← Back to Knowledge CentrePerspective

Governance Wasn't Invented. It Was Finally Named.

DevOps, data governance and the CISO role were all practised for years before anyone agreed what to call them. A reflection on whether communication identifiers are following the same pattern — and what the evidence does and doesn't yet show.

By the time an industry agrees on a name for something, the practice it describes is usually already years old. Three precedents make the point with unusual clarity.

Before "DevOps" had a name, the practice already existed. Developers and operations teams had been experimenting for years with closer collaboration, more frequent releases, and shared ownership of what happened after code shipped — habits with roots in the 2001 Agile Manifesto and, further back, in the Toyota Production System's approach to flow and waste. Patrick Debois gave the practice a name in 2009, organising the first DevOpsDays conference in Ghent after conversations with Andrew Clay Shafer the year before. John Allspaw and Paul Hammond's Velocity Conference talk that same year, "10+ Deploys per Day: Dev and Ops Cooperation at Flickr," gave the idea a wider audience. The name arrived after the practice had already proven itself.

Data governance followed a similar, longer arc. Researchers date organised data-governance activity to the early-to-mid 1990s — but the first academic framework describing it in terms of decision rights and accountability wasn't published until 2010, and the first ISO standard for it, ISO/IEC 38505-1, didn't appear until 2017. A bibliometric review found the term itself barely used in research titles before 2007, with meaningful growth in the literature only from around 2019. A discipline had been operating, informally, for the better part of two decades before it had a standard, and considerably longer than that before anyone was writing much about it.

The clearest example is a title, not a practice. Organisations had informal security functions long before anyone held the title Chief Information Security Officer. Steve Katz is widely credited as the world's first, appointed at Citicorp in 1994–95 — specifically in response to a breach. That appointment came a full decade after the Chief Information Officer role had already been defined in the boardroom. Even within the same broad domain, recognition of a sub-discipline can lag by years, and it often takes an incident to force the question of who, exactly, owns it.

None of this is a claim about communication identifiers specifically. It's a pattern about how industries name things: usually after the practice has already proven itself necessary, rarely before.

The same shape, once more

Telesmart's own public record shows a version of the same shape. The platform launched in 2020. What followed was several years of customer and partner relationships, each solving a specific, practical problem rather than selling a category. Telarix's own public description of the partnership put it plainly: lifecycle authority sits in a separate control layer, while day-to-day provisioning stays with the operational team. HGC's story was an automation problem that, once resolved, changed how the relationship was valued; Liquid's was a number inventory scattered across multiple markets, brought into a single governed view.

By 2024, the platform had been consolidated around a single governed architecture. Only in 2026 — after that consolidation, and years of delivering the underlying capability — did Telesmart begin describing this as "Communication Identifier Governance": the name it uses for its own positioning, not yet one the wider industry has adopted.

The category name is recent. The practice is not. That ordering is the same shape the precedents above describe — one further instance of a general pattern, not proof it is complete or unique to Telesmart.

Where identifiers sit on that curve now

If naming lags practice, the more interesting question is what has been happening to the practice itself — and here, the public record outside Telesmart is informative in its own right.

In November 2023, the US Federal Communications Commission substantially revised its Customer Proprietary Network Information and Local Number Portability rules, specifically to address SIM-swap and port-out fraud. The revised rules require secure customer authentication before a SIM change, proactive customer notification, and multi-year retention of SIM-change records by carriers. In the same year, India's Telecommunications Act, 2023 went further, introducing criminal provisions — up to three years' imprisonment — for tampering with telecommunication identification or fraudulently acquiring SIM cards or other identifiers, explicitly naming Calling Line Identity, IMEI, IP addresses and SMS headers as protected.

Separately, the commercial value attached to identifiers has grown. Analysys Mason's 2023 research on CPaaS describes it as a multi-billion-dollar market — Twilio and Sinch alone reported 2021 revenues of $2.8 billion and $1.8 billion respectively — and frames the strategic problem for carriers as one of monetising network assets, including numbering, that are currently captured by intermediaries rather than by the carriers who own the underlying infrastructure.

Two things are true here, and they are different claims. First: identifiers now carry legal and commercial weight they did not carry a decade ago. That is well documented. Second: no analyst, standards body or regulator publication reviewed for this article uses "governance" language to describe this activity, in the way the term is used for data or cybersecurity. TM Forum's identity-management specifications, for instance, are genuinely substantial — but they are framed as technical data models and open APIs, not as an executive discipline. The practice is visibly maturing. The name for it, industry-wide, has not caught up yet.

Why this matters

None of the individual facts above is, on its own, surprising — regulators update fraud rules, markets grow. What changes the picture is what happens when those things occur together, against ownership that was never designed for this level of scrutiny.

Fragmented ownership of an identifier estate — split across commercial, technical and compliance functions, with no single accountable owner — was tolerable when the cost of getting it wrong was operational friction: a slow provisioning process, an occasional billing error. It becomes a different problem once the cost includes a regulator's retention requirement, a criminal statute naming the identifiers involved, or a commercial opportunity a faster-moving intermediary captures instead. The activity has not changed. What is attached to it has.

This is the same mechanism the earlier precedents describe. A Chief Information Security Officer was not created because security work became more interesting; the record suggests a breach made the cost of leaving it unowned undeniable. Data governance's own path is less clearly evidenced, but the timing is suggestive: formal standards arrived only once data itself had plausibly become something regulators and boards had greater reason to scrutinise. Rising stakes, in both cases, turned tolerated fragmentation into something organisations could no longer afford.

That is the condition the evidence describes for identifiers: rising regulatory consequence, rising commercial value, and an ownership model built for a lower-stakes era — the same conditions that, elsewhere, have reliably produced more disciplined ownership, eventually given a name. Nothing here says that outcome is certain. It says the conditions are familiar.

What I'd watch for

Everything above is documented, or reasoned directly from what is documented. This last part is not — it is a working observation, and I want to be clear about that distinction, because it is an easy one to blur.

In my own conversations over the past few years, I have noticed a shift in who asks the sharpest questions about identifier estates — less often the person who owns the technical implementation, more often someone thinking about risk, or about a commercial opportunity the current setup cannot capture. I cannot point to a survey that measures this the way Gartner has measured boards' growing view of cybersecurity as a business risk: 88% of boards saw cybersecurity as a business risk by late 2021, up from 58% five years earlier. That data exists for security. As far as this research found, it does not yet exist for identifiers specifically, and I want to be honest that my own observation is exactly that — an observation, not a measured trend.

If the earlier pattern holds, that is usually what the early stage of a shift like this looks like: visible in individual conversations well before anyone has measured it in aggregate, and long before there is an agreed name for it. Cybersecurity's own data offers a useful caution, too. Even where boards clearly recognise a risk, actual accountability can lag for years behind that recognition — Gartner's same research found that 85% of organisations still held a technical role, not the board, accountable for it, and only 12% had a dedicated board-level committee. Recognition and ownership are not the same thing, and I would not assume identifiers are further along than that.

None of that makes the pattern certain. But it is consistent with what the precedents opening this article already show: the absence of an agreed name for something has rarely meant the underlying discipline wasn't already being practised. More often, it has meant the industry hadn't caught up with itself yet. If identifiers are on the same curve, the practice is already the leading indicator — any name, if one arrives, will simply be catching up to what is already happening.

Wondering where your own estate stands? Arrange an assessment