing an insurance agency's automated review funnel
The short version

Asking "how did we do" before asking for a public review is common. Using the answer to decide who gets asked is the problem. The FTC's Rule on the Use of Consumer Reviews and Testimonials, effective October 21, 2024, bans displaying reviews in a way that misrepresents them as complete when negative ones were filtered out first1, and Google's own Business Profile policy separately bans "selectively solicit[ing] positive reviews from customers"6. The default reputation-management template built into the CRM most agencies already run routes exactly that way: four and five stars go public, one through three go to a private form7.

The text after every closed policy

A client renews, or a new policy binds, and a few hours later a text goes out. "How was your experience with us today?" with a row of five stars underneath. It reads like customer service, because in your CRM's marketing copy, that's exactly what it's sold as. Someone on your team, or a marketing vendor who set the workflow up for you, turned this on months ago and never thought about it again. It runs quietly in the background of every policy you write.

Here's what happens next, and it's the part almost nobody who turned the workflow on has actually traced through. A four or five star tap sends the client straight to a link that opens your Google Business Profile's review box, pre-loaded and ready to submit. A one, two, or three star tap sends them somewhere else entirely: a private form that lands in your inbox or your CRM's task list, with no public review ever requested. The client who loved you gets asked to tell Google. The client who didn't gets asked to tell you, privately, and nobody else.

That split feels like good triage. You catch problems before they become public, and you don't waste a five-star opportunity on a customer who might type something middling. It is also, named specifically and separately by two different regulators in the last two years, exactly the behavior they built new rules to stop.

Ask most agency owners why the workflow is built this way and the honest answer is "I didn't build it, it came with the template." That's true, and it's also part of why this is worth taking seriously rather than dismissing as something only a bad actor would do on purpose. The template exists because review-management software is sold and reviewed on the star rating it produces. A vendor demoing "how we get agencies to a 4.9" has every incentive to ship the sentiment branch turned on by default, because a workflow that asks everyone the same way, unhappy customers included, produces a lower average score in the demo. Nobody at that vendor is thinking about 16 CFR Part 465. They're thinking about the number on the slide.

This isn't about deleting or hiding a bad review

Removing a review that's already public, or pressuring someone to take one down, is a different and older problem the FTC's rule also covers3. What this guide is about is upstream of that: deciding, before a review is ever written, who even gets invited to write a public one in the first place.

How the star filter actually works

It's worth being concrete about the mechanism, because "review gating" sounds like something a disreputable operator does on purpose, and that's not the typical case in this industry. The typical case is a CRM template. GoHighLevel, the marketing and CRM platform woven through most of the automation an independent agency runs today, ships a reputation-management workflow that marketing partners describe the same way across their own documentation: an automated text or email asks the customer to rate their experience from one to five stars, a four or five star response is prompted to leave a public review with a direct link to Google or Facebook, and a one, two, or three star response is routed to an internal feedback form that notifies the business owner privately7. It's a genuinely useful piece of customer service software. It is also, without any further configuration, a sentiment-based gate sitting in front of every public review your agency ever collects.

Nobody has to configure this to happen. It's the shipped default in the template most agencies copy from a marketing vendor, a fellow agent, or a downline's shared snapshot. The person who set it up almost certainly never read the FTC's final rule, because it wasn't written for insurance agents specifically and nobody flagged it as relevant to a CRM feature. It was written for exactly this pattern, at any business, in any industry, using any software.

The sentiment question

A one to five star tap, asked before any public review platform is mentioned.

The high branch

Four or five stars trigger a pre-filled link straight into your Google review box.

The low branch

One to three stars trigger a private form that never mentions a public review at all.

The displayed set

Your public profile shows only the reviews that survived the first branch.

The implication

A visitor reading your profile has no way to know a filter ran before they saw it.

The shipped default

Most agencies never built this. They inherited it from a template.

Two different rules, same behavior

What makes this worth a whole guide, rather than a one-line warning, is that this specific pattern got named twice, by two different authorities, on two different legal footings, within about eighteen months of each other. Google tightened its own Business Profile content policy to explicitly bar businesses that "discourage or prohibit negative reviews, or selectively solicit positive reviews from customers," under a section it calls rating and review manipulation6. Separately, and on a completely different legal basis, the FTC finalized a federal trade regulation rule that treats a specific version of the same conduct as an unfair or deceptive act or practice, enforceable with civil penalties1.

Neither authority is reacting to the other. Google's rule is a platform content policy, enforced by removing reviews or suspending the profile. The FTC's rule is federal law, enforced by the federal government itself. That two separate systems landed on the same underlying behavior, within roughly the same window, is a signal worth taking seriously even before you get to the dollar figures.

What the FTC's rule actually requires

The Rule on the Use of Consumer Reviews and Testimonials is codified at 16 CFR Part 465 and took effect October 21, 20242. It doesn't ban having a customer feedback process, and it doesn't require you to publish every complaint verbatim. It bans a narrower, specific set of practices, three of which apply directly to a typical agency's review pipeline.

The three FTC provisions a typical agency review workflow touches, 16 CFR Part 465, effective October 21, 20242
Section What it bans Where an agency touches it
465.2, fake reviews Writing, buying, or posting a review that misrepresents whether the reviewer exists or had the experience described3 Any staff-written "customer" review, or a review purchased from a third party
465.5, insider reviews An officer, manager, employee, or immediate relative posting a review without disclosing the relationship4 A producer or a spouse leaving a review for the agency without saying who they are
465.7(b), review suppression Displaying reviews in a way that misrepresents them as most or all of what was submitted, when reviews were actually suppressed based on rating or sentiment5 A public review page built entirely from a sentiment-filtered request funnel

The third row is the one this guide is actually about. Section 465.7 doesn't say a business can never triage negative feedback privately. It says a business cannot let its public review display imply completeness while quietly routing negative sentiment away from ever reaching that display5. A four and a half star Google profile built by a workflow that never gave a one-star customer the chance to post publicly is, under this section, presenting a number that misrepresents what customers as a whole actually reported.

The rule does carve out legitimate reasons to keep a review off a public page: content with someone else's private information, harassment or obscenity, discrimination, reviews unrelated to the product or service, and reviews reasonably believed to be fake5. Predicting a low star rating before it's even written and routing that customer away from the public option is not on that list.

The part worth sitting with. This rule doesn't require you to publish every angry message you've ever received. It requires that the decision about who gets invited to post publicly can't be made before you know what they were going to say. That's a genuinely different standard than most agencies think they're operating under.

What Google already banned on top of it

Google's own policy for Business Profiles addresses the same conduct from a different angle, and it's worth reading because it's the one enforced against your actual listing, not just in the abstract. Under its prohibited and restricted content guidelines, in the section on rating and review manipulation, Google states that businesses may not "discourage or prohibit negative reviews, or selectively solicit positive reviews from customers"6. The same policy separately prohibits pressuring customers to leave reviews while still on your premises and prohibits incentivizing a review with a discount, gift, or other benefit6.

Google updated and clarified this guidance again in early 2026, adding explicit language against a handful of adjacent tactics, review kiosks or shared devices set up in-office to capture reviews on the spot, and requests that a customer name a specific staff member in their review text9. None of that is new in spirit. It's the same underlying concern, that the displayed review set should reflect actual, unmanipulated customer sentiment, applied to a wider set of specific tactics than the original policy language covered.

Google's enforcement mechanism is different from the FTC's, and arguably faster. There's no hearing, no civil penalty calculation, and no court involved. Google's own guidance states plainly that a profile that doesn't follow the rules can be suspended, removing it from both Search and Maps entirely8, and separately, gated reviews that Google's detection systems flag can simply be removed from the profile, individually, without warning. You don't get a letter first. You find out when the review count on your profile drops, or when the profile itself stops showing up.

Two authorities, the same underlying behavior, different enforcement
Authority What triggers it Enforcement
Google Business Profile policy Selective solicitation detected by Google's review systems6 Review removal, or profile suspension from Search and Maps8
FTC, 16 CFR 465.7(b) Public display that misrepresents suppressed reviews as complete5 Civil penalty up to $53,088 per violation, FTC-initiated10

What a violation actually costs

Start with the number, because it's the one that gets attention and it deserves the context that usually goes missing when it's quoted. The FTC's maximum civil penalty for violations tied to Sections 5(l), 5(m)(1)(A), and 5(m)(1)(B) of the FTC Act, which is the enforcement mechanism behind a Reviews Rule violation, was set at $53,088 per violation in the Commission's most recent inflation adjustment, effective January 17, 202510. Legal analysis of the rule's enforcement structure notes that violations under Section 5(m) can be counted per day, meaning a review-request workflow left running non-compliant for weeks doesn't necessarily count as one violation11.

The honest caveat belongs right here, not buried in the FAQ. This penalty is enforced by the FTC itself, not by a customer filing a private lawsuit, and the Commission's actual enforcement priorities to date have leaned toward larger, more visible operators rather than a single-office independent agency. That's a meaningfully different risk profile than a state text-messaging statute that hands the claim directly to whoever received the text. What doesn't change is that the rule applies to every business that solicits reviews, with no size exemption written into it2, and the FTC has shown it will use the fake-review and insider-review provisions against specific companies since the rule took effect.

Oct 21, 2024

Date the FTC's Reviews and Testimonials Rule took effect2

$53,088

Maximum civil penalty per violation, set January 202510

78%

Of consumers were asked to leave a review in the past 12 months12

97%

Of consumers read reviews before choosing a local business12

Stat card titled Review Compliance, By the Numbers, with four figures: October 21, 2024, the date the FTC's Rule on the Use of Consumer Reviews and Testimonials took effect; $53,088, the maximum FTC civil penalty per violation set in January 2025; 78 percent of consumers were asked to leave a review in the past 12 months; 97 percent of consumers read reviews before choosing a local business. Sources noted as FTC.gov and BrightLocal Local Consumer Review Survey 2026

There's a second cost that has nothing to do with either regulator, and it's worth naming because it applies whether or not the rule ever gets enforced against anyone in this industry. BrightLocal's 2026 Local Consumer Review Survey, a representative panel of 1,002 US adults fielded and published in February 2026, found that 78% of consumers were asked to leave a review in the past 12 months, and 65% of the people asked actually wrote one12. Every customer your workflow quietly routes away from that ask, because their sentiment score came back low, is a customer who was statistically likely to have left a review if asked, and who never got the chance. A filtered review set isn't just a compliance exposure. It's fewer total reviews than an unfiltered process would have produced, from the same book of business.

Why the next eight weeks matter more than the rest of the year

The Medicare Annual Enrollment Period runs October 15 through December 7 every year, per CMS's own published enrollment calendar14. If your book carries any Medicare Advantage or Part D business at all, this eight-week window is where a disproportionate share of your year's policy closings, renewals, and plan changes land in a compressed stretch, and it's exactly the volume that feeds a review-request workflow. An agency that sends a review request after every closed enrollment is about to run more of them in the next two months than in the previous six combined.

That compression cuts both ways. A gated workflow filtering out a chunk of that volume before it ever reaches your public profile means the busiest, most representative stretch of your entire year never shows up in what a prospect sees when they search your name in November. And if Google's detection systems flag the pattern during exactly the season your call volume and your review request volume both spike, a suspended profile costs you visibility at the one time of year it's hardest to absorb the loss. Fixing the workflow in September, before AEP volume hits, is a genuinely different position than discovering the problem in the middle of it.

A five-minute check before October 15

Pull up the review-request automation in whatever CRM handles your post-enrollment texts and trace it end to end, the same way you'd want a downline agent to trace theirs. If it exists and runs unmodified through AEP, every enrollment your team closes this fall feeds it. If you'd rather have this and your broader AI citation readiness checked at once, run a free Audit before your November call volume peaks.

Why turning off the filter isn't the whole fix

The instinct, once you see the mechanism, is to go find the workflow in your CRM and delete the branch. That helps, and you should do it. It's not the complete fix, for two reasons that are easy to miss.

First, the FTC's rule is about what's displayed, not only about how it got collected5. If your Google profile already shows a set of reviews built by months or years of a gated workflow, turning the workflow off today doesn't retroactively make that existing, filtered public set representative. The exposure sits in the display as it exists right now, not only in the process still generating new reviews.

Second, a lot of agencies run this exact workflow through more than one channel at once, a CRM automation, a separate review-management app a downline or FMO provided, and sometimes a front-desk habit of only handing the Google review card to customers who seemed happy at pickup. Fixing the CRM workflow and leaving the paper card habit in place solves a third of the actual problem while making everyone feel like it's handled.

Here's a worked example, using hypothetical, round numbers to make the mechanism concrete rather than to represent any real agency's book. Say your agency closes 40 policies in a typical month and a review request goes out after each one. If the CRM's sentiment gate quietly diverts a quarter of those responses to the private form before a Google review is ever offered, roughly 10 customers a month who would have been asked publicly never are. Run that same math against an eight-week AEP surge where enrollment volume triples, and the number of customers routed away from a public review in that window alone can exceed what a smaller agency would otherwise collect across several ordinary months. The filter doesn't feel dramatic day to day. Compounded across a season, it reshapes what your entire public review set looks like.

The mistake we see most

An agency owner finds the sentiment branch, deletes it, and considers the issue closed. Six months later the public review set is still the same filtered set it always was, because nobody went back and thought about whether the existing reviews needed anything, and nobody checked the second and third places the same routing habit was quietly running.

What a compliant review request looks like

None of this requires abandoning review requests, and it doesn't require a compliance officer. Here's the actual checklist, and every item on it is something you can implement yourself this week on whatever CRM you already run.

  1. Ask every customer the same way, with no branch. One message, one link, straight to your Google review box, sent to every customer who closes a policy or completes a service interaction. No sentiment question sits in front of the ask.
  2. Move service recovery to a separate channel entirely. If you want to catch problems early, do it through an unrelated touchpoint, a satisfaction call, a check-in email that has nothing to do with review requests, so the recovery process and the review request never share a decision point.
  3. If you keep a single combined message, don't let the answer gate the ask. You can still ask "how did we do" and separately invite a public review in the same message, as long as every recipient sees the review invitation regardless of what they answer.
  4. Respond to negative reviews publicly instead of trying to prevent them. A professional, factual public response to a bad review is not suppression under either rule, and BrightLocal's own research is a reminder of why it matters anyway: most shoppers are reading the reviews you already have, not waiting for a perfect set12.
  5. Disclose any insider review. If a producer, an employee, or a family member posts a review for the agency, the post needs a clear, visible statement of the relationship, not a vague first name and no context4.
  6. Never offer an incentive tied to a positive outcome. A discount or gift for leaving "a good review" specifically, rather than a review generally, sits on the banned list under both the FTC's rule and Google's own policy26.
  7. Audit whatever review software you already run, not just your CRM. Ask directly whether the tool routes based on predicted rating before a review is submitted. If the vendor can't answer clearly, that's an answer.
Flowchart titled Is Your Agency's Review Request Compliant. Step 1: Does every customer who completes a policy get the same review invitation, with no sentiment question first. If yes, proceed to step 2. If no, the workflow is routing based on predicted rating, which is the exact conduct the FTC's review suppression rule and Google's selective solicitation policy both prohibit. Step 2: Is any service recovery step kept completely separate from the decision to send a public review invitation. If yes, the funnel is compliant. If no, the recovery step is functioning as a gate. Step 3: Are insider reviews from staff or family disclosed, and is no incentive tied to a positive review specifically. If yes on both, the review program clears all three FTC provisions covered in this guide: fake reviews, insider disclosure, and review suppression. Source noted as FTC 16 CFR Part 465 and Google Business Profile policy, verified September 2026

Worth checking this week

Open the review-request workflow in your own CRM right now and trace what happens after each possible star rating. If you find a branch, you've found the exact conduct this guide covers, and you can fix it today without waiting on anyone. If you'd rather have someone check your whole site's compliance signals at once, alongside your AI citation readiness, run a free Audit and see where things actually stand.

How we build review harvesting that stays inside the lines

Reviews are also, separately from any of this, one of the signals feeding what Google's own AI systems say about your agency when someone asks. We've covered how Google's Ask Maps feature now writes an AI-generated summary of your business straight from your review text, and a review set built by filtering out anything below a certain star rating gives that summarizer a thinner, less representative body of language to draw from than a complete one would. Reviews are also one of the ranking signals behind the map pack itself, which we cover in our guide on why insurance agencies don't show up in the map pack. None of that works if the underlying review pipeline is exposed the way this guide describes.

Digital Foundation's Starter tier, currently $247 a month on our live pricing page, includes "Google Business Profile management + review harvesting" as a listed feature, alongside a complete, compliant website and AEO optimization built to help your pages get cited by AI answer engines13. Review harvesting, as we build it, means every customer gets the same invitation, on the same terms, with no sentiment branch deciding who gets asked. If that's the CRM most agencies already run, which is the GoHighLevel-centered stack we cover in a separate guide, the fix is a configuration change inside a tool you already own, not a new platform to buy.

For a single office, that configuration change is a one-time fix. For an FMO or IMO watching this across a downline of agents, each running their own copy of the same inherited template, it's a different scale of problem, because checking every agent's individual CRM workflow by hand doesn't scale past a handful of offices. The same argument that applies to a shared compliance layer for outbound calling applies here: building the review-request standard once, centrally, and applying it across every office under it beats depending on each location to have independently noticed and fixed a sentiment branch nobody told them to look for.

You can do this yourself

Everything in the compliant checklist above is something you can implement in your existing CRM this week, with no new software and no vendor call. This section exists for agencies who would rather the whole cadence, the request, the response monitoring, the AI citation work built on top of it, already be running instead of managed as a side project between renewals.

What you get

Stop treating your review request workflow as a set-it-and-forget-it customer service nicety and start treating it as a compliance surface with a real regulator and a real platform policy attached to it. The fix is not complicated, and it doesn't cost anything beyond the time it takes to open your CRM and remove one branch. What it buys you is a public review set that's actually representative of your book of business, a lower chance of a platform-level suspension you'd have no warning before, and a review pipeline that isn't quietly working against the exact AI citation and map pack signals the rest of your marketing is trying to build.

What this doesn't do is promise an FTC action will never reach an agency this size, or that Google's detection systems will never flag a specific business. Enforcement patterns, platform policies, and penalty amounts are all things that change, the way Google already tightened its own review policy once in early 20269 and the FTC already raised its penalty ceiling once since the rule took effect10. The facts in this guide are current and sourced as of this week. Check the FTC's own rule page and Google's own Business Profile policy directly before assuming last year's reading still holds.

Questions agents ask

What is review gating?

Review gating is asking a customer how their experience went before you ask them for a public review, then routing the ones who answer positively to Google or Facebook and the ones who answer negatively to a private internal form instead. Google's own Business Profile policy names this directly: businesses may not "discourage or prohibit negative reviews, or selectively solicit positive reviews from customers."

Does the FTC's reviews rule really apply to a small insurance agency?

Yes. The Rule on the Use of Consumer Reviews and Testimonials, 16 CFR Part 465, took effect October 21, 2024, and applies to any business, regardless of size, that solicits, displays, or manages consumer reviews. It does not carry a small-business exemption. What varies by size is the likelihood of an actual FTC enforcement action, not whether the rule technically applies to you.

Can I get sued by a customer for review gating, the way I could under a state text messaging law?

No, and this is worth being precise about. The FTC's reviews rule is enforced by the Federal Trade Commission itself, through civil penalties under Section 5(m) of the FTC Act, not through a private right of action a customer can file on their own. A customer cannot sue your agency directly under this specific rule the way a text recipient can sue under a state mini-TCPA statute. The exposure here is regulatory, not private litigation.

Is my CRM's reputation management feature illegal?

The feature itself isn't illegal. Asking a customer a private feedback question is fine. What creates exposure is the combination: filtering based on the answer to decide who gets asked publicly, then displaying the resulting public reviews in a way that implies they represent everyone who was asked. The FTC's rule targets that combination under its review suppression provision, 16 CFR 465.7(b).

What should I do with the CRM workflow I already have running?

Two options that both work. Either ask every customer for a public review the same way, with no branch based on predicted sentiment, and handle service recovery for unhappy customers through a completely separate outreach that has nothing to do with the review request. Or, if you keep a private feedback step, make sure it never determines whether someone is invited to leave a public review at all.

Does responding to a bad review count as suppression?

No. Responding publicly to a negative review, even disputing facts in it professionally, is not suppression and is not what either rule targets. What the rules target is preventing the review from existing on your public profile in the first place, or filtering who even gets the chance to leave one. Answering a review that's already up is good practice, not a violation.

Does this affect how AI answer engines see my agency?

It can, indirectly. A public review set built by routing away anything below a certain star rating produces a reputation signal that looks stronger than it is, and Google's own AI-generated review summaries and answer engines that quote review sentiment draw on whatever the public set actually contains. A thin, filtered set of five-star reviews is a weaker signal for an AI system to cite from than a smaller but complete, actively managed set with responses attached.

Sources

  1. Federal Trade Commission. "Consumer Reviews and Testimonials Rule: Questions and Answers," effective date and scope, checked September 2026. ftc.gov.
  2. 16 CFR Part 465, "Trade Regulation Rule on the Use of Consumer Reviews and Testimonials," effective October 21, 2024. law.cornell.edu.
  3. 16 CFR 465.2, fake or false consumer reviews. law.cornell.edu.
  4. 16 CFR 465.5, insider reviews and disclosure of material relationship. law.cornell.edu.
  5. 16 CFR 465.7, review suppression, including misrepresenting displayed reviews as most or all submitted reviews. law.cornell.edu.
  6. Google Business Profile Help. "Prohibited and restricted content," rating and review manipulation section, banning selective solicitation of positive reviews. support.google.com.
  7. GHL Experts. "Automate Client Reviews with GoHighLevel Reputation Management," description of the sentiment-based routing flow used as a marketing template, checked September 2026. ghlexperts.com.
  8. Google Business Profile Help. "Fix suspended or disabled profiles," suspension causes and effects, verified live 2026-08-13. support.google.com.
  9. Three Chapter Media. "Google Business Profile Review Policy 2026: What Changed," summarizing early-2026 additions to Google's prohibited content guidelines, dated April 22, 2026, citing Google's own policy page. threechaptermedia.com.
  10. Federal Trade Commission. "FTC Publishes Inflation-Adjusted Civil Penalty Amounts for 2025," maximum penalty of $53,088 for violations of Sections 5(l), 5(m)(1)(A), and 5(m)(1)(B) of the FTC Act, effective January 17, 2025. ftc.gov.
  11. Bryan Cave Leighton Paisner. "Part 6: What the FTC's Final Rule on Reviews and Testimonials Means for Enforcement, Penalties," discussing Section 5(m) authority and per-day violation counting. bclplaw.com.
  12. BrightLocal. "Local Consumer Review Survey 2026," a representative panel of 1,002 US adults, published February 11, 2026. brightlocal.com.
  13. Strategic AI Architects. "Digital Foundation" pricing and tier features, verified this week. strategicaiarchitects.com.
  14. Centers for Medicare & Medicaid Services. "Medicare Open Enrollment," the October 15 to December 7 Annual Enrollment Period window, checked September 2026. cms.gov.

Talk it through

Want a second pair of eyes on it?

Free 30 minutes. Bring what you found, or bring nothing and we will look together at how AI engines read your site and which fixes move first.

See what your own review pipeline is doing

Run the free Audit, a live AEO Audit plus a HIPAA tracking scan of your site, in under a minute.

← All guides