For MNOs and MVNEs, the difficult part of IoT eSIM is rarely first activation. It is maintaining control after devices cross borders, contracts change, radio conditions deteriorate, and wholesale routing economics move. A durable operating model treats the SM-SR lifecycle as a governed control plane linking profile state, IMSI assignment, roaming entitlement, and accountable commercial ownership across an estate that may remain deployed for a decade or more.
Lifecycle ownership must outlast initial provisioning
An IoT eSIM programme becomes fragile when responsibility for the SM-SR is distributed across several teams and suppliers but no party holds authority over profile-state decisions. Procurement often treats remote RSP as an implementation deliverable: integrate the interfaces, complete acceptance testing, provision the first cohort, then transfer the platform into routine support. That horizon is too short. The relevant service period is the installed life of the device, including the years after the original commercial assumptions have changed.
Decision rights must cover enable, disable, delete, fallback and recovery actions. They also need to survive changes among the MNO, MVNE, eUICC supplier, connectivity provider and enterprise customer. Technical custody of the SM-SR does not by itself establish commercial accountability. A supplier may execute a disable instruction while another counterparty remains liable for a stranded device population, residual roaming traffic or an estate that no longer complies with local rules.
The operating record therefore has to join the eUICC identifier, active and inactive profile states, IMSI history, relevant location signals, tariff or sponsor identity, and the party that authorised each action. A transaction log confined to the RSP platform is insufficient if finance cannot connect it to settlement, fraud teams cannot identify the initiating authority, or enterprise operations cannot determine which devices require field intervention.
Lost-device, ceased-service and counterparty-insolvency scenarios belong in the original design. A profile that cannot be disabled or reassigned under contracted authority creates fraud exposure and continuing wholesale cost. An MVNE servicing 12+ tenants in EMEA found that common technical interfaces did not resolve conflicting tenant rules on suspension and deletion; the material work lay in approval hierarchies, evidence retention and liability allocation. Standards compliance enables interoperability. It does not set escalation rights, service levels or commercial ownership.
Multi-IMSI assignment is a policy problem before it is a routing feature
Multi-IMSI architectures can improve resilience and geographical reach, but only when each identity has a defined purpose, permitted geography and commercial owner. Permanent identity strategy should remain distinct from temporary connectivity preference. A device may be capable of selecting among several IMSIs, yet that flexibility becomes an operational liability if no policy explains why an identity exists, which routes it may use, or when it must cease to be valid.
Rotation triggers should be explicit and bounded. Relevant conditions include sustained registration failure, roaming denial, regulatory change, network sunset, abnormal attach patterns and contracted route withdrawal. Weak radio indicators alone are a poor trigger. Indiscriminate changes can increase signalling, obscure fault isolation and make fraud monitoring less reliable, particularly where devices repeatedly alternate identities without resolving the underlying coverage or configuration fault.
Operations, security and finance also need a common correlation chain across EID, ICCID, IMSI, MSISDN where present, APN, enterprise account and device serial number. Without that continuity, each function investigates a different representation of the estate. Inventory reports may show the intended profile, network records the attached IMSI, and invoices the route that actually carried traffic.
The rotation mechanism must be equally clear. Bootstrap connectivity, an enabled fallback profile, remote profile management and physical intervention each rely on different availability assumptions and carry different costs. A large IMSI pool is not inherently a continuity strategy. Pool breadth without country-level entitlement, steering control and auditable assignment rules merely transfers complexity from commercial design into operations, where failures are harder and more expensive to unwind.
Roaming controls need to reflect device permanence and local regulation
Conventional wholesale steering assumes that mobility and network preference can be managed within a relatively stable roaming framework. Static IoT devices challenge that assumption. Estates should first be classified as transient, seasonal, semi-permanent or fixed, with separate duration limits, localisation thresholds and intervention policies. A fleet asset crossing several markets is not equivalent to a meter attached to the same building for eight years, even if both initially use the same sponsor identity.
Country policy must connect permanent-roaming rules with sector restrictions, lawful-intercept obligations, spectrum and equipment-certification conditions, and the visited operator’s wholesale terms. At country and network level, the policy should identify allowed IMSIs, preferred visited networks, barred networks, fallback order, data-breakout assumptions and spend guardrails. These controls need scheduled review because regulation, bilateral terms and local network availability can all change during the device life.
Steering instructions are not determinative in constrained coverage. A device may only be able to reach a non-preferred PLMN, or the preferred network may provide adequate outdoor coverage but fail inside the device’s installed environment. The operating model needs an exception path that records why the device departed from policy, who accepted the route, how long the exception may remain, and whether localisation or a profile change is required.
Service recovery must also be assessed against unit economics. A technically successful fallback can still be commercially unacceptable if thousands of low-ARPU sensors move onto an unbudgeted wholesale route. A Tier-2 MNO, Southeast Asia, ~18M subscribers identified this problem after coverage-driven fallback concentrated a fixed-device cohort on a higher-cost visited network. Attach performance improved, but margin deteriorated because route acceptance had not been linked to a device-level spend threshold.
Operators should conduct regular portfolio reviews in countries where deployed populations have become effectively permanent. Waiting for a regulator or visited network to force migration compresses decision time and weakens commercial options. Earlier review permits a controlled choice among continued roaming, a local IMSI, profile replacement, host-network renegotiation or managed withdrawal.
Profile rotation should be governed as controlled change
Profile rotation can reduce supplier, route and regulatory concentration risk. It can also strand devices at scale. Operators should apply release discipline comparable to changes elsewhere in the mobile core and BSS/OSS estate. A rotation runbook should define eligibility, cohort size, maintenance windows, retry limits, rollback criteria and named approval owners. The runbook must distinguish between a failed command, a downloaded but inactive profile, and a device that has changed identity but cannot establish usable service.
Laboratory validation is necessary but not sufficient. Tests should represent actual device classes and access conditions, including low-power modes, intermittent coverage, legacy firmware, constrained bootstrap paths and devices behind private APN configurations. Hardware model, firmware release, geography, radio environment and power cycle behaviour may predict failure more accurately than enterprise account or tariff.
Success measures should extend beyond profile download and enablement. They should cover attach success, PDP or PDU session establishment, SMS reachability where operationally relevant, session stability, roaming settlement impact and device recovery rates. Staged cohorts then allow regional, hardware-specific or firmware-specific faults to emerge before broad deployment. Segmentation should follow operational behaviour, not only customer ownership.
Every change should enter the same evidence chain used for dispute handling: timestamp, initiating party, pre-change state, target state, network outcome, retries, rollback decision and final billing treatment. This record turns a technical event into an auditable commercial action. It also prevents a nominally successful rotation from being closed while devices remain attached through an unintended identity or higher-cost route.
Commercial governance must connect wholesale settlement to device identity
The commercial model fails if settlement relies on a static subscriber inventory after profiles and IMSIs begin to change. CDR and usage reconciliation should use the active identity and profile state at the time of service. Otherwise, finance may attribute traffic to the original profile owner even though a fallback identity, revised sponsor or different visited network generated the charge.
Wholesale agreements should reflect this lifecycle. Ownership of inactive profiles, minimum commitments, roaming rate changes, suspension rights, data-retention periods and exit assistance need explicit treatment. Supplier portability is part of the same control framework. Contractual access to profile inventory, lifecycle history, audit records and migration support becomes most valuable when an MVNE relationship, roaming route or enterprise programme changes under commercial pressure.
Intervention thresholds should identify cohorts with abnormal unit economics, sustained registration retries, unexpected visited-network concentration or rising dormant-device cost. A joint governance cadence across wholesale, RSP operations, fraud, finance and enterprise operations is required because no function sees the full result of a profile decision. Wholesale sees rate exposure, operations sees attach behaviour, fraud sees anomalies, and finance sees the lagging settlement consequence.
A Greenfield MVNO, post-2023, multi-IMSI stack used profile inventory as its initial control source but found that inventory state alone could not explain settlement variances after route changes. Reconciliation improved only when lifecycle events were timestamped against active IMSI, visited network, contract owner and billing treatment. The lesson is not that more identifiers produce control. Control comes from preserving accountable relationships among them.
The relevant unit of governance is therefore not the SIM alone, but the identity-state-route combination. That is the level at which service continuity, regulatory exposure and wholesale cost become attributable to an operating decision. As IoT estates mature, eSIM governance will move from provisioning ownership toward continuous identity and wholesale-risk management. MNOs and MVNEs that can evidence profile state, IMSI purpose and roaming accountability at device level will be better placed to protect margin while preserving migration options.
