The Federal Communications Commission has issued a Further Notice of Proposed Rulemaking (FNPRM) proposing enhanced Know-Your-Customer (KYC) requirements for originating voice service providers. If adopted, the proposed framework would expand the categories of information that originating providers must obtain from their customers before calls are placed, marking a significant evolution in the Commission's ongoing efforts to address illegal and unwanted calling activity at the source of traffic origination.
The proceeding presents a limited but meaningful window for industry participants to shape the contours of any final rules. Initial comments on the FNPRM are due June 25, 2026, with reply comments due July 27, 2026. Originating voice service providers, trade associations, enterprise callers, and other interested stakeholders should consider whether to participate in the record, either individually or through coalition filings, to address questions concerning the scope of required customer information, implementation timelines, recordkeeping obligations, and the operational feasibility of the proposals.
For originating voice service providers in particular, the proposed rules could substantially expand existing compliance burdens. Although providers already perform various forms of customer vetting under existing regulatory and contractual frameworks, the FNPRM contemplates more prescriptive requirements that could affect customer onboarding workflows, due diligence procedures, ongoing monitoring practices, documentation retention, and internal governance. Providers that rely heavily on resellers, intermediate carriers, or high-volume enterprise customers may face particularly complex implementation considerations.
In view of the proposal, originating providers should consider undertaking an early review of their current KYC and customer onboarding practices to identify potential gaps relative to the FNPRM's contemplated obligations. A gap assessment performed now can both inform substantive comments to the Commission and position providers to implement any final rules with less operational disruption. Providers should also evaluate how proposed obligations would interact with existing STIR/SHAKEN, robocall mitigation, and traceback-related requirements, as well as with state-level call authentication initiatives.
This alert provides a general summary of the FNPRM and is not intended as legal advice. Clients should consult with counsel to obtain advice tailored to their particular operations, customer relationships, and compliance posture before taking action in response to the proposed rulemaking.