Summary
- AFRINIC’s current proposal page listed
AFPUB-2026-GEN-002-DRAFT01, the Policy Compliance Dashboard, as “Under Discussion” on 11 August 2026. It is not a ratified rule. - The draft would automate member checks, notices and escalation. It also anticipates procedures for service withholding, resource revocation or member closure, while leaving the persistence threshold and specific rules to staff.
- AFRINIC’s own legal assessment says the text blurs resource policy with contractual enforcement, lacks sufficient procedural safeguards and leaves essential sanction terms undefined.
- The same assessment says the proposed Board exception is vague, and that the draft does not specify the data collected, third-party sources, retention, accuracy checks or a member’s right to challenge a result.
- No member has been shown to have lost services or resources under this unadopted proposal. The immediate news is the warning inside AFRINIC’s own file: the bridge from useful monitoring to punishment has not been safely designed.
The red flag is inside AFRINIC’s own assessment
The strongest objection to AFRINIC’s proposed Policy Compliance Dashboard does not come from an outside campaign. It appears in the legal section of AFRINIC’s own impact assessment, dated 23 June 2026.
The draft begins with a defensible problem. A resource member may not track every change to the Consolidated Policy Manual. A missed update can matter because the Registration Services Agreement, as the proposal describes it, allows serious consequences for non-compliance. The authors call those potential consequences catastrophic for a business. Their answer is a dashboard inside MyAFRINIC that would show each member its status, issue notices and give it a chance to correct mistakes.
That is the protective case for the proposal. AFRINIC’s legal assessment does not reject monitoring itself. It says the most serious problem is what the draft attaches to the monitor.
The text would notify staff when non-compliance persists. But staff would later define how long “persistent” means. Staff would publish the operating procedure. Specific rules for withholding services, revoking resources or closing a member would also be defined later. A separate clause says the Board may take “special measures” where revocation involves essential strategic infrastructure, natural disaster, political instability or another exceptional situation.
In other words, the dashboard supplies a machine-visible beginning to a decision chain, while the most consequential human decisions remain open.
A compliance state could become an enforcement input
The impact assessment shows that the proposal is more than a coloured status panel. AFRINIC staff describe automated checks against WHOIS contact accuracy, abuse-c validity, route-object consistency, RPKI ROA coverage where relevant and reverse-DNS requirements. Each finding would move through logged states such as compliant, first notice, second notice, remediation, escalated and closed. State changes would carry timestamps and trigger emails.
Those functions can improve visibility. A stale contact or inconsistent route object is easier to correct when the holder can see it. An audit trail can expose whether notices were actually sent. Automation can also reduce the unequal timing that comes from reviewing some members manually before others. That was a central argument advanced by an author in the 2020 appeal after an earlier version failed to reach rough consensus.
But an indicator is not a judgment. Some checks are binary: an object exists or it does not; an address answers or it does not. Others depend on context. AFRINIC’s legal assessment names needs justification, utilisation and documentation as examples requiring qualitative evaluation. A machine can flag a field. It cannot decide, without a disclosed rule and review, whether the underlying conduct justifies impairing a network’s resource rights.
That distinction is the point at which administrative convenience becomes institutional power. If “escalated” is merely a request for human review, the dashboard is a warning instrument. If it becomes evidence for withholding a service, revoking resources or closing membership, it enters an adjudicative chain. The draft does not yet specify the evidentiary standard, decision maker, cure period, proportionality test, independent appeal or restoration path for that chain.
AFRINIC’s lawyers identify four missing boundaries
The legal assessment first warns about scope. Resource policies are developed through the Policy Development Process. Contractual compliance and enforcement ordinarily arise under the RSA. Using a policy proposal to create new contractual remedies could cause enforceability problems, the assessment says. The text needs to distinguish monitoring existing obligations from inventing a new sanction.
Second is delegation. “Persistent non-compliance”, the operating procedure and the specific sanction rules are essential elements, not minor implementation details. Leaving them to future staff definition means members cannot know from the policy itself what conduct crosses the line or what follows.
Third is due process. The assessment says the draft does not provide sufficient safeguards and may expose AFRINIC to allegations of procedural unfairness, arbitrary decision-making and unequal treatment. That is conditional language, not a finding that such conduct has occurred. It is nevertheless unusually direct for an organisation’s own assessment of a proposal still before its community.
Fourth is data. The draft does not say what member data will be collected, how a compliance result will be calculated, whether third-party sources will be used, how long the data will be retained, how accuracy will be checked or how a member can challenge it. These are not peripheral privacy notices. They determine whether a member can inspect and rebut the evidence before a registry action affects services or number-resource continuity.
The Board exception reverses the accountability test
Clause 6 would allow the AFRINIC Board to take special measures when revocation touches essential strategic infrastructure or when natural disaster, political instability or another exceptional situation exists. The stated aim is continuity. The drafting problem is that none of the controlling terms is defined.
AFRINIC’s legal assessment calls the language overly broad and vague. It specifically identifies “special measures”, “essential strategic infrastructure”, “political instability” and “exceptional situations” as undefined, and warns that the discretion may be insufficiently constrained.
A true safeguard should narrow power. This clause could instead let the Board decide who qualifies for relief after staff have moved a case toward sanction. It does not say whether the exception must be requested, whether reasons must be published, how conflicts are handled, how long relief lasts or whether comparable cases must be treated alike.
That matters in AFRINIC’s current governance setting. The organisation announced a Board in 2025, while NRS continues to dispute the election’s legal finality. AFRINIC later said an Interim Management Committee was created with Receiver consent and would report jointly to the Board and Receiver. Those facts do not prove the Board invalid, and they do not show that it adopted or used this dashboard proposal. They do show why any new discretionary Board power requires a precise legal source, published limits and an auditable decision record rather than an institutional title alone.
Heng Lu’s doctrine supplies the correct test: who can classify, escalate, exempt and enforce; who bears the downside of a wrong answer; and what liability or remedy follows. A registry staff member or director does not carry the same business loss as the network whose addresses, reverse DNS, routing records or service relationship may be impaired. Power without matched consequence must therefore be bounded before it becomes operational.
The proposal has already travelled this road
This is not the first Policy Compliance Dashboard debate. In 2020, an earlier version failed to reach rough consensus. The recorded objections included redundancy, the absence of a comprehensive system for Board action, resource cost and the argument that the subject belonged to administration. The author appealed, arguing that automation could reduce human error and prevent members from being checked at unequal times.
A 2021 Draft 2 went further. It described a three-month escalation and resource-recovery sequence. Its own legal assessment recommended limiting the policy to dashboard visibility and leaving contract management to the Board acting through management. In 2022, an author again argued that the community could set core protections while staff handled operational detail.
The 2026 draft removes some prescriptive timing but does not resolve the boundary. It shifts decisive definitions back to staff and adds an open-ended Board exception. AFRINIC’s current legal assessment therefore reaches a familiar conclusion in stronger form: monitoring is possible, but sanctions, appeals and revocation should be established separately through transparent procedures and contractual instruments with due-process safeguards.
Visibility first, punishment only after a public control record
AFRINIC’s own recommended sequence is the practical starting point. Launch visibility-only reporting first. Add member notifications. Build a staff-review workflow. Consider enforcement-related steps only later, after systems, procedures, staffing and communications are ready.
For that sequence to protect members rather than merely stage the rollout, the public control record would need more detail. Every automated check should disclose its input, rule, confidence state, update frequency and known limitations. A member should see the evidence and correct the data before escalation. A human reviewer should record why the flag is accurate, which obligation applies and why the proposed response is proportionate.
Enforcement would require an adopted notice and cure procedure, an independent appeal, conflict rules, a reasoned written decision, a restoration path and published aggregate statistics on false positives and reversals. Board exceptions should be narrow, time-limited, reasoned and reviewable. A service affecting routing, registration or resource recognition should not be withheld solely because a dashboard cell changed colour.
The LARUS-hosted governance opinion, although focused primarily on APNIC, reinforces the structural point: the legal allocation of actual corporate authority matters more than the optics of an elected body. NRS’s present demand for transaction-specific authority records applies the same documentary discipline to AFRINIC. These are analytical positions, not court judgments on the proposal.
The bounded conclusion is sharper because it does not overstate the event. AFRINIC has not ratified this draft. The packet shows no member sanctioned under it. What changed on 23 June was the evidentiary record: AFRINIC’s own legal review put the unresolved power chain in writing.
The dashboard is not the central threat. The dangerous step is allowing a monitoring signal to become a sanction input before the organisation has defined evidence access, human review, due process, proportionality, appeal, restoration and the limits of Board discretion. Until those conditions exist in an adopted public instrument, the only defensible dashboard is one that informs a member without deciding its fate.
Readers seeking the wider distinction between a registry record, reliable contactability and adjudication can consult the separate BTW research listed below. That longform is further reading; this briefing reports the dated 2026 proposal assessment and its current under-discussion status.
Sources
- Heng Lu: who gets to speak for a continent, a community or the end user
- Heng Lu: when registry power detaches from liability
- Heng Lu: power, legitimacy and the AFRINIC lock-in
- Heng Lu: the agency problem at the core of Internet governance
- AFRINIC Policy Compliance Dashboard proposal and impact assessment
- AFRINIC current policy proposals
- AFRINIC membership agreements
- AFRINIC Bylaws 2020
- AFRINIC Resource Policy Manual
- AFRINIC Policy Compliance Dashboard Draft 2, 2021
- AFRINIC32 record of the 2020 no-rough-consensus decision
- Appeal against the 2020 non-consensus determination
- 2022 author response on the dashboard proposal
- AFRINIC Board Updates, 19 November 2025
- NRS member action on the AFRINIC authority chain
- LARUS-hosted legal opinion on RIR governance structures
- BTW research: what AFRINIC’s RDAP and Whois records make visible


