In the good old ISDN/SS7, both the network-provided caller-id as well as the user-provided caller id are transported, even in case the caller wants to perform an anonymous call. Usually the last hop before delivering the call to the called party is responsible for removing the relevant information. In SIP, the same exists with From- and P-Asserted-Identity headers.
The SS7 interconnection partners usually go through extensive tests before allowing you to hand over signaling traffic via SS7, but this is not so much the case for SIP interconnects, where we're lacking a bit of clear standards (however working groups like http://www.sipforum.org/sipconnect exist and are taken more seriously nowadays).
If you are allowed to do "CLIP no screening" - which means you can set arbitrary caller ids in the user-provided part, the terminating system (the hop delivering it to the called party) is still able to check both fields, so this could be a way to pin down the real calling party, even if it "spoofs" its caller id.