Summary

  • New Zealand’s proposed number-porting rules would permit a short pause when a provider has reasonable grounds to suspect fraud, while requiring prompt checks, review, customer notice and a record of why the pause continued.
  • The draft also gives a separate, evidence-based route to reverse an unauthorised completed port. Both changes are proposals in a consultation, not rules already in force.

Analysis

A fraud exception needs an expiry condition

A mobile number is more than a routing label. It is often the recovery address for a bank, the contact a family knows and the identifier printed on a customer’s business materials. When a subscriber changes providers, portability lets that person keep the number without asking the old provider to retain the commercial relationship. A fraudster who takes control of the number can exploit the same continuity in reverse, intercepting messages used to regain access to other services.

The New Zealand Commerce Commission’s draft tries to address both sides of that problem. It proposes a new determination for local and mobile number portability from 20 December 2026, after the current terms expire on 19 December. The proposed five-year term would preserve the regulated switching service. The Commission says continued regulation is likely to best promote competition because portability removes a barrier to changing provider.

Inside that continuing right, the proposed fraud clause would let a service provider or carrier temporarily stop a port request when it has reasonable grounds to believe the request is, or is likely to be, linked to fraud, a scam or unauthorised porting. The pause is limited to the minimum time reasonably needed to verify the request, protect the customer or investigate. Verification must start promptly; the suspension must be reviewed as circumstances require and end when its grounds disappear.

The two-business-day point is a governance trigger, not a general service deadline. Any suspension that lasts longer must go to an appropriately authorised person for review and approval, then be checked at least once each business day. That structure makes duration visible as a decision. It asks the provider to keep showing why the risk still justifies interruption instead of letting an initial suspicion silently become a standing veto.

The evidence trail matters as much as the clock. The draft calls for a contemporaneous record of the grounds and information relied on, start and end times, each review, the steps taken to verify the request or protect the customer, notification timing and outcome. Providers would retain it for 12 months and supply it to the Commission or Enforcement Agency on request. The customer should be told as soon as reasonably practicable how to verify or progress the port, unless notice would likely prejudice fraud prevention, customer protection or an investigation. If notice is deferred, both the reason and later notification must be recorded.

Authentication and reversals are different controls

The same draft proposes making two-factor authentication the default for mobile ports. A Gaining Service Provider could proceed without it only under an exception in the Operations and Support Manual or with a reasonable, documented basis. The Enforcement Agency could later examine that basis. The Commission also proposes requiring a customer name on mobile Port Requests, while inviting feedback from prepaid providers that may hold limited customer details.

Those fields should not be collapsed into one test. A name helps identify whose request is being handled; two-factor authentication tests control of a channel; Customer Authorisation is the evidence that the person agreed to the transfer. None alone proves every other step. That distinction is important when an unauthorised port has already completed and a number must be returned.

For a completed transfer, the proposed reversal process would require the Losing and Gaining Service Providers to work together to determine whether valid authorisation existed. The Commission rejected a trigger based only on someone’s belief: reversal can disrupt a legitimate transfer, and “belief” does not say whose judgment counts or on what grounds. Instead, failure by the original gaining provider to produce authorisation evidence within the timeframes already set in the current terms would be enough to deem the port unauthorised and initiate reversal.

The evidence clock is familiar to participants and does not force the losing provider to prove a negative.

Reporting should reveal whether the exception is becoming routine

The draft would make each provider and carrier report aggregate suspension counts, durations and outcomes twice a year, including how many suspensions exceed two business days. The Commission says it needs regular visibility; a request-only power would not show how often the exception is used. Its proposed public porting statistics would also align service-level performance with key customer-impacting measures and count each transfer, including a number ported more than once.

The consultation is open until 5pm on 6 November 2026. The questions for providers include whether the safeguards prevent delay to legitimate ports and whether six-month reporting is workable. The question for customers is plainer: if a transfer is stopped, can they find out what action is needed and when someone will reconsider it?

Sources