InstantApp™ RCS Messaging Available Now

KYC and KYUP Part 1: No Longer Optional in Telecommunications

Mark Speer

Whether You’re a Telecom Provider, Enterprise, or Call Recipient, Everyone Has a Stake in Compliance

Every day, millions of robocalls and spam texts flood American phones—a large percentage of them scams, spoofed political messages, or fraud attempts that pass through legitimate telecommunications infrastructure.

Regulators, carriers, and enterprises have converged on an answer to this problem: Know Your Customer (KYC) and Know Your Provider/Upstream Provider (KYUP). What began as banking terminology has become one of the most important compliance initiatives in telecom today.

From Banking Vault to Phone Network

KYC has deep roots in financial services, where banks have long been required to verify who they’re doing business with to prevent money laundering and fraud. Telecom didn’t inherit this concept by accident, it was deliberately imported. Numeracle (a Commio partner) is widely credited with bringing the idea to the voice communications industry, applying the same fraud-mitigation logic that worked in banking to phone traffic.

The Federal Communications Commission (FCC) formalized the concept a few years later. The FCC instituted KYC requirements for originating voice service providers in 2020 and has continued to expand those requirements ever since. That expansion has now taken a major step forward. In April, 2026, the FCC adopted a Further Notice of Proposed Rulemaking (FNPRM) to convert its existing, principles-based KYC obligation into a far more prescriptive framework for originating providers.

KYC and KYUP: Two Sides of the Same Coin

While KYC focuses on verifying the end customers and businesses placing calls or sending messages, Know Your Upstream Provider (referred to by some simply as Know Your Provider, or KYP) extends that same scrutiny further back in the call chain: to the carriers and intermediaries handing off traffic to one another. The distinction matters because bad actors rarely originate fraud on networks that vet them directly; they route it through less-scrutinized upstream partners instead.

FCC rules since 2024 require that all intermediate and terminating providers take steps to know their immediate upstream provider, effectively making every provider in the call path responsible for the calls that move through their networks. Notably, the Commission has intentionally left the specifics open-ended: providers are expected to collect information such as a physical address, contact persons, state or country of incorporation, and federal tax ID, but the exact due-diligence steps are left to each provider to define and defend.

Compliance-focused providers have had to adapt quickly. And while Commio has been vigilant for years, constant monitoring and scrutiny is required. Meanwhile Numeracle has continued to push the concept forward, pioneering a KYC framework specifically designed to verify the business entities operating within telecommunications networks and tie business identity to observed traffic behavior—extending vetting beyond the initial onboarding moment into ongoing monitoring.

The Cost of Getting It Wrong

  Scam, Spam, and RobocallsThe consequences of weak KYC/KYUP programs aren’t hypothetical. Recent enforcement history reads like a cautionary tale:

  • The FCC reached a $1 million settlement with Lingo Telecom after the carrier failed to properly validate caller ID information, which allowed a deepfake voice of a presidential candidate to be used in robocalls.
  • A coalition of 48 state attorneys general, plus the District of Columbia, sued Avid Telecom, alleging the company was responsible for billions of illegal spam calls, including calls to numbers on the Do Not Call Registry.
  • The FTC took action against VoIP provider XCast Labs after it continued to funnel hundreds of millions of illegal robocalls through its network even after receiving multiple warnings.

FCC Enforcement Bureau Chief Loyaan Egal put the underlying philosophy plainly, stating that “Know Your Customer” principles should be at the forefront of all communications service providers’ business practices—a line regulators have echoed repeatedly as enforcement has intensified.

The FCC’s newest proposals would put real teeth behind that philosophy. The pending KYC FNPRM proposes a $2,500 per-call base forfeiture for KYC violations, and the companion KYUP FNPRM proposes a $2,500 per-call base fine for failing to meet KYUP obligations plus a separate $1,000 per-call fine for improper attestations or unauthenticated-call violations.

Litigation is reinforcing the same message. In a case against Smartbiz Telecom, a court found that the provider’s receipt of numerous traceback requests satisfied an actual-notice standard but left it for a jury to decide whether Smartbiz’s KYC program and robocall mitigation efforts were sufficient to prevent illegal transmissions. The case serves as a warning that a KYC policy on paper isn’t necessarily the same as one a court will find adequate.

Part 1: Background & Costs of Non-compliance
Part 2: The Shifting Legal Perspective
Part 3: Why It Matters to You | Conclusion

Date posted: July 29, 2026

Topic: Branded Calling   Outbound Voice   RCS Business Messaging   Voice API  

Tags: Compliance   FCC   FCC Regulations   STIR SHAKEN  

Mark Speer

As VP of Purchasing, Mark ensures that Commio’s products deliver maximum value and efficiency across a wide variety of implementations. When he’s not working with our carriers to make sure calls complete, he enjoys classic cars, traveling, artwork and exploring the desert southwest. He also enjoys spending time with his wife and family in Tucson, Arizona where they reside.

Recent posts from Mark Speer

Get the latest from Commio

We’ll send you one email a month featuring our latest blog content.

';