For MNOs and MVNEs, lawful-interception coverage is not separable from OTT bypass detection. A traffic pattern can be commercially legitimate, technically unusual, or deliberately structured to avoid regulated voice and messaging routes. The operational task is therefore not to block OTT usage, but to classify traffic and interconnect behaviour with enough evidential discipline to protect termination economics, meet LI obligations, and avoid penalising an MVNO tenant for its normal subscriber base.
Classify bypass by interconnect behaviour, not by application label
A defensible bypass programme starts with the commercial exposure. The objective is to identify undeclared voice termination, uncontracted transit, SIM-box activity, and route manipulation. It is not to catalogue every encrypted application traversing the packet core. That distinction determines which records should be retained, which teams own the investigation, and whether an anomaly can support a chargeback rather than merely a fraud alert.
The evidence base should correlate SIP setup characteristics, SBC records, IMS session data, CDRs, GTP flow behaviour, and destination-number patterns. Each source answers a different question. SIP records describe call establishment. Media-path data shows where traffic actually travelled. CDRs quantify duration and chargeable events. Subscriber and mobility records establish whether the pattern is consistent with normal retail use. No single source provides sufficient context for a tenant escalation, invoice adjustment, or suspension decision.
The practical dividing line is behavioural. Subscriber-originated OTT sessions may be frequent, international, and concentrated around particular time zones without representing wholesale avoidance. Traffic entering through an MVNO IMSI range becomes more concerning when it exhibits termination characteristics: repeated short-duration calls, unusually high destination entropy, narrow calling windows, multiple subscribers sharing infrastructure signatures, or media paths that are asymmetric with the observed signalling route. Those indicators warrant investigation, but not automatic financial recovery.
Signalling and mobility evidence can materially alter the interpretation. SS7 and Diameter events establish identity, registration, roaming state, and session context. HLR and AuC activity can distinguish a roaming subscriber cohort from a pool of devices repeatedly authenticating in a fixed location. MNP status can explain apparent inconsistencies between number range, serving network, and expected termination route. These are not ancillary checks. They determine whether the operator is looking at retail behaviour, roaming complexity, or an engineered bypass path.
A Tier-2 MNO, Southeast Asia, ~18M subscribers, encountered this distinction during an MVNO portfolio review. High-volume international calling patterns were initially attributed to OTT bypass. Correlation with subscriber tenure, destination clusters, approved application use, and charging records showed that a substantial portion came from a legitimate expatriate segment. Broad restrictions would have increased complaints and churn while recovering little termination value. The recoverable exposure emerged only after the inquiry narrowed to sessions with undeclared PSTN breakout and inconsistent interconnect records.
The operating model should therefore assign confidence levels to suspected events. A low-confidence detector output may trigger enhanced monitoring. A medium-confidence case may justify route-level record preservation and a tenant inquiry. Financial remediation should require corroborated interconnect evidence, documented subscriber context, and a review outcome that meets the threshold written into the wholesale agreement. This protects recovery claims from becoming subjective disputes over traffic interpretation.
Keep lawful-interception obligations intact across the MVNO chain
Lawful-interception exposure concentrates at hand-off points. Host MNO, MVNE, MVNO, roaming partner, and voice carrier may each describe traffic ownership differently across network diagrams, service schedules, and interconnect contracts. A usable control model must reconcile those documents. It should map every service path from IMSI allocation through RAN, EPC or 5G core, IMS, SBC, SMSC, signalling, voice interconnect, and any external breakout.
For each hand-off, the map should identify the interception access point, mediation owner, retained metadata, timestamp source, preservation process, and accountable legal entity. The customer relationship alone does not decide responsibility. Licence conditions, numbering ownership, topology, and national implementation requirements may leave the host MNO responsible for capabilities that an MVNO contract assigns only in general terms to the tenant.
Full MVNO and multi-IMSI structures require additional testing. Coverage may follow the serving core, assigned MSISDN, outbound SIP trunk, or a combination of those elements. A roaming event can move signalling and user-plane functions into different jurisdictions. An MNP event can separate number ownership assumptions from the actual serving network. Standard provisioning checks may confirm service activation while missing whether mediation records remain complete after those transitions.
Route change control is consequently part of LI governance. A new IPRN supplier, an eSIM RSP configuration change, an IMS breakout modification, or a revised roaming route can alter interception visibility before settlement volumes move enough to attract commercial attention. The approval workflow should identify whether the change affects access points, mediation interfaces, retention scope, encryption boundaries, or the legal entity receiving warrants.
Periodic proof obligations should sit in the operating schedule rather than an informal assurance plan. Relevant tests include sample warrant execution, mediation-record completeness, timestamp alignment across network domains, retention-policy conformance, and escalation ownership for incidents involving an MVNO tenant. The purpose is not merely regulatory documentation. Complete, time-aligned records also reduce the cost and duration of settlement disputes when suspected bypass crosses several parties.
Suspected bypass and LI failure should share a case reference, evidence-preservation timetable, and decision authority. Fraud teams often focus on rapid containment. Wholesale teams focus on financial exposure. Regulatory teams focus on lawful access and reporting duties. Network operations focus on route restoration. If each opens a separate investigation, evidence can be retained under different clocks and conclusions may conflict. A joint protocol should state who can restrict traffic, who informs the tenant, and who approves a settlement remedy.
Price the control framework into settlement and partner contracts
The economic value of bypass detection depends less on detector sensitivity than on the contract surrounding it. Data access, dispute windows, cost allocation, recovery formulas, and remediation rights determine whether an identified pattern becomes collectible revenue. They also determine whether the operator can defend the action if a tenant challenges the evidence or attributes the anomaly to a downstream carrier.
Costs should follow controllable domains. The host MNO commonly funds core-network LI capability because it controls the relevant access and mediation functions. An MVNE or MVNO may bear incremental CDR enrichment, route-specific assurance, investigation support, or data-retention costs where its architecture creates the requirement. Contracts should distinguish standing capability costs from event-driven investigation costs. Without that separation, routine control expenditure can become an annual pricing dispute rather than an understood part of the wholesale margin.
Settlement cadence must accommodate investigation lead times. Daily or weekly anomaly feeds can contain exposure and preserve records, but they rarely provide enough evidence for final recovery. Monthly settlement reviews allow correlation across SIP, IMS, signalling, and charging domains. Quarterly governance reviews should examine recurring route issues, control exceptions, and whether recovery economics justify further intervention. Where roaming or multi-party interconnect is involved, the true-up mechanism may need to remain open beyond the normal invoice cycle.
- Anomaly reporting cadence
- Daily or weekly operational feed; monthly settlement review; quarterly control-governance review
- Evidence threshold for financial recovery
- Correlated SIP or IMS records, CDRs, route evidence, subscriber context, and documented investigation outcome
- Dispute window
- Typically 30–90 days, extended where roaming, MNP, or multi-party interconnect reconciliation is required
- Revenue allocation for confirmed bypass
- Pre-agreed recovery formula, with treatment for investigation cost, bad debt offset, and downstream carrier claims
- LI assurance obligation
- Defined interception access point, mediation owner, retention scope, warrant-test process, and route-change notification requirement
Confirmed bypass also requires explicit revenue treatment. Recovered termination value may offset unpaid invoices, be divided under a pre-agreed formula, or fund specified fraud-control work. The formula should address investigation cost, tax treatment, bad debt, downstream carrier claims, and reversals if later evidence changes the finding. A recovery clause that states only that the host may “charge for unauthorised traffic” leaves the most material settlement questions unresolved.
Commercial remedies should remain separate from customer-protection measures. Restricting a route may be necessary to contain confirmed abuse. Suspending subscribers on weak evidence is a different decision. False positives can produce churn, regulatory complaints, and enterprise-account loss that exceed the termination value at risk. The contract should define graduated actions, including monitoring, traffic caps, route isolation, deposit adjustments, invoice set-off, and suspension. Each action should correspond to an evidence threshold and named approval authority.
Audit rights must be operationally usable. A general right to inspect records is of limited value if the agreement does not specify route records, CDR samples, mediation evidence, retained signalling metadata, delivery format, and response time. Those rights must also observe data-minimisation rules and jurisdictional restrictions. The practical objective is a bounded evidence package that supports reconciliation without creating unrestricted access to subscriber data.
Structured operator partnerships
Align traffic and settlement controls
Averon works with operator partners to align MVNO traffic governance, interconnect controls, LI responsibilities, and settlement operating models across the same contractual framework.
As MVNO traffic becomes more distributed across IMS, SIP, SS7, roaming, and multi-IMSI arrangements, bypass controls will be judged by their settlement evidence and regulatory resilience rather than detection rate alone. A high alert count has little commercial value if the records cannot sustain recovery, the dispute window has expired, or route ownership remains ambiguous.
The durable commercial model joins traffic classification, LI accountability, and recovery rights in the same operating agreement. That structure protects termination economics without treating legitimate OTT use as presumptive abuse. It also gives the host, enabler, tenant, and carrier a common basis for investigation, settlement, and regulatory response.
