STI-GA moves to vet governance authorities no national regulator stands behind
STI-GA / ATIS · source ↗
The Secure Telephone Identity Governance Authority — STI-GA, the ATIS-administered body that runs STIR/SHAKEN certificate governance in the US — has selected Numeracle to design a framework for vetting “non-jurisdictional governance authorities” (NJGAs) seeking interoperability with the US ecosystem. The assessment covers an authority’s identity, governance structure, certificate-management security, and alignment with STI-GA policies, plus ongoing monitoring for continued compliance. “Fraud doesn’t stop at a border, so trust can’t either,” said Numeracle CEO Rebekah Johnson.
The term NJGA is new, and the release defines it mostly by what it isn’t. It isn’t “foreign”: the established cross-border path runs between regulator-backed authorities — the US STI-GA and Canada’s CST-GA already hold a mutual-recognition MoU. NJGAs are the other kind, in STI-GA chair Glenn Clepper’s words “those not established by national regulators.” That leaves the operative questions open — what qualifies a body as non-jurisdictional, what it’s assessed against, and what stands in for the regulator that isn’t there. Regulator backing is what has made trust in this chain legible so far: a national mandate is public and accountable by construction. Where there’s no mandate, the vetting criteria carry that weight instead.
Which is the whole of it. Get the criteria right and authenticated calling reaches places no national regulator is going to; get them wrong and accountability for a verified call quietly moves to a private assessment nobody voted for. The framework is being designed now and the details aren’t public — worth reading closely when they are. The fuller read is in this week’s Sector Watch.