VERICODE vericode.com.au

$2,500 per call: the FCC priced identity failure now

Vericode · 3 May 2026


On Thursday the FCC voted to adopt a proposed rulemaking that puts a $2,500 base price on a single illegal call, tied back to an originating provider’s KYC failure. Proposed is the word to hold onto. This isn’t a final fine schedule landing tomorrow. It’s still a sharp signal, because the regulator is asking the market to think about caller-identity failure one call at a time.

That’s a different posture from broad supervision.

The proposed rules point upstream. Originating voice providers would be expected to verify customers at onboarding, re-verify at renewal or when traffic patterns start looking odd, capture more on high-volume callers and keep the records for years after the customer’s gone. The provider that waves the call into the system becomes part of the identity story.

That sits alongside the FCC’s earlier call-branding work. Put the two together and the direction’s plain: caller identity isn’t just something the person answering has to figure out. It’s something the originator and the display layer should help make trustworthy before the call ever rings.

Australia isn’t there. That’s not an insult, it’s a description of the architecture.

The Scams Prevention Framework goes live on 1 July with banks, telcos and digital platforms in the first wave. ACMA runs blocking programs, compliance work and the SMS Sender ID Register. Telcos are already doing serious operational graft against scam traffic. But Australia doesn’t currently have a per-call originator KYC price that says: this failed call traces back to your customer due diligence, and here’s the base forfeiture.

There are good reasons to be careful about copying the United States. The US voice market is a different animal. Its robocall problem has different scale, history and wiring. Per-call penalties can breed strange incentives if you don’t calibrate them well. And a proposal always reads cleaner in a fact sheet than it behaves in the network.

The point isn’t that Australia should import the rule. It’s that the global conversation has moved.

For years the receiver carried most of the trust burden. Did the customer answer, did the business pick up, did the bank catch the payment later, did the victim smell the scam, did a staff member challenge the caller? The FCC’s move asks a harder question, and it asks it upstream: who let this caller in with that identity posture in the first place?

That question will travel.

It’ll travel because voice scams are getting more personal and more synthetic at the same time. Blocking suspicious volume is necessary, but it doesn’t answer the branded, spoofed, high-context call. Payee verification protects the payment moment. SMS sender registration protects the message name. Platform enforcement protects part of the ad surface. The caller-originator layer is the next obvious pressure point.

Australia’s model today is broader and less per-call. Sector codes, regulatory supervision, blocking and registered sender IDs all matter, and they may be the better fit for this market. But once an overseas regulator starts putting a dollar figure on a single failed call, Australian boards and fraud teams will eventually ask what the local equivalent is.

That doesn’t mean the answer has to be a fine. It might be a code obligation, a procurement requirement, a telco standard, an attestation scheme, a verified call display, something quieter. But the comparison isn’t going away.

The FCC put a number on a single failed call. Australia hasn’t yet. Read that as a forecast, not a flaw.