False Answer Supervision (FAS) is a billing fraud practice in VoIP and telecommunications where a carrier charges for a longer call duration than the actual connected duration. In plain terms: you are billed for time the destination phone was ringing, or for time a fake audio signal was playing — not just for the time a real conversation occurred. The billed duration exceeds the genuine answer-to-hangup duration.
FAS is not a technical glitch. It is deliberate. A carrier — often a transit route sitting somewhere in the middle of the call path — manipulates billing signals so that its billing clock starts earlier than the real answer event. Multiplied across millions of calls per month, even two or three fraudulent seconds per call becomes a material, recurring charge for nothing.
Understanding how FAS works, what it looks like in your CDRs, and how to test for it is practical knowledge for anyone running high-volume outbound call center traffic over wholesale routes. This article covers all three.
How False Answer Supervision works
There are three common FAS mechanisms. They differ in the SIP signal or audio technique used, but the end result is the same: your billing clock starts before a real human answered the call.
1. Billing on ringing (180 Ringing billing)
In normal SIP call flow (as defined in RFC 3261 §13), a 180 Ringing provisional response tells the originating side that the destination phone is ringing. The call is not yet answered. A 200 OK response signals actual answer — this is when billing should legitimately start.
In a 180-based FAS scheme, the rogue carrier starts its billing timer when it receives or generates the 180 Ringing signal rather than waiting for the 200 OK. Every ring cycle — typically four to six seconds — that goes unanswered is billed as connected time. On calls that ring several times before going to voicemail or being abandoned by the dialer, this can add five to twenty-plus fraudulent seconds per attempt.
2. Fake ringback and early media fraud (183 Session Progress)
SIP 183 Session Progress (defined in RFC 3261 §21.1 and extended by RFC 3262) is used to carry early media — audio that plays before a call is formally answered. Legitimate uses include ringback tones played by the destination network or in-network announcements. FAS exploits this channel.
In this method, the rogue carrier injects a fake ringback audio stream or a pre-recorded greeting via early media while simultaneously sending an answer signal (200 OK) or a billing start event to the originating system. The originating system — your dialer or softswitch — sees what looks like a connected call. Billing starts. The destination phone may still be ringing or may never ring at all. The "conversation" audio your system receives is fabricated.
3. Fake voicemail injection
A variant of early media fraud, this method involves the rogue carrier playing a convincing voicemail greeting — "You have reached..." — before the destination system has even received the call. The originating system logs the call as answered (a live person or voicemail system picked up), billing starts, and the call is recorded as a completed attempt. The called party never received it. Answering machine detection (AMD) systems that listen for voicemail greetings may detect this as a "machine answer" and disconnect, leaving a short-duration "answered" call in your CDRs — exactly the FAS fingerprint described in the next section.
The financial impact
FAS fraud is effective precisely because the per-call fraud amount is small enough to be invisible without deliberate analysis. Two to eight extra seconds of billing on a call that generates thousands of completed-call records per hour adds up quickly. You will not notice it on a single call. You will notice it as a systematic discrepancy between your expected termination cost and your actual invoice — if you know what to look for.
The financial damage scales directly with call volume. High-CPS dialer traffic — which is the profile most exposed to FAS because of the sheer number of call attempts generated — accumulates fraudulent charges faster than lower-volume traffic. This is not a coincidence: FAS is disproportionately targeted at call center traffic because the volume makes it lucrative.
Note also that FAS distorts your ACD (average call duration) metric. If short fake-answered calls are included in your ACD calculation, they drag it down. More critically, they inflate your answer-seizure ratio (ASR) — calls that were never genuinely answered appear as answered in your CDRs, making a route look better-performing than it actually is. A suspiciously high ASR on a route can be a FAS signal, not a sign of quality. The Network Effectiveness Ratio (NER) is less susceptible to FAS distortion than ASR because NER counts busy and no-answer as successful network delivery — but FAS still inflates the "answered" component within NER calculations.
Who is responsible — and why it is hard to pin down
The contracted provider you are buying routes from may not be the entity committing FAS. In the wholesale voice chain, calls often traverse multiple carriers: your contracted provider, one or more transit carriers they use to reach the destination, and finally the terminating carrier at the destination. FAS typically occurs at a rogue transit route in that chain — a carrier your contracted provider routes through that the contracted provider may not be fully monitoring.
This is what makes FAS particularly difficult to address at the contract level alone. Contractual commitments from your direct provider don't necessarily constrain every carrier downstream in the route path. The practical protection is detection and route replacement — identify which routes are exhibiting FAS behavior and move traffic off them, regardless of whether the direct provider is the proximate cause.
This is also one of the reasons discussed in how to choose a CC routes provider — a provider who has real visibility into their downstream routing chain and actively monitors for FAS behaviors is materially different from one who does not, even if both offer similar quoted rates.
CDR patterns that reveal FAS
FAS leaves a recognizable footprint in call detail records. You do not need specialized equipment to begin an investigation — standard CDR data is sufficient for initial detection. The key patterns to look for:
| CDR Signal | What It Indicates |
|---|---|
| Short "answered" calls: 1–10 seconds billed duration | Primary FAS fingerprint. Calls recorded as answered but far too short for any real conversation. |
| Originating side always hangs up; no agent-side disconnect | Consistent caller-hangup pattern with no agent involvement means no real conversation took place. |
| High concentration of short answered calls on one specific route or carrier | FAS is route-specific. If the pattern clusters on a single route and doesn't appear on others, that route is the source. |
| Abnormally high ASR on the route | A suspiciously high answer rate — especially on a destination that normally has moderate ASR — may reflect fake answers being counted. |
| Billing duration consistently exceeds internal call duration logging | If your dialer or softswitch logs call duration independently and the carrier's billed duration is systematically longer, the delta is the fraudulent billing window. |
How to detect FAS on your routes
There are four practical detection methods, ranging from CDR analysis you can do with existing data to active testing that confirms FAS conclusively.
1. CDR duration distribution analysis
Pull your CDRs segmented by route or carrier. Filter for calls with a disposition of "answered" and a billed duration between 1 and 10 seconds. Calculate what percentage of that route's total answered volume falls in this window. Then cross-reference those calls with hangup-direction data — who ended the call. If your originating system consistently ended these ultra-short answered calls (with no record of an agent bridging into the call), you have the primary FAS signal.
A legitimate call center route will have some short answered calls — answering machine detection disconnects voicemail-bound calls quickly, and some contacts genuinely hang up in one or two seconds. The FAS indicator is a proportion or cluster that is anomalous relative to your other routes carrying similar traffic. Compare across routes, not just in isolation.
2. RTP audio recording and analysis
For calls showing the CDR pattern above, capture the RTP audio stream during early media and at the moment of "answer." If the call is showing as answered in SIP signaling but the RTP audio is carrying a looped ringback tone, an obviously pre-recorded greeting, or silence where real conversation audio should appear, that is direct evidence of early media FAS. This requires audio recording capability at your SBC or softswitch and is the most definitive non-test-call confirmation method.
3. Test calls to known-unanswered numbers
This is the most conclusive FAS test. Dial numbers that you know with certainty are unassigned, disconnected, or out of service on the route under investigation. If those calls return as "answered" in your CDRs — with a short billed duration — FAS is confirmed. A disconnected number cannot answer a call. Any "answer" record for such a call is fabricated by the FAS mechanism in the route.
Run this test against multiple carriers simultaneously if possible. The route that returns answered records for disconnected numbers is the problem route. This approach is described alongside other route vetting steps in how CC routes work.
4. ASR spike monitoring
Monitor ASR trends per route over time. A sudden, unexplained spike in ASR on a route — especially one that had a stable, lower ASR previously — can indicate that the route has started generating fake answer events. Real ASR improvements are gradual and correlate with infrastructure changes. A sharp spike with no corresponding change on your end warrants immediate investigation.
Combined with duration analysis (high ASR + high proportion of 1–10 second answered calls), this is a reliable composite indicator of FAS activity. The exact short-call threshold varies by route, destination, and traffic type — some operators use tighter windows based on historical baselines for specific corridors.
FAS detection checklist
- Filter CDRs by route: flag answered calls with billed duration 1–10 seconds
- Check hangup direction on flagged calls: originating-side hangup with no agent bridge = FAS signal
- Compare short-answered-call rate across all routes carrying similar traffic — identify the outlier
- Monitor ASR per route over time — unexplained spikes warrant audio or test-call investigation
- Capture RTP audio on early media for suspicious routes — looped ringback or pre-recorded audio on "answered" calls confirms early media FAS
- Dial known-disconnected numbers through the route — any answered CDR record for a disconnected number confirms FAS
- Compare your internal call duration log to the carrier's billed duration — a systematic gap is the fraudulent billing window
How to protect against FAS
Detection is step one; protection is the operational practice that follows:
- Use providers with transparent CDR access. You need per-call duration data with hangup direction to run FAS analysis. Providers who only offer aggregate reporting make this analysis impossible — which is itself a red flag.
- Run regular test calls on active routes. Test calls to known-unanswered numbers should be a recurring part of route monitoring, not a one-time exercise. Routes can start exhibiting FAS after initial onboarding.
- Monitor ASR alongside ACD on each route. These two metrics together surface anomalies that either metric alone would miss. An ASR/ACD dashboard per route is the baseline monitoring layer for FAS and general route quality.
- Have route alternatives ready. If you identify a FAS-afflicted route, the response is to move traffic. Having backup routes that have been vetted means you are not forced to stay on a fraudulent route while alternatives are sourced.
- Understand the downstream routing chain. Ask your provider how many transit hops a call typically traverses and what their monitoring of downstream carriers looks like. Providers who route through an opaque chain of transit carriers are more likely to unknowingly pass FAS-afflicted traffic.
The buyer-side evaluation for these characteristics — CDR transparency, route monitoring, downstream visibility — is covered in detail in how to choose a CC routes provider.
Frequently asked questions
For broader context on how call center routes are structured and what quality monitoring looks like throughout, see how CC routes work. For the full buyer-side evaluation — including which provider capabilities actually protect against FAS exposure — see how to choose a CC routes provider. FAS is one form of VoIP toll fraud — that guide covers broader fraud prevention including IRSF, Wangiri, and PBX hacking. For a structured approach to vetting route quality before committing traffic, see how to test wholesale VoIP route quality.