Member Content
The FCC’s KYC Pivot: Identity, Accountability, and the Future of Voice Networks
The FCC’s Anti-Robocalling Rule Proposal: What’s Actually Changing

By Mike Pedrick, VP of Cybersecurity Consulting
PDI Technologies
In an effort to curb illegal robocalling, the Federal Communications Commission (FCC) is seeking comment on the part of experts regarding a controversial proposed update to the way carriers are to provision numbers.
The more strict screening process calls for carriers to collect and maintain customer identity data, including “name, address, government ID, and alternative phone numbers – before enabling service,” according to the FCC’s own press release.
Source: https://docs.fcc.gov/public/attachments/DOC-421309A1.pdf
This applies to new and existing customers.
It’s important to note that the FCC is not inventing Know Your Customer (KYC) from scratch; it is hardening it. Today, originating providers must take “affirmative, effective measures” to avoid being a conduit for illegal robocalls, but the rule is intentionally vague. The new proposal would move from “be prudent” to “do these specific things.” That includes defined customer identification requirements for new and renewing customers, verification and re‑verification of data, differentiated treatment for high‑volume customers, and explicit retention expectations. The Commission is also floating per‑call penalties for KYC failures, which turns weak onboarding into a metered liability rather than a one‑time mistake.
In other words: KYC shifts from a policy paragraph in a mitigation plan to a measurable control surface that can be audited, enforced, and priced into the carrier’s risk model. Strong data governance programs become non-negotiable.
From Number Trust to Identity Trust
STIR/SHAKEN solved a narrow problem: “Is this caller ID legitimately associated with the originating provider’s customer?” It did not ask, “Who is that customer, really?”
If KYC becomes prescriptive, carriers need to connect three layers:
- Identity proofing: establishing that a customer is a real, attributable entity
- Number assignment: binding numbers to that identity and maintain that mapping over time
- Attestation policy: designing STIR/SHAKEN attestation levels to reflect the strength and verifiability of that binding
This applies pressure on carrier infrastructure. In the data model, a unified customer identity record must be created that can be referenced by provisioning, numbering, and STIR/SHAKEN systems. Attestation decisions must be driven by KYC status (e.g., pending, verified, high‑risk) rather than static product codes in the control plane, and regulators will be interested in defensible documentation regarding how a given A‑attested call traces back to a specific, verified identity.
The more robust that identity record becomes, the more it looks like a high‑value target. To avoid complications from breach events or privacy regulation scrutiny, strict access control, minimization of attributes, and clear separation between “identity needed for KYC” and “data used for marketing or analytics” is warranted.
Customer Onboarding
The current standard lets providers argue that basic fraud checks and traffic monitoring satisfy their duty. The rulemaking explicitly seeks to fill the gap between that flexible requirement and the rigorous KYC steps necessary to protect consumers.
To operationalize that shift, carriers will need formal onboarding workflows for identity verification steps that are embedded in order entry, not bolted on as manual review. Risk‑tiered controls would help differentiate KYC depth for low‑volume residential lines from high‑volume VoIP aggregators, easing administrative strain. Finally, automated lifecycle governance is key; re‑verification triggers at renewal, major profile changes, or anomalous traffic patterns.
There are data protection implications in the proposed rulemaking that no carrier should ignore. To comply with privacy standards that call for purpose limitation, carriers should be prepared to defend processes which keep KYC data, which is collected solely for fraud and compliance, away from broad commercial reuse systems – as well as how KYC artifacts are managed through the lifecycle to inevitable secure destruction.
Where verification is outsourced, third-party risk management programs must be revised to ensure compliance.
This is where carriers will likely feel the cultural change: onboarding becomes a compliance function as much as a sales function.
Traceback
Traceback has become one of the FCC’s primary enforcement tools against illegal robocalls. The Eighth Report and Order leans heavily on traceback to justify broader blocking and mitigation obligations.
Today, traceback often dead‑ends at a provider whose customer records are thin or unverifiable. KYC aims to change that. For carriers, that means:
- Traceback‑ready records: customer identity, contact, and contractual data must be structured so that a traceback request can be answered quickly and accurately
- Linkage between traffic and identity: call detail records, trunk assignments, and routing configurations must be traceable back to a specific verified customer, not just a reseller label
- Exception handling: when traceback reveals that a “good” customer is generating bad traffic, playbooks are needed that combine enforcement, remediation, and potential re‑verification
From a privacy standpoint, traceback is a controlled disclosure of customer information to industry traceback consortia and regulators. Clear policies are needed on what is shared, under what authority, and how disclosures are logged and reviewed.
Done poorly, traceback cooperation can look like uncontrolled data sharing. Done well, it is a narrowly scoped, well‑governed exception.
Privacy and Consumer Sentiment
State privacy regimes like the CPRA emphasize data minimization, purpose limitation, and consumer control. KYC pushes in the opposite direction: collect more, verify more, retain more.
Carriers will need to reconcile these pressures by design, not by after‑the‑fact legal arguments. Defining the minimum attribute set that satisfies regulatory expectations for each customer type is a good start; finding the balance of ‘just-enough-KYC’ is consistent with sound risk management. Explain, in plain language, why specific data is being collected, how long it will be kept, and how it protects consumers from fraud and scams. Finally, for non‑regulated uses (e.g., marketing), keep KYC data out of scope entirely.
Consumer sentiment is the wild card. People already distrust carriers on privacy. Asking for government IDs or business documents to turn on phone service will trigger swift and often very public skepticism.
That means:
- Expect higher abandonment rates in onboarding flows.
- Plan for customer support scripts that can explain KYC without sounding like surveillance.
- Consider independent attestations (e.g., SOC 2, ISO 27001) and privacy seals as part of the trust story.
Numbering, Anonymity, and the End of Frictionless Voice
Numbering rules already require accurate records of number assignments. KYC would tighten the coupling between a number and a verified identity, especially for high‑volume and VoIP use cases. Operationally, that means robust number inventory systems that track not just block entitlement but which verified entity is responsible for specifically-identified traffic.
For carriers that sell to aggregators, contractual and technical mechanisms may be required to ensure downstream KYC is performed and auditable.
Carriers will need to decide whether and how to support scenarios like hotlines, shelters, or other sensitive services that rely on some degree of caller anonymity, which would represent a degree of non-compliance.
From a data protection angle, the risk is over‑linkage: turning phone numbers into universal identifiers across services. Limit cross‑system use of KYC identifiers, avoid using KYC data to enrich advertising or data‑broker relationships, and build internal guardrails against function creep where KYC data becomes a convenient shortcut for other analytics.
Enforcement Posture
The rulemaking contemplates assessing penalties for KYC violations on a per‑call basis. Combined with the Eighth Report and Order’s expansion of blocking and mitigation duties, the message is clear: The FCC intends to price KYC failures into every illegal call that leaves the network.
For carriers, that changes the math dramatically. KYC is no longer a binary control; it is a variable that affects expected loss per call. Spending, then, on identity verification, data protection, and monitoring can be justified directly against avoided per‑call penalties and enforcement actions.
In terms of governance, boards and executives will need clear reporting on KYC coverage, exceptions, and incidents, similar to how they view credit risk or AML in financial services.
To stay on the right side of both regulators and customers, carriers will have to treat KYC as a core part of their security and privacy architecture, not a compliance checkbox. The infrastructure work is significant, but so is the opportunity to rebuild trust in a channel that consumers increasingly associate with fraud.
Connecting the Dots
The FCC’s proposal forces carriers to confront a simple truth: the voice network can no longer rely on trust by default. Prescriptive KYC turns identity verification, data governance, and lifecycle controls into core operational disciplines rather than peripheral safeguards.
It also exposes the tension between fraud prevention, privacy expectations, and consumer tolerance for friction – while ratcheting up the consequences for carriers who are ill-prepared.
Carriers that treat this as a compliance exercise will struggle. Carriers that redesign their infrastructure around verifiable identity, controlled data flows, and transparent customer communication will be positioned to meet both regulatory scrutiny and public skepticism.
The work is significant, but so is the opportunity to rebuild consumer confidence in a channel that has become synonymous with risk.
To contribute content, please contact comms@ccamobile.org. (CCA members only.)



