The Federal Communications Commission has unanimously advanced a proposal that would significantly reshape how voice service providers vet customers, signaling a shift toward mandatory identity verification and stricter enforcement tied directly to call volume. The Further Notice of Proposed Rulemaking, approved last week, asks whether providers should be required to verify customer identities using government-issued IDs and other data before enabling service, while also exploring penalties based on the number of illegal calls placed.
The move builds on the FCC’s broader effort to stop illegal robocalls before they enter the network, with regulators increasingly focused on the role originating providers play at the front end of the call path.
A Shift Toward More Prescriptive KYC Standards
The proposal marks a clear evolution from the FCC’s current principles-based KYC framework to something closer to a formal compliance regime. Regulators are seeking comment on requiring providers to verify:
- Customer name and physical address
- Government-issued identification
- Alternative phone numbers
- Additional data for high-volume callers, such as use case and IP address
The FCC is also considering whether providers should maintain documentation and audit trails for years after the customer relationship ends, and whether re-verification should be triggered by suspicious calling patterns.
Chairman Brendan Carr said the changes are intended to “close the gaps” that have allowed bad actors to access U.S. networks, noting that some providers have done “the bare minimum” under existing rules.
Enforcement: Aligning Penalties With Call Volume
A key component of the proposal is how violations would be enforced. The FCC is seeking input on assessing penalties on a per-call basis, rather than per violation, to better reflect the scale of harm caused by illegal robocalls.
This approach would materially raise the stakes for providers that fail to adequately vet customers, particularly those enabling high-volume traffic.
Tying KYC to Broader Robocall Initiatives
The KYC proposal does not stand alone. It is part of a broader FCC strategy that includes:
- Strengthening STIR/SHAKEN caller ID authentication standards
- Closing loopholes that allow bad actors to obtain high-level call attestations
- Expanding “know your upstream provider” requirements
- Potentially removing providers from U.S. networks if they enable illegal robocalls
Industry groups, including the American Bankers Association, have supported stronger identity verification as a way to reinforce the call authentication framework and reduce fraud exposure.
At the same time, organizations like ACA International are expected to weigh in on how new requirements could impact legitimate business communications and smaller providers.
What Comes Next
Once published in the Federal Register, the FCC will open the proposal for public comment. The outcome could redefine onboarding, monitoring, and compliance expectations for any organization placing calls at scale.
For collection operations and other high-volume callers, the direction is clear: the FCC is moving upstream, and the bar for who gets access to the network is about to get much higher.




