Why Verified Businesses Keep Starting Over, and How CTM’s Sr. Director of Carrier Relations and Regulatory Is Rethinking Accountability In Telecom
A Q&A with Rick Ruth, Sr. Director of Carrier Relations and Regulatory at CTM and author of “When Trust Collided: The Rise of Conditional Trust in a Fragmented Telecom World”
Rick Ruth brings a rare mix of field experience and strategic insight to telecom policy. He is the author of When Trust Collided: The Rise of Conditional Trust in a Fragmented Telecom World, which examines how trust between carriers, platforms, businesses, and consumers has eroded and been rebuilt on new, conditional terms. His background spans product management, sales, marketing, carrier relations, and telecommunications, giving him a practical view of how regulation actually lands on the businesses trying to reach their customers. He has worked with the Department of Homeland Security (DHS), the Federal Emergency Management Agency (FEMA), the Commercial Mobile Alert System (CAP) Forum, the Alliance for Telecommunications Industry Solutions (ATIS), the Telecommunications Industry Association (TIA), and Wireless Local Number Portability initiatives; cross-functional work where policy, operations, technology, compliance, and customer impact all converge. That experience gave him a nuanced view of how national communications policy travels from concept to implementation, and how those decisions ripple out to carriers, platforms, enterprises, small businesses, and consumers.
Rick has deep knowledge of Federal Communications Commission (FCC) telecom regulations and is a veteran negotiator, well-versed in reducing vendor costs, improving operational efficiency, and driving product advancements. He holds a degree in Business Administration from Wright State University and the University of Cincinnati. That regulatory expertise recently earned him an invitation to join REACH’s Government Affairs Advisory Council, where he contributes to comments on mobile telecommunications issues that could shape policy discussions at both the FCC and congressional levels; work that connects directly to the proposal he lays out below.
We sat down with Rick to talk through an idea he’s been developing: the Business Passport.
1. The FCC is focused on number availability, number rotation, call blocking, and call labeling. You’ve suggested the industry may be aiming at the wrong target. What do you mean by that?
I want to be clear upfront: I think the FCC is right to focus on illegal robocalls, number misuse, blocking, and labeling. Those are real problems. Consumers need protection.
My concern is that number movement by itself is an imperfect signal.
A number changed. A business used a pool of numbers. A provider changed. A vendor got added. From the outside, that can look suspicious. And sometimes it is suspicious. But sometimes it is just normal business activity.
Businesses have different locations, brands, departments, campaigns, and call flows. They use numbers for routing, tracking, customer service, local presence, and business continuity. Sometimes they change numbers because a number was mislabeled and they are trying to keep a working communication path open with customers who actually expect the call.
So to me, the question should not only be, “Did the number change?” or “How many numbers are being used?”
The better question is, “Can we tie that number back to a real business that is verified, authorized, and accountable?”
That is where I think the target needs to be: not just the number, but the responsible party behind the number.
2. When a legitimate business changes numbers, switches providers, or adds vendors, that can look suspicious from the outside. How should the industry interpret that kind of behavior?
Carefully. I don’t think every change should be treated as bad behavior. Businesses change things all the time. They switch providers. They add CPaaS platforms. They bring in call centers. They change texting vendors. They open new markets. They add brands. They acquire companies. They change numbers because one got mislabeled.
That is normal. At the same time, bad actors move around too. They hop providers. They burn through numbers. They hide behind layers. So I would not say change itself is the issue. Unexplained change is the issue. Untraceable change is the issue.
If a business can explain who it is, why it is calling, what numbers it is using, who its provider is, who its vendor is, and who to contact if there is a problem, that is very different from someone using fake information or disappearing when questions get asked.
That is the distinction I think matters.
The FCC and the industry should be able to look at number movement and ask: is this normal business activity tied to an accountable party, or is this an attempt to avoid detection? That is a better question than treating all movement the same.
3. Let’s get to the core idea. What is the Business Passport, and what problem is it built to solve?
The Business Passport is a concept. It is not me saying everyone needs another product, another database, or another compliance box to check.
The idea is pretty simple: a business should not have to prove the same basic identity information over and over again every time it changes providers, adds a vendor, or uses a different communication channel.
Today, a business may get verified for voice, then texting, then branded calling, then Rich Call Data. Then it switches providers or adds a platform and has to start a lot of that over again.
That creates friction for the business, but also for everyone else. Providers are reviewing the same information. Analytics companies may not have the full context. Traceback partners may have to work through layers to find the responsible party.
A lot of people are asking the same basic questions: Who is behind this traffic? Are they allowed to use these numbers? What is the use case? Who is responsible if something goes wrong?
The Business Passport idea asks whether some of that verified information can move with the business. Not as a free pass. Not as a way around the rules. Not as permission to call anyone. Just as a cleaner way to carry identity, number authorization, vendor relationships, use cases, and contact information across the industry.
And like a normal passport, it should not last forever. It should need to be renewed or rechecked after some period of time, or when something important changes. I’m not saying I have the final structure figured out. I’m saying there is a real problem here, and this may be a practical way to start solving it.
4. What kind of information would a Business Passport actually organize and carry with the business?
It would organize information that people are already asking for.
Who is the legal business? What brands or DBAs does it use? What domains are tied to it? What numbers is it authorized to use? What providers or platforms are acting on its behalf? What are the use cases? Who handles compliance? Who handles traceback?
It could also show whether the information is current. Is the business verified? Does something need to be updated? Is something under review? Has something expired? Was something suspended or revoked?
If a vendor is involved, that relationship could be reflected too. That could include a CPaaS provider, contact-center vendor, messaging provider, branded-calling partner, or offshore vendor where relevant.
But I want to be clear: I do not think this should be a public database where everyone sees everything. That would create its own problems.
Different parties need different levels of information. A regulator may need one view. A traceback partner may need another. A provider may need another. An analytics company may only need enough to understand whether the business and number relationship is real.
The point is not to expose everything. The point is to get the right information to the right party when it actually matters. Privacy, confidentiality, and access control would have to be part of the discussion from the beginning.
5. How does the Business Passport relate to STIR/SHAKEN? Since STIR/SHAKEN verifies that a call really came from the number displayed but doesn’t establish who stands behind the calling business or whether they’re accountable for how they operate, is the Passport meant to replace it or fill a different gap?
It fills a different gap. STIR/SHAKEN is important. I’m not trying to replace it.
But STIR/SHAKEN does not answer every question. It helps with authentication and attestation. It does not always tell you who the business really is, what brand is behind the call, what vendor is involved, what the call is for, or who is responsible if something goes wrong. That is where I think the Passport idea could help.
STIR/SHAKEN helps answer, “Was this call signed?”
The Passport helps answer, “Who is standing behind this communication?” Those are connected, but they are not the same thing.
If we can connect business identity, number authorization, provider relationships, and use-case information, then STIR/SHAKEN becomes more useful too. So I would not call it a replacement. I would call it a way to add the accountability piece that the current systems do not always carry.
6. Where do KYC and KYB fit in? How do you make verification stronger for catching bad actors without making it harder for legitimate businesses?
KYC and KYB matter. I’m not arguing against them. I’m saying we should make them work better.
If a business is hard to verify, high volume, using unclear vendor relationships, not responding to traceback, or showing suspicious patterns, then yes, ask more questions. Put more scrutiny there.
But if a business is verified, transparent, and cooperative, it should not have to start from zero every time it changes a provider. I don’t see that as lighter verification. I see it as smarter verification.
The point is to make good information reusable and keep it current. If something changes, update it. If something looks wrong, review it. If abuse is confirmed, restrict it or revoke it. That is important. The Passport should not be “verify once and forget it.” That would be a mistake.
It should be reusable, but it cannot be stale. It needs to be renewed, updated when things change, and pulled back if something goes wrong. That is how you reduce burden for legitimate businesses without creating a loophole for bad actors.
7. Offshore traffic comes up a lot in these conversations. How should the industry think about it without painting every offshore operation as abuse?
I think we have to be careful here. Offshore does not automatically mean bad. Plenty of legitimate businesses use global operations. Customer support, technical support, scheduling, healthcare coordination, travel, financial services, and back-office work can all involve offshore teams.
But there is also abusive traffic that comes through offshore paths, and sometimes those paths are hard to trace. So I don’t really care where the call center sits as much as I care whether someone is accountable for the traffic.
If a verified business uses an offshore vendor, maybe that relationship should be visible in a practical way. Who is the business? Who is the vendor? What is the use case? Who is responsible? Who responds to traceback? That would help separate legitimate global operations from anonymous or evasive traffic.
This is not about giving offshore operations special treatment. It is not about protecting offshore abuse. It is about making sure legitimate operations are accountable and bad actors cannot hide behind geography.
Offshore is not automatically the problem. Lack of accountability is the problem.
8. When a lawful call gets labeled “Spam Likely” or “Scam Likely,” what should the correction path look like?
There needs to be a practical way to fix it. I understand why labels exist. Carriers and analytics providers are trying to protect consumers. That matters.
But lawful businesses also need a fair process when the label is wrong.
If a business can show who it is, what numbers it is authorized to use, what the use case is, and why the consumer is being contacted, there should be a way to review that and correct it. And it should not be pay-to-play.
A business should not have to buy a premium branded-calling product just to fix an inaccurate spam label.
If there is a real problem, tell the business enough so it can fix it. If there is not a real problem, and the business is verified and accountable, then the label should be corrected in a reasonable timeframe.
Right now, too much of this feels like a black box. That is not good for businesses, and it is not good for consumers who are waiting on important calls.
The goal is not to weaken blocking or labeling. The goal is to make it more accurate.
9. How does Rich Call Data fit into this trust picture?
Rich Call Data can help, but only if the trust behind it is real.
A name, logo, and reason for the call can help the consumer decide whether to answer. That is valuable. But if that information is not tied to a verified business and an authorized number, it can also be misused.
So I do not see Rich Call Data as just a display feature. It should be connected to trust. The consumer sees the name, logo, or call reason. The Passport idea is about supporting the accountability behind that display.
If the trust layer is weak, the display layer can become a problem. If the trust layer is strong, Rich Call Data becomes much more useful. That is why I think this matters. The display is only as trustworthy as the verification behind it.
Having the same business upload the same paperwork ten times may look like more protection, but it may not actually give anyone a clearer picture.
10. You’ve also pointed to outbound text messaging. How could a portable Business Passport change the registration and approval burden there?
Texting has the same problem in a different form. A business can go through brand registration, campaign registration, use-case review, sample messages, opt-in and opt-out review, privacy policy review, and approvals. Then it changes messaging providers, and a lot of that identity work may happen again.
Some of that review is necessary. Consent matters. Content matters. Use case matters. But the core identity question should not have to start from scratch every time.
Who is the business? What brand is it using? What domain is tied to it? What is the use case? Who is the provider? Who is responsible? That information should be easier to carry forward. Again, not as an automatic approval. Just as a way to reduce duplicate work and keep accountability clear.
The Passport would not replace campaign review or consent requirements. It would help carry the verified identity and accountability layer underneath those reviews.
11. Some might worry that reducing duplicative verification weakens consumer protection. How do you respond to that?
I get the concern. But I don’t think duplicative verification is the same thing as effective verification.
Having the same business upload the same paperwork ten times may look like more protection, but it may not actually give anyone a clearer picture.
The better question is: is the information right, is it current, and can anyone actually use it when there is a problem? That is why renewal matters.
Just like a normal passport, this kind of trust record should not last forever. Businesses change. Providers change. Vendors change. Numbers change. Use cases change. So maybe there is a renewal cycle. Maybe there is an annual check-in. Maybe there is a recheck when something important changes.
I would not try to dictate the exact timing right now. The main point is that trust cannot be stale.
If the information is wrong, fix it. If the business changes something important, update it. If abuse is confirmed or the business will not cooperate, restrict it or revoke it. That is not weaker protection. That is better accountability. Consumer protection is stronger when the information is accurate, current, and usable.
12. At the end of the day, who benefits if this works, and what does success look like for the consumer?
Consumers should benefit first. Success is fewer scam calls, fewer misleading calls, fewer anonymous calls, and fewer missed calls that consumers actually needed.
A consumer should have a better chance of recognizing the doctor’s office, pharmacy, school, bank, utility, insurance company, service company, or business they asked to call them back.
Businesses benefit because they are not starting over every time they change a provider.
Providers benefit because the verification process is more consistent. Analytics companies benefit because they have better context. Traceback partners and regulators benefit because it is easier to find the responsible party.
To me, success is simple: good actors are easier to recognize, bad actors are easier to stop, and consumers have more confidence in what shows up on their phone. That is the consumer benefit. Better trust.
13. This clearly isn’t something one company can build alone. What needs to happen next, and who needs to be at the table?
This cannot be solved by one company. And honestly, I don’t think it should be.
A single call or text can involve a lot of different parties: the business, the provider, the platform, the carrier, analytics, branded calling, messaging, traceback, and regulators.
Everyone sees part of the picture. The business knows who it is and why it is communicating. The provider knows the customer relationship. The carrier and analytics side sees traffic and labels. Traceback and regulators see complaints and bad patterns.
The problem is that those pieces do not always connect. So I think the next step is conversation. Businesses, enterprises, carriers, CPaaS companies, messaging providers, analytics providers, branded-calling providers, traceback partners, policy makers, regulators, and consumer-protection groups all need to be part of it. Not to create another burden. To see whether we can reduce burden and improve accountability at the same time.
Maybe that starts with a working group. Maybe it starts with a small pilot. Pick a few real use cases where the consumer benefit is obvious — healthcare reminders, fraud alerts, school notifications, utility updates, service callbacks.
Test it. See what works. See what does not. I’m not looking to create another silo. We already have enough of those. I’m asking whether we can connect some of the trust signals we already have. I’m not trying to prescribe the answer. I’m trying to start the right conversation with the right people at the table.