A Carrier's Playbook for Investigating Customers After a Traceback
TL;DR: When a traceback confirms that your customer originated illegal traffic, the FCC expects action. You generally must terminate the relationship or block the customer's traffic. Doing nothing leaves the provider exposed, and many carriers use internal traceback thresholds to trigger termination.
We've covered the major roles in the call path and examined gateway provider obligations in detail. Now we turn to a scenario every carrier needs to handle, a traceback that points directly to its own customer.
This is different from simply identifying who handed you a suspicious call. When your customer is the source, the investigation does not end with the traceback response. The carrier must decide what action to take and document why.
This article examines what that process looks like in practice. We'll use an FCC enforcement case as a template, then examine traceback thresholds and CDR metrics. These tools can help carriers make termination decisions more consistent and less subjective.
What Does “Investigate and Take Action” Mean?
The FCC's expectation is simple in principle. Once a traceback identifies illegal traffic tied to your customer, you must investigate promptly. If the investigation confirms the activity, you must take appropriate action.
Failing to investigate can create a separate compliance problem. Your response therefore matters, even when the underlying traffic turns out to be legitimate.
1. Confirm Who Originated the Traffic
The first question is whether your customer actually originated the traffic. The traceback may reach your network without making your customer the original source.
Your customer could be the true originator, or another provider could have sent the traffic through your customer. The investigation must establish which situation applies before you decide what happens next.
2. Connect the Traceback to Your Records
The traceback gives you a useful starting point. It typically identifies the calling number, called number, and exact time of the call. Your job is to connect those details to your customer's account and traffic records. This is where reliable CDR retention becomes critical.
You can then look beyond the individual call. Related calls may reveal the same numbers, destinations, timing patterns, or traffic behavior.
3. Decide What Action Is Required
Once the investigation establishes that your customer originated the illegal traffic, the carrier must decide how to respond. The appropriate action depends on the facts, the applicable FCC requirements, and the provider's compliance procedures.
That makes investigation more than a box checking exercise. It creates the evidence needed to explain what happened, what the carrier knew, and why it took the resulting action.
A Real Case: How the FCC Handled the Urth Access Investigation
The FCC's enforcement record gives us a useful example of this process in practice. In late 2022, the Enforcement Bureau sent Urth Access LLC a cease and desist letter.
The letter concerned robocall traffic linked to what the FCC called the Student Loan Robocall Operation. It required Urth Access to investigate the traffic and take steps to mitigate it.
The timeline was tight. Urth Access had 48 hours to report its initial mitigation steps to the Bureau and the ITG. It then had 14 days to explain how it would prevent new or returning customers from repeating the same pattern.
The Terminate or Block Standard
The order also made the required outcome unusually clear. A voice service provider carrying the operation's traffic could terminate the customer relationship or block all of that customer's traffic.
Either approach could satisfy the obligation. Investigating the traffic and then taking no action could not. That distinction matters because it turns investigation into a decision point. Once the evidence confirms that your customer is responsible, the carrier must take meaningful action.
The Urth Access case therefore provides a practical template for carriers facing the same situation. Investigate quickly, document the findings, and take a clear action when the evidence warrants it.
The Three Strikes Rule Carriers Actually Use
Few carriers make a fresh judgment every time a customer generates a traceback. Most build a numeric threshold into their compliance policy instead. The industry has largely converged around a similar number.
The FTC's settlement language with one VoIP provider illustrates this approach clearly. It required termination when a customer received three or more USTelecom traceback requests or carrier complaints within 60 days. The same applied to three or more subpoenas or civil investigative demands within 12 months.
Filed Robocall Mitigation Plans show similar thinking. One carrier's published RMP states that three tracebacks within 90 days result in a permanent platform ban. The exception applies only when the carrier can establish that every example was legal.
Whether the window is 60 or 90 days, the logic remains the same. One traceback could result from a bad list, a misconfigured dialer, or an isolated mistake. Three within a short period starts to establish a pattern rather than an isolated incident.
Building Your Own Threshold
You do not need to copy either number exactly, but you do need a defined threshold. A consistent threshold protects you in two ways.
First, it gives your compliance team a clear trigger for action. Second, it creates a defensible policy if a terminated customer later disputes the decision.
The important point is consistency. A threshold only helps if your team applies it consistently across customers and documents any exceptions.
CDR Metrics That Should Trigger a Review
Waiting for a traceback before reviewing customer traffic is a reactive approach. Mature compliance programs monitor call detail records proactively, looking for patterns that often precede a traceback.
Published mitigation plans point to a consistent set of metrics worth tracking weekly. These include total call attempts, answer seizure ratio, average call duration, and the share of calls under 60 seconds.
No single metric proves that traffic is illegal. A sudden spike in attempts, falling answer rates, and more very short calls provide a stronger signal together. Taken as a pattern, these metrics can reveal automated dialing activity before a traceback arrives.
None of these metrics is proprietary or difficult to extract from a standard CDR system. The difference is whether someone reviews them on a defined schedule, rather than waiting for a complaint.
Reviewing New Accounts More Closely
New accounts deserve tighter monitoring than established customers. A new customer showing known robocall patterns presents a different risk than an established customer with years of clean traffic.
A practical approach is to review new accounts more frequently during their first 30 to 60 days. Once the customer establishes a clean and predictable traffic pattern, the review cadence can gradually decrease.
Documentation You'll Need to Show the ITG
Once your investigation is complete, the documentation matters almost as much as the investigation itself. Originating providers must explain how their robocall mitigation plans support customer identification and the detection of illegal traffic.
Record What Triggered the Review
Start by documenting why the investigation began. Record the traceback details, relevant dates, customer information, and any other facts that prompted the review. Then document what your CDR analysis found. Preserve the traffic patterns, relevant numbers, call volumes, and other evidence that shaped your decision.
Document the Customer Response
Keep a record of every relevant customer communication. Include when you contacted the customer, what you asked, and how the customer responded. Finally, record the action you took and when you took it. This creates a clear timeline from the initial concern through the final decision.
Use the ITG as Your Benchmark
A completed ITG traceback record provides a useful model for structuring your own files. The portal captures the responding carrier's status, response time, responding contact, and enrichment data.
That data can include Do Not Call Registry status, terminating line type, and STIR/SHAKEN attestation details for each hop. Your internal records do not need to match the ITG's depth exactly, but a similar structure makes future investigations faster.
Good documentation protects you in both directions. It demonstrates cooperation during an ITG review and gives you a defensible record if the customer later disputes your decision.
Terminate or Block: What Actually Satisfies the FCC's Standard
There is no universal rule that makes termination mandatory after a customer's first violation. A warning or closer monitoring may be appropriate in some cases.
Once your internal threshold is crossed, however, the options become more limited. When an investigation confirms a clear, repeated pattern, two responses can satisfy the FCC's standard, terminate the customer or block the customer's traffic.
What does not satisfy the obligation is investigating the problem and taking no action. Confirmed illegal traffic can expose carriers to the downstream consequences covered earlier, including ITG non-cooperative classification and further regulatory escalation.
Option 1: Terminate the Customer
Termination removes the customer from your network entirely. It also creates a clear record that you acted after confirming the customer's involvement in illegal traffic.
This can be the simplest approach when the relationship has become a recurring compliance risk. It prevents the same customer from generating further traffic through your network.
Termination does not guarantee that the traffic disappears elsewhere. The customer may have relationships with other providers, but your network is no longer carrying that traffic.
Option 2: Block the Customer's Traffic
Blocking takes a different approach. Instead of closing the account, you prevent the customer's traffic from reaching the network.
Some carriers may prefer this option after a serious first offense. It stops the immediate traffic while leaving open the possibility of restoring service after the customer demonstrates that the underlying problem has been fixed.
The important point is that both approaches can satisfy the FCC's standard. The decision should follow your documented compliance policy and the facts established during the investigation.
What's Next in This Series
A traceback should never be the moment your compliance process begins. By then, you need to know who owns the investigation, which records to pull, what thresholds apply, and how the final decision gets documented.
The difference between a controlled response and a compliance scramble is preparation. The carriers best positioned to handle repeated scrutiny are not necessarily the ones that react fastest, but those that already have a process in place.
The next article focuses on building that process. We'll cover designated compliance contacts, CDR retention, investigation workflows, and response templates that turn a traceback from an urgent disruption into a routine compliance task.

















