Telcos, Compliance and the Power to Take Risk

Avatar photo

Lifecycle Software’s decision to launch a compliance consultancy might not sound like the most significant development in telecoms this week. But it boils down to a central question: what makes a company a telco?

Lifecycle, which provides BSS and MVNE technology, says its new Compliance Consultancy Service will help MNOs and MVNOs navigate data protection, security, KYC, information security and other regulatory requirements. Its proposition includes an “obligation map” linking regulatory requirements to different stages of the customer journey.

What this suggests is twofold: that our traditional mental model of what “a telco” is has become increasingly outdated, and also that the relationship with regulation is necessarily changing alongside it.

The classic telco owned spectrum, switches, transmission, access networks, customer systems and perhaps thousands of people to build and operate them, and succeeded based on scale. A telecoms service provider today might operate a very different business model and have very few possessions.

An MVNO can buy wholesale network access. An MVNE can provide much of the technical infrastructure required to launch a mobile service. Cloud providers can supply critical computing infrastructure. Specialist companies can handle identity, fraud, payments, customer management and other functions.

As a result, we might have to think about the modern telco less about what it has, and more about what it organises.

Subscribe to the 6G Influx

TelcoForge's new intelligence service for 6G is here - register for free now and get ready for the next G!

Risky Business

Regulation is already adapting to this reality.

The UK’s revised Telecommunications Security Code of Practice, issued in 2026, explicitly recognises different sizes of provider through a three-tier system. Tier 1 covers providers with relevant turnover of £1bn or more; Tier 2 covers those between £50m and £1bn; and Tier 3 covers smaller providers that are not micro-entities. The detailed Code applies to the larger and medium-sized operators, while Tier 3 providers remain subject to the underlying requirement to take “appropriate and proportionate” security measures.

The framework shows an awareness that regulators can’t impose the same burdens on an incumbent and a ten-person team, and they take a risk-based approach. It also reflects the distributed nature of modern telecoms; its security requirements include supply-chain considerations and maintaining records of third-party suppliers and their dependencies.

So the regulator is, to some extent, catching up with the business model, but there is a problem still, which goes back to the idea of acting in an “appropriate and proportionate” way.

Appropriate and proportionate is very different from “understandable”.

A small telecoms business may have only a handful of people. Its founders might be experts in retail, software, marketing or finance rather than telecoms regulation. Yet it can find itself responsible for a mixture of telecoms obligations, data protection, security requirements, KYC, customer rights and supplier governance.

That is entirely reasonable from a regulatory perspective, but for a small company’s staff it leaves a very difficult question: how confident can they be that it has identified every regulation that applies to it, then interpreted and implemented them all appropriately?

The small telco carries risk and, ultimately, doesn’t know what it doesn’t know.

Who Would Fardels Bear?

So Lifecycle’s consultancy startup is answering a real market need, but it also exposes a problem with the regulatory model. If businesses need specialist help to translate rules into the systems and processes they actually operate, then there is a question about the usability of regulation as well as its substance.

We’re not arguing for less regulation; telecoms services – and flaws in them – can have consequences far beyond the companies that operate them. But we should think again about how to make regulation easy to understand for non-specialists, so that a smaller provider can make a reasonable assessment of its own risk.

The financial services industry has done something like this already.

Financial institutions have spent years becoming dependent on external technology providers. Cloud computing, payments, software platforms and specialist services have made it possible to outsource huge amounts of capability.

However, financial regulation has made it clear that you can outsource capability, but not  responsibility.

The EU’s Digital Operational Resilience Act (DORA), for example, puts considerable emphasis on ICT third-party risk. Financial entities are expected to manage their dependence on technology providers, maintain appropriate governance and retain responsibility for critical functions even when those functions are delivered externally. Meanwhile the European Banking Authority’s guidance stresses the responsibility of the financial entity’s executives for managing third-party risk.

So maybe that gives us a better definition of a modern telco. Maybe these days a telco is any company that takes responsibility for a telecommunications service, regardless of how much of the underlying capability it owns.

“You Have 30 Seconds to Comply”

So let’s put Lifecycle’s “obligation map” in this context. There is something neat in the idea of linking regulation to the customer journey. But is it one step on the way to a final destination?

If a customer signs up for a mobile service, identity needs to be verified. Certain information needs to be collected, retained, deleted. Access needs to be controlled. Fraud needs to be managed. Customers need to be able to exercise their rights. Suppliers need to be governed. But those are all processes which can be engineered.

A consultancy such as Lifecycle’s may be extremely useful during the transition: helping a new operator understand its obligations, map them onto its business and identify gaps.

But the end state could be something different; compliance could become part of the product architecture.

Instead of asking whether a telecoms business is compliant with regulation after it has built its operation, could we build telecoms operations in such a way that compliance is an inherent property of the system? Especially with software-based systems, automatic compliance with changing regulations may be just an update away.

That would be a scary thought for many software companies, as it means adopting some of the business risk on behalf of the client. They’d need to be very confident that they have things correct. However, that does also increase the value of what they’re offering.

If the industry is moving towards a multitude of smaller companies, with more outsourcing and more specialised providers, the old assumption that every telco has a large regulatory, security and legal machine behind it is becoming increasingly questionable. They might lose ownership of the network and of the software, but the accountability remains.

Image courtesy of Robocop Wiki

Total
0
Shares
Previous Post

Rio Meeting Shows Future Telecoms Valuations Will Depend On Different Measures