Compliance Is a Moving Target
Telecom regulatory attorneys have been especially vocal about the fact that minimum FCC compliance is a floor, not a ceiling. Jonathan Marashlian, Managing Partner of Marashlian & Donahue, PLLC (The CommLaw Group), has argued that voice service providers who assume STIR/SHAKEN and robocall mitigation filings are sufficient are misreading the risk landscape. He points out that even after providers check the basic regulatory boxes, compliance with the bare minimum requirements established by the FCC is insufficient to mitigate the myriad of business risks arising from government action and private litigation alike.
That risk isn’t limited to federal regulators. Marashlian notes that providers can also be exposed to the FTC and state attorneys general’s “known or should have known” standard, as well as an increasingly creative plaintiffs’ bar—including cases with companies that have no direct involvement in a scam campaign. For example, a hotel chain victimized by impersonation robocalls sues “John Doe” defendants specifically to preserve the ability to later pull in any carrier that transported the fraudulent traffic.
The CommLaw Group also flags a subtler risk: overcorrecting. In recent guidance on FCC “deficiency” solicitations, the firm warned that providers who rush to file more detailed KYC procedures than they actually follow can create more legal exposure, not less. They advise companies to not add KYC, traceback, monitoring, or enforcement language to a filing unless the company actually follows those procedures, and avoid confusing “more detailed” with “more compliant.”
Where Regulation Is Headed
The KYC FNPRM: In April, the Commission adopted a Further Notice of Proposed Rulemaking that would convert the existing, principles-based KYC obligation into a detailed, auditable framework for originating voice service providers. Among the proposals:
- Requiring originating providers to collect a customer’s name, physical address, government-issued ID number, and an alternate phone number before activating service;
- Verifying that information;
- Retaining records for 4 years after the customer relationship ends; and
- Re-verifying information if red flags arise (e.g., a spike in call volume).
The FNPRM also asks whether information-collection requirements should scale with risk—for example, applying stricter rules to high-volume, foreign-based, or prepaid customers—and whether online service providers should have to certify KYC compliance directly in their Robocall Mitigation Database (RMD) filings, potentially with independent third-party audits. Notably, the Commission grounded part of its authority for the rule in national security, not just consumer protection.
The KYUP and STIR/SHAKEN FNPRM: In May, the Commission adopted a similar FNPRM that does for upstream providers what the KYC FNPRM does for end customers. Chairman Brendan Carr framed the goal directly: to “hold providers to a higher accountability measure or to eliminate them from the voice ecosystem if they continue to facilitate illegal robocalls.” The proposal would require voice service providers to take reasonable, effective steps to ensure that any originating or intermediate provider they directly receive traffic from isn’t using their network to transmit illegal calls, including:
- Collecting and verifying specified business, ownership, and regulatory-history information directly from upstream providers;
- Retaining those records for 4 years; and
- Monitoring upstream partners on an ongoing basis using call analytics and traceback history, not just at onboarding.
The FNPRM also proposes giving the STIR/SHAKEN Governance Authority a bigger enforcement role—tightening who can obtain SPC tokens, requiring more active policing of token misuse, and coordinating with the Industry Traceback Group—and would require all providers serving end users (not just originating providers) to make attestation-level determinations..
A third proceeding is now layered on top: the Robocall Mitigation Database FNPRM released this month (July 2026). This proposal would tighten and expand the RMD itself, tying it more directly into the KYC, KYUP, traceback, and numbering-access initiatives described above. It particularly targets providers that obtain numbers through wholesale arrangements, RespOrg relationships, resellers, or third-party platforms, signaling that the FCC increasingly views number access itself as a compliance lever.
None of these FNPRMs are final law yet. These are proposed rules open for public comment, and the FCC has indicated that any adopted KYUP/STIR-SHAKEN rules would take effect the later of 12 months after Federal Register publication of a final Report and Order, or 30 days after OMB approval of any new information-collection requirements. Attorneys are advising providers to use the comment period to audit current KYC/KYUP practices now, rather than wait for final rules to identify gaps.
Numeracle, for its part, has continued to expand its identity-verification tooling in anticipation of formal KYUP rules, positioning ongoing vetting—versus one-time onboarding checks—as the new baseline expectation for the industry.
Part 1: Background & Costs of Non-compliance
Part 2: The Shifting Legal Perspective
Part 3: Why It Matters to You | Conclusion
