Summary

  • Public pages associated with AFRINIC’s election process, court records, receiver notices and service status are useful evidence leads, but this run did not independently verify a specific 2025–2026 order, election result, service incident or completed corrective measure.
  • Durable repair would require evidence that authority, privileged access, prevention, detection, recovery and succession operate as separate, testable control chains rather than as conclusions inferred from titles, uptime or institutional statements.

AFRINIC’s continuity problem is narrower and more consequential than a dispute over whether an institution looks operational. A registry can remain visible to members and the wider Internet while the public record leaves unanswered who may authorise a high-impact change, who can execute it, who records it, who can reverse it and who can review the decision afterward.

That distinction matters because prior coverage has already addressed AFRINIC’s board legitimacy, receivership risk, receiver or accountant management and board composition. The remaining accountability question is operational: what evidence would show that the organisation can preserve number-resource administration through contested authority, personnel change or institutional failure?

The available public record does not answer that question conclusively. AFRINIC maintains public entry points for its 2025 board-election process, court-order archive, receiver information, news chronology and service-status information. The runtime-issued records for this investigation preserve those URLs and identify their publishers, but they do not preserve the historical page contents needed to verify a particular order, election outcome, incident or remedy. The responsible conclusion is therefore not that a control failed or a repair succeeded. It is that the control evidence remains an open accountability requirement.

Four different questions are often collapsed into one

The first question is institutional continuity: does the organisation remain identifiable and does its registry machinery appear available? AFRINIC’s public status endpoint is a lead for checking service events, but status information alone cannot establish uninterrupted service, data integrity, legal authority or the identity of every privileged operator.

The second is formal authority: which court order, corporate filing, election record or other authenticated instrument gives a person or body the power to act? AFRINIC’s court-order archive can help locate relevant instruments, while the Supreme Court of Mauritius, the Mauritius Government Gazette and the Mauritian corporate registry are the places where legal and corporate claims should be cross-checked. An archive maintained by a party to a dispute is not a substitute for the complete judicial record.

The third is practical operational control: who can change registry data, resource records, routing-security material, membership status, credentials or other high-impact state? A title or public announcement does not establish system access. Nor does the continued publication of a registry prove that separation of duties, dual approval or independent review is functioning.

The fourth is durable repair: would the controls still work if a named official left, an emergency credential expired, a court order changed or a dispute prevented one institution from acting? Repair is stronger when it survives personnel and institutional failure. It should be demonstrated through restoration tests, failover evidence, credential-independent succession, protected backups, tamper-evident access records, approval trails and documented exception handling.

What the evidence chain should contain

Prevention begins with least privilege, separation of duties, dual approval, expiring emergency access and documented delegation. For a resource registry, those are not abstract compliance terms. They determine whether one person can make an irreversible change without a second approver, whether emergency access remains active after the emergency and whether a successor can take control without relying on a departing individual’s private credentials.

Detection requires more than an incident notice. Investigators should be able to compare registry and RPKI states, inspect access and approval histories, correlate changes with incidents and identify whether an independent reviewer examined the event. The public record should distinguish a statement that a control exists from a reproducible record showing when it operated and what exception it detected.

Response should be bounded and reversible. A receiver notice may describe operational measures, but such assertions need to be attributed and matched to the legal authority said to support them. The Mauritius Legal Information Institute may provide useful republications of judgments, but a republication is a cross-check, not automatically the complete or controlling court record. Interim orders must be distinguished from merits decisions, and later variations, stays or appeals must be checked before describing a remedy as settled.

Recovery is the point at which continuity becomes testable. A credible recovery record would show restoration tests, failover, protected backups, portability where applicable and retesting of unresolved exceptions. It would also show how members or affected parties were notified and how they could challenge a high-impact action. A functioning endpoint after a disruption may demonstrate availability at one moment; it does not demonstrate recoverability under a different authority or credential set.

External records can add context without resolving AFRINIC’s internal control question. The IANA IPv4 address-space registry can provide limited allocation context. The NRO stability-fund material may illuminate continuity support. ICANN correspondence and ICANN Board materials may show coordination concerns or formal institutional positions. None of those sources, by themselves, establishes who controlled AFRINIC systems, whether a Mauritian order remained effective or whether a corrective measure was completed.

The accountability gap is itself measurable

The absence of independently attestable evidence should not be converted into an accusation. It is, however, measurable. A serious continuity review can ask for a dated authority chain; a current access-control inventory; records of dual approvals; change histories for registry and RPKI systems; incident and escalation notices; recovery-test results; succession procedures; and an exception register showing what remains unresolved.

The same test should be applied to every claimed remedy. What was the prior control? What changed? Who approved the change? What independent record shows that it worked? What happens if the person, board or receiver associated with the remedy is no longer available? Without those answers, “continuity” may mean only that a public endpoint remained reachable.

That is the central distinction for AFRINIC’s next accountability phase. Institutional continuity is valuable, but it is not equivalent to legitimate governance. Formal authority is important, but it is not equivalent to practical control. Practical control is necessary, but it is not equivalent to durable repair. Each claim requires its own evidence chain.

The public leads assembled for this briefing are enough to define the verification plan, not enough to declare its outcome. A later report should compare the complete Mauritian court docket with AFRINIC’s dated notices, corporate filings and system-level evidence. Until then, the bounded conclusion is clear: keeping the registry visible is a necessary condition of continuity, while proving who can authorise, execute, detect, reverse and review high-impact changes is the condition that would make continuity trustworthy.