A Carrier's Playbook for Investigating Customers After a Traceback

TL;DR: When a traceback confirms that your customer originated illegal traffic, the FCC expects action. You generally must terminate the relationship or block the customer's traffic. Doing nothing leaves the provider exposed, and many carriers use internal traceback thresholds to trigger termination.

We've covered the major roles in the call path and examined gateway provider obligations in detail. Now we turn to a scenario every carrier needs to handle, a traceback that points directly to its own customer.

This is different from simply identifying who handed you a suspicious call. When your customer is the source, the investigation does not end with the traceback response. The carrier must decide what action to take and document why.

This article examines what that process looks like in practice. We'll use an FCC enforcement case as a template, then examine traceback thresholds and CDR metrics. These tools can help carriers make termination decisions more consistent and less subjective.

What Does “Investigate and Take Action” Mean?

The FCC's expectation is simple in principle. Once a traceback identifies illegal traffic tied to your customer, you must investigate promptly. If the investigation confirms the activity, you must take appropriate action.

Failing to investigate can create a separate compliance problem. Your response therefore matters, even when the underlying traffic turns out to be legitimate.

1. Confirm Who Originated the Traffic

The first question is whether your customer actually originated the traffic. The traceback may reach your network without making your customer the original source.

Your customer could be the true originator, or another provider could have sent the traffic through your customer. The investigation must establish which situation applies before you decide what happens next.

2. Connect the Traceback to Your Records

The traceback gives you a useful starting point. It typically identifies the calling number, called number, and exact time of the call. Your job is to connect those details to your customer's account and traffic records. This is where reliable CDR retention becomes critical.

You can then look beyond the individual call. Related calls may reveal the same numbers, destinations, timing patterns, or traffic behavior.

3. Decide What Action Is Required

Once the investigation establishes that your customer originated the illegal traffic, the carrier must decide how to respond. The appropriate action depends on the facts, the applicable FCC requirements, and the provider's compliance procedures.

That makes investigation more than a box checking exercise. It creates the evidence needed to explain what happened, what the carrier knew, and why it took the resulting action.

Traceback Investigation Workflow
Investigate first. Act on evidence.
01
Confirm origin
Did your customer actually originate the traffic, or did another provider route it through them?
Customer → Origin?
02
Match the records
Use calling number, called number, and timestamp to connect the traceback to the customer's account and CDRs.
Traceback → CDR → Account
03
Take action
If the evidence confirms illegal activity, apply the response required by the facts and your compliance procedures.
Evidence → Decision → Action
DOCUMENT THE INVESTIGATION
Why the investigation matters: even when traffic turns out to be legitimate, a documented investigation shows what the carrier checked, what it found, and why it reached its conclusion.

A Real Case: How the FCC Handled the Urth Access Investigation

The FCC's enforcement record gives us a useful example of this process in practice. In late 2022, the Enforcement Bureau sent Urth Access LLC a cease and desist letter.

The letter concerned robocall traffic linked to what the FCC called the Student Loan Robocall Operation. It required Urth Access to investigate the traffic and take steps to mitigate it.

The timeline was tight. Urth Access had 48 hours to report its initial mitigation steps to the Bureau and the ITG. It then had 14 days to explain how it would prevent new or returning customers from repeating the same pattern.

The Terminate or Block Standard

The order also made the required outcome unusually clear. A voice service provider carrying the operation's traffic could terminate the customer relationship or block all of that customer's traffic.

Either approach could satisfy the obligation. Investigating the traffic and then taking no action could not. That distinction matters because it turns investigation into a decision point. Once the evidence confirms that your customer is responsible, the carrier must take meaningful action.

The Urth Access case therefore provides a practical template for carriers facing the same situation. Investigate quickly, document the findings, and take a clear action when the evidence warrants it.

The Terminate or Block Standard
Investigation must lead to a meaningful outcome
Evidence confirms illegal activity
Decision point reached
The carrier must move beyond investigation and take meaningful action.
Terminate
End the customer relationship
OR
Block
Stop the customer's traffic
The critical distinction: investigate and take no action is not equivalent to investigate and resolve.
Investigate quickly
Document findings
Take clear action

The Three Strikes Rule Carriers Actually Use

Few carriers make a fresh judgment every time a customer generates a traceback. Most build a numeric threshold into their compliance policy instead. The industry has largely converged around a similar number.

The FTC's settlement language with one VoIP provider illustrates this approach clearly. It required termination when a customer received three or more USTelecom traceback requests or carrier complaints within 60 days. The same applied to three or more subpoenas or civil investigative demands within 12 months.

Filed Robocall Mitigation Plans show similar thinking. One carrier's published RMP states that three tracebacks within 90 days result in a permanent platform ban. The exception applies only when the carrier can establish that every example was legal.

Whether the window is 60 or 90 days, the logic remains the same. One traceback could result from a bad list, a misconfigured dialer, or an isolated mistake. Three within a short period starts to establish a pattern rather than an isolated incident.

Building Your Own Threshold

You do not need to copy either number exactly, but you do need a defined threshold. A consistent threshold protects you in two ways.

First, it gives your compliance team a clear trigger for action. Second, it creates a defensible policy if a terminated customer later disputes the decision.

The important point is consistency. A threshold only helps if your team applies it consistently across customers and documents any exceptions.

Threshold Guide
Turn repeated tracebacks into a defined compliance trigger
The exact number can vary. The important part is having a documented rule before the pattern appears.
1 traceback
Investigate
Could be isolated. Match the call, investigate the source, and document the outcome.
2 tracebacks
Escalate
Review the customer's broader traffic pattern and increase compliance attention.
3+ tracebacks
Trigger action
A recurring pattern may activate your defined restriction, termination, or ban policy.
Build your own threshold
Number of events
+
Time window
+
Required action
Example policy models
3 tracebacks / 60 days
3 tracebacks / 90 days
Two controls make it defensible
Apply the rule consistently
Document legitimate exceptions
The objective is not the number itself. It is a predictable response to a repeated pattern.

CDR Metrics That Should Trigger a Review

Waiting for a traceback before reviewing customer traffic is a reactive approach. Mature compliance programs monitor call detail records proactively, looking for patterns that often precede a traceback.

Published mitigation plans point to a consistent set of metrics worth tracking weekly. These include total call attempts, answer seizure ratio, average call duration, and the share of calls under 60 seconds.

No single metric proves that traffic is illegal. A sudden spike in attempts, falling answer rates, and more very short calls provide a stronger signal together. Taken as a pattern, these metrics can reveal automated dialing activity before a traceback arrives.

None of these metrics is proprietary or difficult to extract from a standard CDR system. The difference is whether someone reviews them on a defined schedule, rather than waiting for a complaint.

CDR Review Threshold Guide
One metric is a signal. Several moving together are a trigger.
Use weekly CDR reviews to identify changes before a traceback arrives.
Call attempts
↑ Spike
Review sudden increases against the customer's normal baseline.
Answer seizure ratio
↓ Drop
A falling answer rate can indicate increasingly inefficient or automated traffic.
Average duration
↓ Shift
A change in typical duration can reveal a different calling pattern.
Calls under 60s
↑ Share
A growing share of very short calls deserves closer review.
Review trigger
Attempts ↑
+
ASR ↓
+
Short calls ↑
=
Investigate
Important: no single metric proves illegal traffic. Use changes across multiple metrics to decide when a customer deserves investigation.
WEEKLY REVIEW

Reviewing New Accounts More Closely

New accounts deserve tighter monitoring than established customers. A new customer showing known robocall patterns presents a different risk than an established customer with years of clean traffic.

A practical approach is to review new accounts more frequently during their first 30 to 60 days. Once the customer establishes a clean and predictable traffic pattern, the review cadence can gradually decrease.

Documentation You'll Need to Show the ITG

Once your investigation is complete, the documentation matters almost as much as the investigation itself. Originating providers must explain how their robocall mitigation plans support customer identification and the detection of illegal traffic.

Record What Triggered the Review

Start by documenting why the investigation began. Record the traceback details, relevant dates, customer information, and any other facts that prompted the review. Then document what your CDR analysis found. Preserve the traffic patterns, relevant numbers, call volumes, and other evidence that shaped your decision.

Document the Customer Response

Keep a record of every relevant customer communication. Include when you contacted the customer, what you asked, and how the customer responded. Finally, record the action you took and when you took it. This creates a clear timeline from the initial concern through the final decision.

Use the ITG as Your Benchmark

A completed ITG traceback record provides a useful model for structuring your own files. The portal captures the responding carrier's status, response time, responding contact, and enrichment data.

That data can include Do Not Call Registry status, terminating line type, and STIR/SHAKEN attestation details for each hop. Your internal records do not need to match the ITG's depth exactly, but a similar structure makes future investigations faster.

Good documentation protects you in both directions. It demonstrates cooperation during an ITG review and gives you a defensible record if the customer later disputes your decision.

Investigation Record
Build the file as a chain of evidence
A defensible record should let another person reconstruct what happened without repeating the investigation.
01
Trigger
Traceback, dates, customer, reason for review
02
Evidence
CDRs, numbers, volumes, patterns, analysis
03
Response
Customer contact, questions, responses, timestamps
04
Action
Decision, action taken, date and rationale
Use the ITG record as your structural benchmark
Response status
Response time
Contact
Enrichment data
Why this structure matters: it connects the trigger, evidence, customer response, and final action into one chronological record that can demonstrate cooperation and support the carrier's decision if challenged.

Terminate or Block: What Actually Satisfies the FCC's Standard

There is no universal rule that makes termination mandatory after a customer's first violation. A warning or closer monitoring may be appropriate in some cases.

Once your internal threshold is crossed, however, the options become more limited. When an investigation confirms a clear, repeated pattern, two responses can satisfy the FCC's standard, terminate the customer or block the customer's traffic.

What does not satisfy the obligation is investigating the problem and taking no action. Confirmed illegal traffic can expose carriers to the downstream consequences covered earlier, including ITG non-cooperative classification and further regulatory escalation.

Option 1: Terminate the Customer

Termination removes the customer from your network entirely. It also creates a clear record that you acted after confirming the customer's involvement in illegal traffic.

This can be the simplest approach when the relationship has become a recurring compliance risk. It prevents the same customer from generating further traffic through your network.

Termination does not guarantee that the traffic disappears elsewhere. The customer may have relationships with other providers, but your network is no longer carrying that traffic.

Option 2: Block the Customer's Traffic

Blocking takes a different approach. Instead of closing the account, you prevent the customer's traffic from reaching the network.

Some carriers may prefer this option after a serious first offense. It stops the immediate traffic while leaving open the possibility of restoring service after the customer demonstrates that the underlying problem has been fixed.

The important point is that both approaches can satisfy the FCC's standard. The decision should follow your documented compliance policy and the facts established during the investigation.

After a Confirmed Pattern
Two paths to meaningful action
Once the evidence and your compliance threshold require intervention, the carrier needs a clear operational response.
Option 01
Terminate the Customer
Relationship ends
Remove the customer from your network entirely and stop carrying future traffic for the account.
Best suited when
The relationship has become a recurring compliance risk and continued service is no longer defensible.
Operational effect: Customer → Off network
Option 02
Block the Traffic
Traffic stops
Prevent the customer's traffic from reaching the network without necessarily closing the account itself.
Best suited when
Immediate traffic suppression is required while the relationship remains subject to remediation or further review.
Operational effect: Customer → Traffic blocked
Both represent affirmative action
×
The third option is the problem
Investigate → confirm a repeated illegal traffic pattern → take no meaningful action.
Decision rule: let the investigation establish the facts, then let your documented compliance policy determine which action follows.

What's Next in This Series

A traceback should never be the moment your compliance process begins. By then, you need to know who owns the investigation, which records to pull, what thresholds apply, and how the final decision gets documented.

The difference between a controlled response and a compliance scramble is preparation. The carriers best positioned to handle repeated scrutiny are not necessarily the ones that react fastest, but those that already have a process in place.

The next article focuses on building that process. We'll cover designated compliance contacts, CDR retention, investigation workflows, and response templates that turn a traceback from an urgent disruption into a routine compliance task.