Wholesale VoIP Carrier Roles and What Each One Owes the FCC

We've now covered what a traceback is, who can request one, what the request contains, and how tight the response clock is. Now it's time to get specific about your business.

The FCC's rules don't treat every voice service provider identically. Your obligations depend heavily on your role in the call path for any given call. A single wholesale VoIP carrier can play different roles on different calls throughout a single day.

This article breaks down the four roles carriers can occupy i.e. originating, intermediate, gateway, and terminating, and what each one is specifically obligated to do. You can then identify which bucket applies the next time a traceback lands on your desk.

Understanding this distinction matters for more than just your traceback response. It shapes your compliance program and your customer vetting process.

As we will see toward the end of this article, it also determines how quickly you can catch problems before they generate a formal request in the first place.

The Four Roles in the Call Path, Defined

Every call that crosses the US telephone network passes through a chain of providers. Each provider in that chain occupies one of four roles relative to that specific call.

The originating provider is the one that first puts the call onto the network. Typically the carrier who serves the customer who placed the call. The terminating provider is the one that delivers the call to its final destination. They’re the carrier serving the customer who received it. Everything in between falls into intermediate or gateway categories, depending on where the traffic came from.

The Call Path
Four roles. One end-to-end chain.
A provider's role is determined by where it sits in the path of that specific call.
Originating
Puts the call
onto the network
Gateway
Brings foreign
traffic into the U.S.
Intermediate
Receives and
forwards the call
Terminating
Delivers the call
to the recipient
The key distinction
Originating / terminating
Defined by the endpoints
Gateway / intermediate
Defined by the traffic's position
Think about the role for this call, not the provider in isolation.
The same carrier can occupy different roles on different calls.

How to Tell Which Role Applies to a Specific Call

Here's the practical test. Ask where the call entered your network from, and where it left to. If the call originated with your own customer, you're the originating provider for that call. If you delivered it to your own customer's handset or endpoint, you're the terminating provider.

If you received it from another carrier and handed it to another carrier, you're intermediate. However, if that traffic crossed an international boundary onto the US network through you, you're a gateway provider.

Call-by-Call Role Test
Follow the call. The role reveals itself.
Your position is determined by the call's entry point, exit point, and international boundary.
Question 01
Where did the call come from?
Your own customer → Originating
Another carrier → Intermediate or Gateway
Question 02
Where did the call go next?
Your own endpoint → Terminating
Another carrier → Intermediate or Gateway
The gateway exception
Foreign traffic
Your network
U.S. network
If the traffic crosses the international boundary onto the U.S. network through you, you are the gateway for that call.
One carrier · three calls · three roles
CALL A
Originating
CALL B
Intermediate
CALL C
Terminating
So the right question is not
“What kind of carrier are we?”
It is
“What role did we play in this call?”

The same carrier can be originating on one call, intermediate on the next, and terminating on a third, all within the same hour. Your obligations are evaluated call by call, not role by role for your business as a whole.

This matters practically because it means you can't set a single company-wide compliance posture and assume it covers every traceback you'll ever receive.

A carrier that primarily operates as a wholesale transit provider mostly deals with intermediate obligations. However, it still needs a process for the occasional call where it happens to be the terminating leg, delivering directly to a retail customer's endpoint.

Originating Provider Obligations

As the originating provider, you carry the heaviest burden for preventing illegal traffic from entering the network in the first place. As you're the one with a direct relationship to the customer actually placing the calls.

Originating providers are required to know their customers. You are to take affirmative, effective measures to prevent new and renewing customers from originating illegal calls.

This isn't a passive requirement. It means actual vetting at onboarding and ongoing monitoring of call patterns. You must exhibit willingness to act when a customer's traffic looks like a robocall campaign rather than legitimate business communication.

For carriers offering wholesale origination services, this obligation can feel at odds with the speed and ease of onboarding that competitive markets demand. New customers want to start sending traffic quickly, and heavy handed vetting can feel like friction.

The regulatory reality, though, is that this friction is exactly what the FCC expects. Carriers that skip it are the ones most likely to show up repeatedly as the originating network in ITG tracebacks.

Originating Provider Control Model
The obligation starts before the first call
PREVENT → MONITOR → ACT
01 · Onboarding
Know the customer
Vetting must happen before traffic is allowed to establish a pattern on the network.
Customer identityBusiness purpose
02 · Monitoring
Watch the traffic
Customer approval at signup is not the end of the control. Call behaviour must remain consistent with legitimate use.
VolumePatterns
03 · Intervention
Act on suspicious traffic
When traffic resembles an illegal robocall campaign, the provider must be willing to investigate and take effective action.
InvestigateRestrict
Wholesale Origination Tension
Fast onboarding ≠ minimal vetting
Market pressureRegulatory control
The operational friction created by customer vetting is not a regulatory loophole. For an originating carrier, that friction is part of the prevention control.
CONTROL WORKS
Vetting + monitoring + intervention reduce the chance that your network becomes the recurring originating hop in traceback investigations.
CONTROL FAILS
Easy onboarding without meaningful controls can turn repeated suspicious traffic into a traceable pattern associated with your network.
For originating providers, the strongest compliance posture is a documented control loop: know → observe → act → reassess.

Know Your Customer, in Practice

This obligation is often described using the same shorthand as the gateway provider's "know your upstream provider" rule, just aimed in the opposite direction.

As an originating provider, you are expected to understand who you are actually doing business with and verify identifying information at onboarding. You must also watch for red flags like sudden spikes in outbound volume, short call durations consistent with robocall patterns, or a high proportion of calls that never connect.

When a traceback identifies your network as the origination point, the obligation doesn't stop at answering the request. The FCC has made clear that originating providers are also expected to take action against the customer responsible. We'll cover this topic in much greater depth later in this series.

It's worth pointing out that "know your customer" obligations aren't static either. The FCC has signaled ongoing interest in tightening these requirements further. Recent proposals aim at making customer vetting more prescriptive rather than leaving carriers to define "reasonable" measures on their own.

Building a genuinely robust onboarding and monitoring process now, positions your business well ahead of wherever these requirements land next.

Know Your Customer · Practical Control Loop
Customer knowledge is a lifecycle, not a signup form
ONBOARD → OBSERVE → ACT
01
Identify
Verify who the customer is and understand the business purpose behind the traffic.
02
Baseline
Establish what normal calling behaviour looks like for that customer.
03
Detect
Compare live traffic against expected behaviour and investigate material anomalies.
04
Intervene
Take appropriate action when evidence indicates the customer is generating problematic traffic.
What monitoring can reveal
Sudden volume spike
Outbound volume changes sharply from the customer's established baseline.
Very short calls
Call durations cluster at unusually short intervals consistent with automated campaigns.
Low connection rate
A large share of attempts fail to connect or otherwise show unusual completion patterns.
Traceback finding
“Your network originated the call.”
The investigation moves from routing evidence to customer accountability. Answering the traceback is only one part of the originating provider's responsibility.
Why build now?
Prescriptive rules may increase.
A documented, repeatable customer-control process creates a stronger foundation than a policy built only after requirements become more specific.
CORE PRINCIPLE
A customer is not “known” simply because their identity was verified once. The stronger control is continuous: know who they are → know how they normally call → recognise when behaviour changes → act when it matters.

Intermediate Provider Obligations

Intermediate providers sit in the middle of the call path, receiving traffic from one carrier and passing it to another. They do so without directly serving either the originating customer or the terminating customer.

It's tempting to assume this position carries lighter obligations. You're not the one who signed up the customer and you're not the one delivering the final call. However, that assumption is only partly correct.

Intermediate providers still carry the full traceback response obligation. You still have to respond within the 24 hour window, and are still expected to cooperate fully when the ITG comes asking who handed them a specific call.

Intermediate carriers often carry high volumes of transit traffic from multiple upstream sources. This position can make record keeping the single most important operational habit for this role.

Without solid CDR retention and fast lookup capability, an intermediate provider can find itself unable to answer a traceback quickly. Not because it's unwilling to cooperate, but because its own internal systems weren't built to surface the answer fast enough.

Intermediate providers who repeatedly show up as unresponsive links in traceback chains face the same non-cooperative classification and downstream consequences as any other provider. This applies regardless of the fact that they never directly touched the originating customer or the terminating consumer.

Volume is not a valid excuse in the eyes of the FCC or the ITG. Carriers handling large transit volumes should treat that as a reason to invest more in fast lookup systems, not less.

Why "We Just Pass Traffic Through" Isn't a Free Pass

Where intermediate providers do have somewhat narrower obligations is around proactive vetting. You're not required to know your intermediate counterparty's own customers the way an originating provider has to know its own.

But you are required to identify who you received the traffic from, accurately and quickly, every time you're asked.

Intermediate Provider Control Model
Your role is not to know the customer. It is to know the handoff.
TRANSIT ≠ EXEMPTION
Upstream
Carrier A
Hands traffic to you
You
Intermediate Provider
Receives → records → forwards
Downstream
Carrier C
Receives traffic from you
Traceback asks
Who handed you this call?
Your evidence
CDRs + routing records
Response window
24 hours
What you are expected to know
Which upstream carrier delivered the call
When the handoff occurred
Which downstream carrier received it
How to retrieve those facts quickly
What is narrower for your role
You do not own the originating customer relationship
You do not own the terminating consumer relationship
You are not expected to vet every customer behind your counterparty
You still must identify your immediate upstream handoff
The operational bottleneck
1
Traceback arrives
2
Find matching CDR
3
Identify upstream
4
Respond within 24h
The intermediate-provider test
You may not know where the call originally began. You must know who handed it to you. For a high-volume transit carrier, fast and reliable record lookup is therefore a core compliance control, not merely an operational convenience.

Gateway Provider Obligations

Gateway providers occupy a specific and heavily regulated position: they're the entry point for foreign originated traffic coming onto the US network. Because foreign-originated illegal robocall traffic has historically been a major fraud vector, the FCC has layered additional obligations onto this role. These specific obligations do not apply to purely domestic intermediate providers.

Gateway providers must apply STIR/SHAKEN caller ID authentication to unauthenticated, foreign-originated calls carrying US numbers and respond to traceback requests within 24 hours. They are also required to block calls once notified that they are conduits for illegal traffic and implement what the FCC calls know-your-upstream-provider procedures.

The FCC originally piloted several of these requirements, including the 24-hour traceback response window, specifically on gateway providers. These were later extended to the rest of the industry, as we covered in the last article. That history is not a coincidence.

Foreign originated traffic entering the US network has consistently been treated as the highest risk entry point for illegal robocalling. Hence, gateway providers continue to carry obligations beyond what domestic-only carriers face.

Why This Role Carries the Heaviest Compliance Burden

The final requirement, knowing your upstream provider, deserves particular attention. We will cover this topic in depth in a future article.

In simple terms, gateway providers must take reasonable, effective steps to assess their immediate upstream foreign provider. They must ensure the provider is not using the gateway to carry illegal traffic onto US networks.

Gateway providers also face specific blocking obligations after receiving proper FCC Enforcement Bureau notification. Once notified, providers have a defined timeframe of at least 14 days to investigate and comply. Failure to act can eventually lead to an order requiring downstream providers to block all gateway traffic.

That outcome is effectively equivalent to losing access to the US network.

Carriers entering the gateway provider space should plan for substantial operational investment from the beginning. This applies whether they expand an existing wholesale business or launch new international services.

Compliance should be built into international termination and origination operations from day one. Retrofitting compliance after regulators identify problems is considerably harder and more expensive. Building the necessary controls early provides a stronger foundation for sustainable gateway operations.

Gateway Provider Control Model
The gateway is the regulatory control point for foreign traffic
HIGH-RISK ENTRY POINT
Foreign origin
Upstream provider
Traffic originates outside the US network.
Gateway control point
US entry
AUTHENTICATEASSESSBLOCK
US network
Downstream carriers
Traffic continues toward US destinations.
Gateway-specific control stack
01
Caller ID authentication
Apply required authentication treatment to relevant foreign-originated calls.
02
Traceback response
Maintain the operational capability to respond within 24 hours.
03
Upstream assessment
Know and assess the immediate foreign provider supplying the traffic.
04
Blocking response
Act when properly notified that traffic is associated with illegal activity.
Know your upstream provider
The gateway's version of customer diligence points upstream. The focus is the immediate foreign provider whose traffic is being introduced into the US network.
IdentifyAssessControl
Notification → enforcement path
FCC notificationInvestigateComply
Failure to respond can escalate into broader blocking consequences affecting continued access to US networks.
Why build the controls before launch?
Gateway compliance touches routing, authentication, upstream due diligence, traceback operations, monitoring and blocking. These controls are significantly easier to integrate into an international operation from day one than to retrofit after regulatory scrutiny begins.
The gateway is more than a transit point. It is the control boundary between foreign-originated traffic and the US network.

Terminating Provider Obligations

The terminating provider is the final carrier in the chain, delivering the call directly to the consumer's phone. This is also where many tracebacks begin.

Terminating carriers typically receive the initial consumer complaint, either directly or through the FTC and FCC complaint databases. That complaint can trigger the traceback process.

Terminating providers carry the same 24-hour response obligation as other providers in the call path. They are also typically contacted first when a traceback begins.

Their position makes terminating providers the starting point for tracing the call backward through the network. This gives them a strong incentive to respond quickly and accurately.

Because of this starting position, terminating providers often develop highly mature traceback response processes. A delayed or inaccurate initial response can slow the entire investigation behind it.

Traceback Starting Point
The terminating provider sees the problem first
Consumer
Complaint
Spam or scam call reported directly or through complaint channels.
Terminating provider
Traceback begins here
Identify the reported call, locate the upstream handoff and return the next link.
Network
Trace backward
Follow the call through intermediate providers toward its source.
01 · Receive
Consumer signal
Complaint creates the investigative starting signal.
02 · Match
Call record
Reported number and time are matched against network records.
03 · Continue
Upstream handoff
The response gives the next provider needed to continue the traceback.
Terminating provider advantage: the carrier closest to the consumer often has the earliest visibility into the complaint pattern and the first opportunity to make the traceback chain move.

What Happens After You Deliver the Call

Traceback responses are only one part of a terminating provider's compliance responsibilities. Providers increasingly face call blocking and labeling obligations under the broader robocall mitigation framework.

These requirements are separate from the specific traceback rules discussed above. Delivering illegal traffic at scale still creates compliance responsibilities, even when the provider did not originate it.

Terminating providers also have a unique opportunity to identify suspicious patterns before they trigger formal tracebacks. They often see repeated complaints involving specific numbers, campaigns, or traffic sources.

Strong monitoring can therefore help carriers identify and block problematic traffic before an ITG request arrives. This proactive approach can reduce both regulatory exposure and operational disruption.

There is also a practical business reason to maintain effective filtering. Consumers increasingly rely on third-party tools that automatically label or block suspected spam and scam calls.

These tools often use aggregated complaint data to assess calling reputation. Weak filtering can therefore associate a carrier's network with poor spam scores.

Those scores can affect legitimate call completion rates for retail customers. The consequences can extend beyond regulatory scrutiny into customer experience and commercial performance.

Terminating Provider Risk Loop
Filtering is both a compliance control and a business control
PROACTIVE CONTROL
01
Traffic arrives
Calls reach the terminating network from multiple traffic sources.
02
Patterns emerge
Complaints, numbers, campaigns and traffic behaviour can reveal recurring signals.
03
Filter & block
Effective controls can stop or reduce problematic traffic before it becomes a traceback case.
04
Protect reputation
Better filtering can reduce unwanted traffic and help protect legitimate call completion.
Weak filtering
More unwanted traffic reaches consumers
Complaints can accumulate, increasing the likelihood of investigation and poor calling reputation.
Strong filtering
Less unwanted traffic reaches consumers
Proactive controls can reduce complaint pressure while protecting the experience of legitimate callers.
The commercial consequence
Poor filteringMore complaintsPoor spam reputationPotential impact on legitimate calls
Strategic takeaway: terminating providers should not wait for an ITG traceback to discover suspicious traffic. The same visibility that supports traceback response can be used earlier to identify, filter and manage problematic calling patterns.

What's Next in This Series

You now understand how obligations vary according to your role in a given call path. The next article examines gateway providers and their heightened regulatory responsibilities.

We will focus specifically on the know your upstream provider requirement. The article will explain how documentation and monitoring work in practice, beyond the rule's wording.

We will also examine what happens when a traceback points directly at your own customer. That scenario creates additional obligations, regardless of your role in the call path.