The FCC wants phone companies to run bank-style KYC.
The FCC sought comment on making phone companies collect and verify government ID before granting service. What FCC 26-27 asks, and what it proposes.
Scam robocalls cost Americans close to $2 billion last year. The Federal Communications Commission has spent years fighting them mid-network. On 1 May 2026 it turned to the front door, and asked whether phone companies should verify who their customers are before letting them dial.
The short version
- The target. The target is illegal robocalls. The Federal Communications Commission has attacked them mid-network for years; Further Notice FCC 26-27, released 1 May 2026, moves to the point where callers first get onto the network.
- The model. The FCC built the proposal on US bank rules. Its background section is titled "Financial Sector" and cites the Bank Secrecy Act and the Customer Identification Program rule at 31 CFR § 1020.220.
- The fields. Four items were floated as a minimum: name, physical address, government-issued identification number, and an alternate telephone number, collected from new and renewing customers before service begins.
- The posture. Almost everything here is a question, not a rule. The FCC "seeks comment on requiring" each measure. Only the penalty is a firm proposal: $2,500 per illegal call.
- Where it stands. Comments closed on 27 July 2026. A day later 50 state and territory attorneys general told the FCC the proposals do not go far enough. No rules have been adopted and there is no timetable.
The FCC is going after illegal robocalls at the point where callers first reach the network
Americans received roughly 29.6 billion scam robocalls and texts last year and lost close to $2 billion, according to a coalition of 49 state attorneys general. The Federal Communications Commission has been attacking those calls at every stage of their life. On 1 May 2026 it turned to the first stage: who gets onto the network at all.
The FCC says fighting illegal calls is "our top consumer protection priority". It works on three fronts: stopping calls before they enter the network, making the companies in the middle block them, and giving people better information about the calls that get through. This proposal is about the first front.
Volume is what makes the entry point matter. In their July letter the attorneys general describe a North Carolina case in which scammers placed 17.3 million calls in a single day through one phone company. Traffic at that scale reaches the network through an originating provider, and if that provider never established who the customer was, there is little for an investigator to work back from. The coalition publishes these figures without pointing to an underlying dataset, so they are best read as the attorneys general's numbers rather than as independently established ones.
An originating voice service provider is the company that puts a customer's call onto the phone network. Under the existing rule at 47 CFR § 64.1200(n)(4), that company must already take "affirmative, effective measures" to prevent customers from originating illegal calls, including knowing its customers. What the FCC has never done is say what those measures are.
That gap is the whole proceeding. The duty exists; the specification does not. On 30 April 2026 the FCC adopted a Further Notice of Proposed Rulemaking, FCC 26-27, released the following day under two dockets: CG Docket No. 17-59, Advanced Methods to Target and Eliminate Unlawful Robocalls, and CG Docket No. 02-278, the Telephone Consumer Protection Act rules. It asks whether to write that specification, and it went looking at financial services for the template.
Some do the bare minimum (or worse) and have become complicit in illegal robocalling schemes.
— Brendan Carr, Chairman, FCC. Statement to FCC 26-27, 30 April 2026
Commissioner Olivia Trusty, issuing a separate statement, put it more carefully: the FCC has maintained know-your-customer requirements for several years, but "experience suggests that further refinement may be warranted", while "provider flexibility remains important as well".
The proposal is built directly on the Bank Secrecy Act's Customer Identification Program
The FCC's notice opens its background with a section titled "Financial Sector". It points to the Bank Secrecy Act of 1970 and to the Customer Identification Program rule, 31 CFR § 1020.220. That rule is why a US bank asks for your name, date of birth, address and an ID number before it will open an account.
The lineage matters because it tells you what the FCC thinks it is building. Section 326 of the USA PATRIOT Act amended the Bank Secrecy Act in 2001 to require the US Treasury to set minimum standards for verifying customer identity at account opening. Banks respond with a written Customer Identification Program, verified using documents, non-documentary methods, or both.
The FCC said so plainly: gathering this information "is the standard to prevent money laundering", and given the misuse of networks by organised criminal groups, it "provides a good model for our work".
Banks agree, and lobbied for it. The notice cites a letter from the American Bankers Association dated 23 April 2026 supporting enhanced requirements, and one from Henderson State Bank a week earlier backing the extension of know-your-customer duties to originating providers.
They then filed together. On 25 June 2026, eleven financial trade associations lodged a joint comment in the proceeding. They include the American Bankers Association, the Bank Policy Institute, America's Credit Unions, the Consumer Bankers Association, the Mortgage Bankers Association and the Financial Technology Association. Their argument is that today's rules lack "specific standards for compliance", and that telecom providers should carry obligations comparable to the ones banks already carry.
The comparison rests on an assumption worth checking. Bank customer identification operates inside a closed, licensed system: the institutions are supervised, the counterparties are known, and money leaves a traceable trail between them. Phone networks are open by design, and the FCC's own notice raises the question of foreign customers using domestic providers to originate large volumes of calls. Identity collected from a US customer at a US provider addresses one part of that population. Whether it reaches the rest is a question the record will have to answer.
The parallel is not exact in the detail either, and the differences are where the practical work sits.
| Requirement | US banks: Customer Identification Program | FCC, voice providers |
|---|---|---|
| Name | Required | Sought comment |
| Physical address | Required | Sought comment |
| Identification number | Required | Sought comment, government-issued |
| Date of birth | Required (individuals) | Asked whether to add |
| Alternate telephone number | Not required | Sought comment |
| Screening against federal terrorist lists | Required | Not proposed |
| Record retention | 5 years after the account closes | 4 years after the relationship ends (sought comment) |
Sources: 31 CFR § 1020.220; FCC 26-27
Four identity fields would be collected before a customer places a single call
In its May 2026 notice, the FCC sought comment on requiring originating voice service providers to obtain four items from new and renewing customers before granting access: name, physical address, government-issued identification number, and an alternate telephone number. High-volume customers would additionally supply the intended use of the service and the IP address calls originate from.
Read that list against your own onboarding flow. Three of the four are ordinary customer-record fields that most providers already hold in some form. The government-issued identification number is the one that changes the nature of the exercise, because collecting it implies verifying it. The alternate telephone number is not a Customer Identification Program field at all; it is specific to this proposal.
Only one of the four carries a definitional argument. The FCC asked how "physical address" should be defined, and whether to exclude virtual addresses, shared office locations without a dedicated suite or floor, P.O. boxes, mail forwarding services and hosted servers, each named as a way bad actors conceal identity. If that exclusion survives, a provider cannot satisfy the field by recording whatever the customer typed.
High volume
For high-volume customers, a category the FCC expressly says covers business and foreign customers, the notice adds the intended use of the service, giving marketing, education and political campaigns as examples, plus the originating IP address where applicable.
There is a definitional hole here, and the FCC admits it. In a footnote it states that the Commission "has not defined 'high-volume originating service'", having instead left providers discretion to judge it against their own service offerings. Any provider modelling the cost of this proposal is modelling against an undefined population.
The FCC also asked whether a tiered approach should apply: stricter requirements for high-volume callers, for callers using equipment associated with robocalling, or for particular traffic patterns. That is risk-based customer checking by another name, and it will be familiar to anyone who has built point-of-sale identity checks for a newly regulated sector.
The notice asks whether the trade-off is worth it, and leaves the question open. It asks how the Commission can "minimize burdens on consumers so they are not unduly hindered in gaining access to voice services", and whether enhanced requirements would fall harder on smaller providers. The arithmetic behind that question is worth stating plainly: every customer of every originating provider would hand over a government-issued identification number, while the population the rule is aimed at is a small fraction of them. Where that balance should land is not settled in the notice, and it is one of the things the closed record now has to resolve.
Verification would mean documents, and the records would be held for four years
In the same May 2026 notice, the FCC sought comment on requiring originating voice service providers to obtain supporting records to verify a customer's identity, "such as copies of government-issued identification". It also floated keeping those records for four years after a customer leaves, which is how long the FCC has to bring a case over spoofing or deliberate breaches.
For high-volume customers the list of documents gets much longer:
- company formation records
- proof that the company is in good standing
- confirmation that the phone number given is real and in use
- independent records of the address
- evidence the business actually exists: a website, social media, or a shop front
That is a business verification workflow, not an individual one. A provider onboarding a call centre would be checking company existence, standing, contactability and physical reality before letting a single call through.
Re-checking customers is treated as essential, not optional. The FCC says ongoing review is needed "to ensure that bad actors have not gained access to the network". It asked providers how often they re-check today, and what prompts them to do it.
Read the retention number carefully
Four years, but from a different starting line than banking
Banks keep these records for five years after the account closes. The FCC floated four years after the customer leaves. That number is not arbitrary. Four years is how long the FCC has to bring a case over spoofing or deliberate breaches, so it is the window in which it might still need the file. Same idea, different starting point, different length. Do not assume a banking retention schedule covers a telecom one, or the other way round. The equivalent trap exists in AML: reporting deadlines and record-keeping periods are set by different clocks.
Only one element is a firm proposal: $2,500 for every illegal call
One part of the FCC's May 2026 notice is a firm proposal rather than a question. The FCC proposed a fine of $2,500 for every illegal call, written into the rule at 47 CFR § 64.1200(n)(4). It chose a per-call fine over a per-customer one so that the penalty tracks how many illegal calls a provider let through.
This is the distinction that matters most when reading coverage of this proceeding. Across the identity fields, the verification steps, the retention period and the risk tiers, the FCC's formula is "we seek comment on requiring". On the penalty, and only there, it is "we propose to codify".
The per-call basis is worth pausing on. The FCC's own term for this is a "base forfeiture", which is simply a starting fine that can be adjusted upward. A per-customer version, which the FCC rejected, "would result in a single base forfeiture regardless of the number of illegal calls made by the customer". Charging per call means the bill grows with the traffic. The same sign-up mistake costs a different amount depending on what that customer did next.
That ties the penalty to the outcome rather than to the quality of the check. Two providers running identical vetting can end up with very different exposure depending on which customers they happened to onboard. The FCC's position is that tying fines to harm "would better encourage compliance with the rule".
Both limbs
The FCC also closed an argument. Rule 64.1200(n)(4) has two limbs: knowing your customers, and exercising due diligence to keep your services from originating illegal traffic. A provider that fails either limb is in violation. Doing the paperwork while ignoring what the traffic shows is not compliance.
The notice pairs this with a question about speed: whether and how to expedite handing customer information to the FCC or law enforcement once a provider is told one of its customers is under investigation.
The FCC has not chosen between writing rules and setting a standard
In its May 2026 notice the Federal Communications Commission asked for comment on two approaches and has chosen neither. It could write detailed rules setting out the exact fields, checks and retention period. Or it could set a standard and protect any provider that meets it, whatever method they used. That protection is called a safe harbour.
Which one the FCC picks matters more than the field list, because it decides what a provider is answerable for. Under rules, you are judged on whether you collected the right things. Under a standard, you are judged on whether bad actors got through.
Option one
A detailed rulebook
The FCC names the fields, the checks and how long to keep records. Simple to follow and simple to audit. It also freezes the method into regulation while the fraud it targets keeps changing. Most of the notice is written this way.
Option two
A standard to meet
The FCC says what good looks like and protects providers who reach it. It asked whether an accredited outside verifier should count, and whether an effective automated system should. Harder to prove than a completed form, and more forgiving of new methods.
No scheme yet
The telecom side is not resisting this. The Cloud Communications Alliance, an industry body with more than 150 member companies, filed on 29 June 2026 in support. It asked the FCC to go further than the notice does: build in accredited third-party verification rather than leave each provider to check customers alone. Its president, Joe Marion, put the case this way: "For too long, bad actors have exploited gaps in identity verification to gain access to the network." The Alliance's position is that only verified, legitimate entities should be able to originate traffic at all.
Two cautions on the second option. No accreditation scheme for third-party identity verifiers exists under these rules. The FCC asked whether to create one; there is nothing to be accredited by today, and any vendor claiming FCC accreditation for this purpose is describing something that does not exist.
Second, the FCC is plainly conscious of not freezing the technology. Elsewhere in the notice it asks how to ensure enhanced requirements "do not inhibit the development and deployment of AI and automated KYC systems", and how the effectiveness of automated tools compares with traditional document verification. It asked the question; the record now holds the answers, and none of it is decided.
The record closed on 27 July, and a day later every state attorney general asked for more
Reply comments in the FCC's know-your-customer proceeding closed on 27 July 2026, leaving the record complete and no rules adopted. On 28 July 2026, the day after it shut, 50 state and territory attorneys general wrote to the FCC arguing the proposed requirements do not go far enough.
The attorneys general asked for three things. Providers should have to understand their customers' business, examining practices, reputation, history, intended use of the service and compliance with state and federal law, rather than collecting identity fields alone. The same standard should apply to every originating provider, including the smallest, because as the coalition puts it, illegal calls "are often facilitated by smaller voice service providers". And providers should carry out longer-term monitoring of high-risk customers, such as those on high-volume services.
South Dakota Attorney General Marty Jackley, one of the signatories, framed it as a continuing campaign rather than a single intervention. "This is an ongoing effort by Attorneys General to convince the FCC to be more diligent in combating robocall scams," he said. "Attorneys General see what such scams are doing to citizens in their states, and the federal government needs to do more." The coalition was led by the attorneys general of Illinois, Indiana, New Jersey, North Carolina, Ohio and Pennsylvania.
Both letters belong to Operation Robocall Roundup, run by the Anti-Robocall Multistate Litigation Task Force. Phase 1 began in August 2025 with warning letters to 37 smaller voice providers said to be allowing suspected illegal robocalls onto the network. Phase 2 began in December and extended to four of the largest intermediate providers in the country.
A second, separate letter is easy to confuse with it. On 8 July 2026, 49 attorneys general wrote to the FCC about its numbering resources proposal, which governs who may buy and resell telephone numbers rather than who may originate calls. That letter asked for stronger certification of resellers, disclosure of how numbers are assigned, and reporting on number sales. It carries the volume and loss figures quoted at the top of this piece. Two letters, three weeks apart, two different proceedings.
For providers, the practical posture is the one that fits any rulemaking with a closed record and no adopted text: the fields and the verification steps are now reasonably predictable, the timetable is not. That is a familiar position, and the discipline that works is the same one that works for any multi-year regulatory transition: build against what the regulator has actually written down, and date every assumption.
Taken together, the two proceedings show the FCC pushing identity requirements at two different points in the call chain: who may hold phone numbers, and who may put calls on the network. The pattern will look familiar to anyone who has watched a financial regulator extend obligations into sectors that never had them.
| Date | What changed | Status |
|---|---|---|
| 30 Apr 2026 | FNPRM adopted FCC 26-27, CG Docket Nos. 17-59 and 02-278. Chairman Carr and Commissioner Trusty issue separate statements. | Done |
| 1 May 2026 | Released Comment dates set relative to Federal Register publication: 30 and 60 days. | Done |
| 26 May 2026 | Published in the Federal Register Public Notice DA 26-523 fixes the two deadlines. | Done |
| 25 Jun 2026 | Comments closed First-round filings in CG Docket Nos. 17-59 and 02-278. | Done |
| 8 Jul 2026 | 49 attorneys general write to the FCC On the separate 2026 numbering resources proposal, not this proceeding. | Done |
| 27 Jul 2026 | Reply comments closed The record is now complete. | Done |
| No date set | Commission decision The FCC has not published a timetable. It sought comment on whether rules would apply only to customers acquired or renewed after an effective date, and on a six-month runway after Paperwork Reduction Act approval. | Pending |
Key takeaways
- Nothing is in force. The FCC has adopted no new know-your-customer rules. The existing duty at 47 CFR § 64.1200(n)(4) already applies, unspecified, and has since before this proceeding.
- "Sought comment" is not "proposed". Every identity field, verification step and retention period in FCC 26-27 is framed as a question. Only the $2,500-per-call fine is a firm proposal. Coverage that blurs the two overstates where the FCC has landed.
- The template is banking. The notice's background opens with a "Financial Sector" section and builds on the Bank Secrecy Act and the Customer Identification Program rule. The American Bankers Association wrote in support on 23 April 2026.
- High-volume verification is business verification. Corporate formation records, proof of good standing, third-party address records and evidence of commercial presence are company checks, not individual ones.
- The safe-harbour question is the one to watch. Whether an accredited third party or an effective automated system can discharge the duty decides whether this becomes a checklist or an outcome standard. No accreditation scheme exists today.
- Two AG letters, three weeks apart. On 28 July 2026, 50 attorneys general wrote about this proceeding, asking that providers assess a customer's business and that the standard apply to every provider. A separate 8 July letter from 49 attorneys general concerned the numbering resources proposal instead.
Using Didit for the collection and verification steps
Didit covers the identity checks this proceeding is about. ID Verification reads and validates a government-issued document. Proof of Address tests a physical address rather than storing whatever the customer typed, the distinction the FCC raised when it asked about excluding P.O. boxes and mail forwarding services. Phone Verification confirms a number is live and reachable, which is what the notice asks for on the alternate telephone number. Business Verification (KYB) pulls company formation records and standing for the high-volume customers the FCC would treat as higher risk.
Published rates are $0.15 per ID Verification check, $0.20 per Proof of Address, from $0.03 per Phone Verification and $2.00 per KYB bundle. The Full KYC bundle is $0.33 per check, with 500 free every month. Current module prices are listed on the pricing page.
These checks produce evidence, not conclusions. Deciding whether a customer is a bad actor, watching traffic for the red flags that would trigger re-verification, answering FCC or law-enforcement requests, and retaining records for whatever period is ultimately adopted all stay with the provider. And no FCC accreditation scheme for identity verification exists. The Commission has only asked whether to create one, so no vendor, Didit included, can offer a safe harbour today.
Common questions
Do these Know Your Customer requirements apply to voice providers today?
No. The FCC has not adopted the measures described in FCC 26-27. The existing duty at 47 CFR § 64.1200(n)(4) already requires originating providers to take affirmative, effective measures to know their customers, but the FCC has never specified what those measures must be. Specifying them is what this proceeding is about.
Is the $2,500 per-call penalty in force?
No. It is a proposal. The FCC proposed a fine of $2,500 for each illegal call and asked the public for comment on it. That comment period closed on 27 July 2026, and no rules have been adopted.
Does the FCC accredit third-party identity verification providers?
No such accreditation scheme exists under these rules. The FCC asked whether using an accredited third party to verify customer identity should trigger a safe harbour from enforcement. That is an open question in the proceeding, not an existing programme.
Which companies would be covered?
Originating voice service providers: the company that puts a customer's call onto the network. The FCC sought comment on applying the requirements to both new and renewing customers, and on whether any rules would apply only to customers acquired or renewed after an effective date.
How would this differ from bank Know Your Customer rules?
Three differences stand out. Banks must screen customers against federal terrorist lists; the FCC did not propose sanctions screening. Banks retain records for five years after an account closes; the FCC floated four years after a customer relationship ends. The FCC also asked about an alternate telephone number and originating IP address, which the bank Customer Identification Program rule does not require.
Related reading
- AUSTRAC Tranche 2 for dealers in precious metals & stones — What point-of-sale identity checks look like when a sector is pulled into a regime for the first time.
- The new AUSTRAC SMR form (2026) — Expanded reportable details, and how reporting deadlines and record-keeping run on separate clocks.
- Prediction markets: who are your users? — Three regulators examined a new market in 2026 and all landed on the same question about identity.
- AUSTRAC new forms transition timeline (2026–2029) — How to read a multi-year regulatory transition without missing the dates that bind.
Sources
- Advanced Methods to Target and Eliminate Unlawful Robocalls; Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991. Further Notice of Proposed Rulemaking, FCC 26-27 — Federal Communications Commission · Adopted 30 April 2026, released 1 May 2026
- Consumer and Governmental Affairs Bureau Announces Comment Dates for Know-Your-Customer Further Notice of Proposed Rulemaking. Public Notice DA 26-523 — Federal Communications Commission · 26 May 2026
- Enhancing Know-Your-Customer Requirements — Federal Register · Published 26 May 2026
- FCC Seeks Comment on Enhanced Know-Your-Customer Requirements — Federal Communications Commission · Proceeding page
- 50 State and Territory Attorneys General Urge Stronger KYC Rules to Fight Illegal Robocalls — National Association of Attorneys General · 28 July 2026
- Attorney General Jackley Urges Federal Government to Strengthen "Know Your Customer" Rules Against Illegal Robocalls — Office of the Attorney General, South Dakota · 28 July 2026
- Bipartisan Coalition of 49 Attorneys General Urges Federal Action on Illegal Robocalls — National Association of Attorneys General · 8 July 2026 · numbering resources proceeding
- Trades Support FCC Effort to Strengthen Know Your Customer Safeguards on Telecom Providers — Joint comment of eleven financial trade associations · 25 June 2026
- CCA Files FCC Comments on Enhanced Know-Your-Customer Requirements — Cloud Communications Alliance · 29 June 2026
- 31 CFR § 1020.220: Customer identification program requirements for banks — US Department of the Treasury · Electronic Code of Federal Regulations
- 47 CFR § 64.1200: Delivery restrictions — Federal Communications Commission · Electronic Code of Federal Regulations
Who wrote this
Tuan Nguyen — Growth · Didit
Writes about identity verification, fraud and compliance at Didit. This piece was written from the FCC's own filings in CG Docket Nos. 17-59 and 02-278 rather than from secondary coverage, because the difference between "sought comment on requiring" and "proposed to require" changes what a provider should do about it.
Last reviewed 28 July 2026 against the sources above
Related articles
- Asia is moving the cost of weak identity checks onto banks and platforms
- Six Latin American economies rewrote their identity rules in 21 months
- EU law lets five years pass before you recheck who owns a customer.
- The firms reporting the most risk to the FCA report the widest control gaps.
- A risk assessment that did not work cost one operator £4.75 million.
- Regulators are asking prediction markets about identity, not trading.