Summary
- Telstra told the Australian Communications and Media Authority on 24 March 2020 that it would suspend local-number portability from the next day, except for certain urgent priority-assistance or emergency-service requests. The company said COVID-19 had affected the offshore operations performing the work.
- The regulator found 895 scheduled ports were cancelled. It separately estimated that 13,558 port-out requests could not be actioned, while warning that an estimate of 3,041 expired ports could not be cleanly attributed to the suspension.
- Service returned in stages between 6 April and 20 July, and the affected Category C backlog was cleared on 16 October. The sequence shows that a number registry or port request is only a record of intended state; customers keep their number in practice only when validation, scheduling, cutover and routing all execute.
What it means to keep a local telephone number
A local telephone number can look like a simple label. A household may have printed it on school forms. A clinic may have given it to patients. A small company may have placed it on invoices, shop signs and years of advertising. When the customer changes provider, losing those digits can mean missed calls and costly updates.
Number portability lets the customer change provider while retaining the number. The number does not physically travel like a handset. Instead, several systems must agree that the service relationship is changing and make future calls reach the new provider.
Think of it as moving a well-known entrance without changing the street address. The old operator must recognise a valid request. The gaining operator must supply correct service information. Both sides must agree a time. At cutover, routing must change so that callers using the familiar number arrive at the new service. Records must then show one coherent result rather than two competing versions.
That process is especially important for local numbers used by organisations. A single residential service may be relatively straightforward. A business can have a group of related numbers, multiple lines, complex equipment and a planned cutover window designed to avoid losing incoming calls.
The public does not see most of these steps. It sees only whether the old number still works after the move. That makes portability a good example of infrastructure accountability: the right is easy to state, but the operational evidence is a completed handover and correctly routed calls.
Category A, Category C and the checkpoints between carriers
The ACMA report distinguishes two common forms of local-number porting. Category A ports are largely automated and generally concern single numbers, often residential services. Category C ports usually concern multiple numbers or more complex business services and rely more heavily on manual work.
Complex ports include several messages between carriers. A Pre-Port Number Validation request, often shortened to PNV, checks service information before the move. It helps the gaining carrier confirm that the number and related customer service details can enter the porting process.
Another message, the Complex Notification Advice or CNA, provides the initial detail for numbers moving through the Category C process. Once it is validated, a confirmation must return within the required period. The parties also need a booking and a cutover date.
These terms sound bureaucratic, but each answers a practical question. Is this the correct active service? Is the request authorised and still current? Which numbers belong in this batch? When will the routing change? Has the other carrier acknowledged the same state?
A database can store every field and still leave the port unfinished. The messages need to be processed, the responses need to arrive, and the cutover needs to run. If the workflow stops between those points, the customer remains with the old arrangement despite having requested a move.
The March 2020 suspension
On 24 March 2020, Telstra advised the ACMA that it was suspending local-number portability activities from 25 March. It preserved an exception for certain urgent requests related to priority assistance or emergency services. The regulator said it was not aware of an impact on those excepted services.
Telstra linked the decision to the effect of the COVID-19 pandemic on offshore operations where its local-number porting functions were performed. It said no new port-in or port-out requests could be submitted and scheduled activity from 25 March until at least 6 April would be cancelled.
This was the beginning of a long operational tail, not simply an eleven-day pause. Different parts of the workflow returned on different dates, and complex-port backlog work continued for months.
The regulator recorded that Telstra did not apply for an exemption under the Numbering Plan. ACMA described the decision as unilateral, made with little notice and immediately consequential for consumers and other carriers. Telstra asked ACMA to exercise forbearance in relation to the contraventions, but the request was declined.
The distinction matters. A severe external event can explain why an operating model failed without automatically changing a statutory duty. Continuity planning must therefore address both the technical and organisational capacity to keep the service working, as well as the formal process for any relief that the rules permit.
Recovery came in four visible stages
Telstra reported that Category A processing resumed on 6 April. These ports are mostly automated, tend to involve single numbers and commonly serve residential customers. Category C third-party ports also resumed at that point.
On 1 June, Telstra resumed accepting all new Category C port requests. These more complex ports often involve several numbers and business services. The report notes that Category C port-out work depended heavily on manual processes performed by offshore staff.
On 20 July, Telstra said it resumed processing all Category C booking-cutover-date requests. This was another separate checkpoint. Accepting a request did not mean that every port could already be scheduled and executed.
Finally, on 16 October, Telstra advised that it had cleared the backlog of Category C ports affected by the suspension.
The staged return is useful because it reveals the real service components. “Porting restored” is not one switch. The path includes accepting a request, validating it, booking the change, cutting over the service and resolving the accumulated queue. A status report that names only the first restored step can overstate what customers can actually do.
For non-specialists, a simple recovery dashboard would ask five questions: Are new requests accepted? Are validation messages being answered? Can cutover dates be booked? Are scheduled ports completing? Is the backlog shrinking without old requests expiring?
The 895 cancellations and the 13,558 estimate are different measures
ACMA found that Telstra cancelled 895 scheduled ports between 25 March and 16 October. These were identified porting events that had already reached a scheduled stage.
The regulator also estimated that 13,558 port-out requests could not be actioned during the suspension. That estimate was based on information Telstra supplied about usual processing volumes. It indicates that the likely operational effect was wider than the readily established contraventions.
The two numbers should not be substituted for each other. The 895 count concerns scheduled ports that ACMA found were cancelled. The 13,558 figure estimates requests that could not be actioned. Some may never have reached a scheduled cutover. The evidence does not turn all 13,558 into proven cancellations or distinct legal findings.
ACMA further estimated that 3,041 ports expired during the relevant period. Here the boundary is even more important. Telstra could not identify which expiries or withdrawals resulted from the suspension and which occurred through ordinary carrier processes. The figure signals a record-reconciliation weakness, not a verified total of suspension-caused expiries.
This is why incident ledgers need more than totals. Each request should carry an identifier, arrival time, current stage, last action, reason for delay, expiry state and final outcome. Without that lineage, an organisation may know that a queue grew but be unable to explain precisely which customers were affected by which control failure.
Why 895 became 2,685 legal instances
ACMA assessed the same 895 cancelled scheduled ports against three duties in section 111 of the Telecommunications Numbering Plan 2015.
First, a carrier or service provider involved with a portable service had to ensure that the customer could exercise the right to number portability. Second, it had to do what was necessary to port the number when another provider asked at the customer's request. Third, it had to complete the port at the agreed time or within the otherwise applicable period.
The regulator found 895 contraventions under each of those three provisions. That produced 2,685 related instances under subsection 462(1) of the Telecommunications Act: three legal classifications multiplied by 895 cancelled ports.
It would be wrong to report 2,685 as the number of customers, telephone numbers or cancelled porting jobs. Legal counts often classify the same event under more than one obligation. A clear article should preserve both the event count and the legal structure.
The distinction is not merely technical. Leaders who mistake legal-instance counts for service-event counts cannot size remediation correctly. Equally, leaders who report only 895 may miss that each cancellation defeated several separate safeguards: the right to act, the requested transfer and the agreed timing.
Delays continued after parts of the service resumed
The investigation also examined two Category C message types after Telstra began accepting new work again.
Under the applicable Local Number Portability Code, the losing carrier had to process PNV requests and respond within performance thresholds: 80 percent within three business days and 99 percent within five. ACMA found that 275 ports missed those requirements between 1 June and 16 September 2020.
For successfully validated Complex Notification Advice messages, a confirmation at batch level had to return within five business days. ACMA found 502 ports missed that timeframe between 1 June and 11 November.
These findings should not simply be added to the 895 cancellations to create a supposed number of unique customers. A complex port can appear at more than one process stage, and the public report does not establish a one-to-one population across the counts.
Operationally, however, the findings make an important point. Reopening intake is not the same as restoring capacity. A service can accept new work while validations and confirmations remain slow. If demand returns faster than processing capacity, the organisation can create a second backlog behind the first.
A responsible recovery plan therefore tracks flow, not just the open-or-closed state. It measures arrivals, completions, age at each checkpoint, missed service levels and how many jobs repeatedly return for correction.
The continuity-plan assumption that did not cover the event
The ACMA report records Telstra's argument that the contraventions arose from matters outside its control. It also describes a specific continuity-planning boundary.
Telstra said its plan catered for the loss of one of two main offshore partner sites. It did not address the loss of both major sites, which were about 600 kilometres apart, together with the loss of other offshore sites.
Geographic separation can reduce risks such as a local power failure, building outage or city-level disruption. It does not automatically create independence from a pandemic restriction, a common supplier dependency, the same staffing model or a shared operating procedure.
The lesson is not that offshore operations are inherently unreliable, nor that every process must remain in one country. The evidence does not support blaming named workers or a location. The lesson is that a continuity scenario must follow shared dependencies across sites.
If two facilities rely on the same labour market, access rules, provider governance or manual handoff, distance on a map may not separate the failure. A resilience review should ask what can remove both sites at once and how the work continues when that common assumption fails.
A registry records the intended state; it cannot perform the handover
Numbering systems and carrier records are essential. They show which provider holds a number, which customer has rights to use it, what service is active and what change has been requested. Without accurate records, carriers could route calls inconsistently or create disputes over control.
But the record is a ledger. It describes the intended state. It cannot by itself validate the service details, send a response to another carrier, reserve a cutover window or update live network routing.
This is the difference between record authority and operational authority. A properly authorised request should govern what the parties intend to do. Running systems and completed messages show whether the change actually happened.
When the two disagree, neither should be ignored. The live service tells operators the customer's present reality. The ledger tells them what should have happened and supports reconciliation. The control objective is to bring both back into one accurate state without duplicating, losing or misrouting the number.
That is also why portability matters to infrastructure accountability. A customer does not merely borrow digits from a database. The number is a stable public address whose usefulness depends on correct routing and on an executable process for changing the provider behind it.
What good porting continuity looks like
First, map the process as a state machine. Name each stage from customer authorisation through validation, acceptance, scheduling, cutover, routing verification and closure. Give every stage an owner and a timestamp.
Second, automate carefully where rules are stable, while preserving a controlled manual path for exceptions. Category A processing returned earlier in 2020 partly because it was more automated. Automation still needs capacity, monitoring and a tested recovery path.
Third, design for common-mode loss. Test the loss of all sites that share a supplier, staffing pool, remote-access dependency or regulatory restriction. Do not stop at one-building failure.
Fourth, keep an onshore or otherwise independent minimum capability for critical decisions if the risk model justifies it. Independence is about failure assumptions, not national labels. The alternate team needs access, current instructions, authority and rehearsed tools.
Fifth, preserve queue lineage. Every delayed request should show whether it is waiting for customer information, losing-carrier validation, gaining-carrier action, a cutover booking or routing confirmation.
Sixth, protect against expiry. The system should warn before authorisations, validations or bookings become stale. Where rules permit, teams should obtain renewed authority before the job silently drops from the queue.
Seventh, publish recovery in layers. Report separately whether intake, validation, booking, cutover and backlog clearance are available. This prevents a partially restored service from being described as fully normal.
Eighth, verify the result from outside the workflow. After cutover, controlled test calls should show that relevant networks route the number to the new service and that the old route no longer claims it.
Ninth, reconcile both carriers' records. A port is not complete if one system shows the new provider while another continues to route or bill as before.
Tenth, retain evidence. Message acknowledgements, cutover timestamps, routing checks and exception decisions should remain available for customer support, incident review and regulatory assurance.
Questions customers and procurement teams can ask
A small business cannot inspect every carrier system, but it can ask its gaining provider for a clear porting plan. Which category applies? What information must be validated? Which date is booked? What service interruption is expected? How will the provider confirm that inbound and outbound calls work after cutover?
Customers with many numbers should keep their own inventory. It should show the number, current provider, service purpose, physical or virtual destination, dependency on alarms or payment systems, and the person authorised to approve a change.
Procurement teams can ask providers how they maintain porting during simultaneous disruption at multiple operations sites. What work is automated? What needs trained people? Which common dependencies exist? How old was the last exercise that removed all primary staffing locations at once?
They can also ask how backlog status is reported. A count alone is not enough. Useful reporting shows the oldest request, stage distribution, missed deadlines, expiry risk and the expected rate of clearance.
For critical numbers, the customer should have a communications plan that does not assume the port will finish on the first proposed date. That may include temporary call forwarding where available, alternative published channels and an escalation contact at both providers. These steps do not replace the carrier's obligation; they reduce the customer's exposure while the move is controlled.
What the public record does not prove
The sources do not prove that 13,558 customers had scheduled ports cancelled. That number is an ACMA estimate of port-out requests that could not be actioned. The established scheduled-cancellation count is 895.
They do not prove that all 3,041 expired ports resulted from the suspension. Telstra could not separate suspension-related outcomes from business-as-usual expiry or withdrawal.
They do not show that 2,685 different people were affected. That figure results from applying three Numbering Plan provisions to 895 cancelled ports.
They do not establish that 275 PNV delays and 502 CNA delays belong to completely separate customers, or that they can be added to 895 without overlap.
They do not establish an impact on the urgent priority-assistance or emergency-service requests excluded from the suspension. ACMA said it was not aware of such an impact.
They do not support blaming a named offshore employee, partner site or country. The accountable questions concern the operating model, shared dependencies, decision process and continuity coverage.
They do not mean that paying an infringement notice is by itself an admission of liability. The notice states otherwise. The investigation report separately records that Telstra admitted breaches while arguing that their causes were outside its control.
These boundaries keep the analysis tied to operational evidence rather than turning a serious continuity failure into an exaggerated story.
The regulatory outcome
ACMA's public investigations register records that Telstra paid AUD 1,512,000 in relation to the Numbering Plan and Telecommunications Act breaches. The regulator also issued a direction requiring Telstra to comply with the Local Number Portability Code.
The payment is one outcome. The more durable accountability measure is whether the operating process can now continue through the shared failures revealed in 2020, or fail in a controlled way without losing request lineage and customer choice.
A future assurance review would therefore look beyond a policy statement. It would sample multi-site exercises, observe fallback staffing, inspect queue lineage, measure validation and confirmation times, and verify completed ports through live routing tests.
That evidence would connect the rule to the service. Customers have a right to retain eligible numbers. The infrastructure must be able to execute the change that makes the right real.
The durable lesson
The 2020 event was not a loss of telephone numbers from a registry. It was a loss of the operating path that moved those numbers between providers.
The recovery dates reveal the layers. Automated and simpler work returned first. Complex request intake followed. Booking and cutover processing returned later. The backlog took until October to clear. At each stage, the recorded intention and the live ability to perform it were different things.
That is the reality-layer test for number portability. Accurate records and clear rights are necessary, but neither is sovereign over a network outcome. The practical authority is the combination of a valid request, a processed inter-carrier workflow, a completed cutover, correct routing and a reconciled ledger.
For customers, keeping a number feels like continuity of identity. For operators, it must be engineered as continuity of execution.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
