Summary

  • AFRINIC's reconstituted board is a necessary repair, not proof that concentrated institutional risk has disappeared. The crucial question is whether a member can maintain recognised records and critical dependencies when AFRINIC is legally, technically or operationally impaired.
  • Registry-service portability is not a sale of address space, a change of holder or permission for duplicate authorities. It is the ability of the same recognised holder to move defined registration services between qualified providers while one ordered authoritative state and complete history remain intact.
  • Portability requires four distinct arrangements: ordinary voluntary provider substitution, supervised movement during serious service failure, temporary emergency continuity and eventual institutional succession if recognition changes. Each has different triggers, authority and return conditions.
  • Data escrow is necessary but limited public evidence. A continuity design also needs tested restoration, current identity and authority evidence, ordered transaction history, dispute restrictions, RDAP and WHOIS publication, reverse DNS, routing registry data and carefully bounded RPKI key and certificate handling.
  • AFRINIC's 2025-2026 recovery programme addresses leadership, audits, technology, staffing, community bodies and legal stability. Those measures improve the incumbent institution but do not yet establish a routine holder-controlled exit or a demonstrated provider substitution path.
  • The emerging revision of the global RIR governance framework recognises emergency continuity and temporary operators. An NRS-style approach would extend the resilience principle into normal times through qualified choice, without waiting for the extreme threshold of regional registry failure.
  • Recovery should be judged by independent stress tests: loss of the member portal, data corruption, court restraint, key compromise, insolvency, staff unavailability and a voluntary provider move. Passing means one accepted current state, no loss of holder control and a clean return or cutover supported by evidence.

A board repairs authority, not concentration

The NRO welcomed the September 2025 board election as a step toward full restoration of AFRINIC's governance and activities. That language was appropriately measured. A step toward restoration is not a declaration that every institutional weakness has ended.

The reconstituted board can do things that a receiver or staff operating without directors cannot do sustainably. It can set strategy, recruit a chief executive, approve budgets, oversee risk, convene members and restore committees. AFRINIC's October 2025 joint statement by the board and Receiver described ongoing work on leadership, audits, litigation, community representation, policy discussion and constitutional reform. Its March 2026 member update described priorities including stable operations, a substantive chief executive, technology and human-resources evaluation, and governance repair.

These are real recovery tasks. They are directed primarily at making AFRINIC function well again. They do not give a resource holder an alternative if AFRINIC later cannot perform a critical registration act. The holder still depends on the same legal entity, operational team, service interfaces and recognition arrangement.

Good directors can lower institutional risk. Portability changes who bears the residual risk when good governance is not enough. A resilient design needs both.

The crisis was broader than the absence of directors

AFRINIC's difficulties cannot be reduced to eight empty board seats. Litigation affected governance and consumed attention. Receivership placed unusual authority in a court-supervised office. Audited financial statements were delayed. The policy community went years without ordinary meetings. The organisation lacked a substantive chief executive. Questions arose about records, backups and election integrity.

Staff kept core services running through these conditions, which is evidence of commitment and some operational resilience. It is not evidence that every service would survive a more severe or differently timed failure. Continuity achieved by exceptional staff effort can mask undocumented dependencies and concentrated knowledge.

The public consequence also extends beyond AFRINIC's corporate status. Network operators rely on recognised resource records when maintaining contacts, reverse DNS, route objects and routing-security material. Public agencies, universities, banks, mobile operators, data centres and access providers can all depend on timely changes. A dispute that does not interrupt packet forwarding today can still prevent a holder from correcting authority or responding to an incident tomorrow.

The relevant risk is therefore compound. Legal authority, corporate governance, staff capacity, member identity, technical publication and global recognition interact. Replacing directors addresses one layer. Recruiting a chief executive addresses another. Neither creates an alternative path when several layers fail together.

Registry failure is not the same as an Internet outage

Care is needed when describing consequence. If an RIR portal becomes unavailable, existing routes do not automatically vanish. Routers forward according to configurations and routing protocols, not by querying the membership office for every packet. Existing address use may continue during a registry dispute.

That does not make registry continuity optional. A holder may need to update public contacts, create or change route authorisations, alter reverse DNS, register a transfer, correct a route object, respond to an abuse or security issue, or prove authority to a counterparty. Delay in those acts can increase operational risk even when traffic still flows.

RPKI makes the dependency more visible. Resource holders use certificates and route origin authorisations within a trust structure described by the RPKI architecture in RFC 6480. A failure affecting certificate issuance, key control, publication or revocation can influence how relying networks classify routes. The effect depends on the exact failure and on network policy; it should not be exaggerated into instant universal disconnection.

Resilience analysis should therefore measure functions separately. Public registration, account control, RDAP, WHOIS, reverse DNS, Internet routing registry data, RPKI, new allocation and transfer service have different tolerances and recovery paths. A vague assurance that the Internet stayed up cannot substitute for evidence that holders retained the ability to act.

Personnel recovery changes probability, not blast radius

A competent board may improve controls, settle priorities and reduce the chance of another governance breakdown. It may also recruit leaders, fund backups and clarify authority. These measures matter because prevention is usually cheaper than emergency substitution.

But the blast radius of failure remains large if one institution is the mandatory service point for a region. A court restraint, severe cyber incident, internal control failure, insolvency event or loss of key staff can affect many holders at once. Better people reduce the likelihood of those events; they do not give affected members a tested exit if one occurs.

This is the same distinction made in other critical services. A well-run provider still maintains failover, exports and recovery drills. Confidence in management is not used as a reason to make customer data non-portable or to leave restoration untested. The higher the public consequence, the weaker the case for relying only on institutional virtue.

Portability also disciplines ordinary performance. A provider that knows holders can move service has a stronger reason to keep records accurate, resolve complaints and publish measurable service levels. Exit is not a punishment. It is a control that limits the consequence of persistent failure without requiring the whole institution to be replaced.

Portability must be defined narrowly

Registry portability should mean that a recognised resource holder can change the qualified provider performing defined registration services while the holder, resource identity, allocation history and authoritative current state remain the same. The provider authenticates instructions, maintains agreed service records and submits or executes permitted changes. It does not create a rival allocation.

The definition excludes three misleading interpretations. First, portability is not a claim that addresses are unrestricted private property. The legal character of number resources and the terms under which they are held remain governed by applicable agreements, policy and law. Second, it is not a transfer to a new holder. The organisation controlling the resource does not change merely because its registration service changes. Third, it is not authority for several providers to publish conflicting current holders.

The Internet Numbers Registry System described in RFC 7020 depends on coordinated registration and uniqueness. A portability model must preserve those properties. One resource has one accepted current holder state, one ordered history and defined current authority for each service role.

This narrow definition makes portability compatible with global coordination. Competition or substitution occurs around service. Uniqueness remains a shared constraint. The right to leave one provider does not become a right to choose whichever version of the facts is most convenient.

Four movements must not be confused

The first movement is a resource transfer. It changes the recognised holder of some number resource under applicable transfer policy. AFRINIC's policy overview ratified in February 2026 addresses transfers involving IPv4 and autonomous system numbers, including specified inter-regional conditions. That is a market and registration event involving source and recipient.

The second movement is registration-service portability. The holder remains the same, but a qualified provider takes over defined administrative service. No sale or reassignment is implied. The event resembles changing the custodian of a record rather than changing the person recognised by it.

The third movement is emergency continuity. A temporary operator performs affected services because the recognised regional institution cannot do so adequately. Authority is bounded by the emergency, and service should return when capability is restored. The holder need not make an individual market choice during the crisis.

The fourth movement is institutional succession. If an RIR is ultimately replaced or its recognition changes, an authorised successor assumes regional responsibility under a global governance decision. That is a constitutional event, not ordinary customer switching.

Policies, records and technical controls should name these movements separately. Confusion invites either overreach or paralysis. A normal provider change should not require the threshold for replacing an RIR. An emergency operator should not gain power to rewrite holder history. A resource transfer should not be disguised as a service switch.

NRS supplies a direction, not proof of a finished system

The Number Resource Society has made exit, portability, redundancy and less geographically captive administration central themes of its public advocacy. Its governance statement on decentralisation and portability offers a useful direction: critical number-resource administration should not depend solely on the durability of one gatekeeper.

That direction should not be treated as evidence that every operational detail has already been solved. Identity assurance, provider qualification, authoritative ordering, RPKI continuity, lawful restrictions, liability and global recognition all require exact arrangements. Advocacy becomes infrastructure only after those arrangements survive adverse tests.

The value of the NRS counterfactual is that it asks a question the regional-monopoly design tends to suppress. Why must preservation of one authoritative number record require one permanent service provider for every holder associated with a continent? Global uniqueness and service exclusivity are different properties.

AFRINIC recovery is an opportunity to test that distinction without weakening the institution. AFRINIC could remain a recognised authority and a strong provider while participating in common portability rules. The objective is not to make AFRINIC fail. It is to make member continuity less dependent on AFRINIC never failing.

One authoritative state is the non-negotiable boundary

Portability becomes dangerous if two providers can each assert a different current holder or issue incompatible resource credentials. The system must therefore order every accepted change against a known current version. A service switch cites the resource, holder, outgoing provider, incoming provider, affected roles and current state. Acceptance creates one successor state.

Competing submissions cannot both succeed. A stale instruction fails or enters review. A correction creates another visible event rather than erasing history. Every qualified provider and public service converges on the accepted result. Observers may replicate the record, but replication does not grant origin authority.

The NRO's Internet Number Registry System agreement commits RIRs to uniqueness, accuracy, public entries and cooperation in consistent global registry services. Portability must strengthen those commitments by reducing dependence on one service office while preserving one coherent answer.

This boundary also limits provider marketing. No provider should promise immunity from valid restrictions, anonymous control or alternative recognition. A holder may choose service quality and jurisdictional terms within common rules. It may not purchase a second version of title or escape an active dispute by moving the interface through which the dispute is recorded.

The minimum portable record must be sufficient and restrained

A receiving provider needs enough information to continue service but should not receive every note, invoice or identity document ever held by the outgoing institution. The common minimum should include resource identity, recognised holder, authority contacts, allocation or assignment basis, current serving provider, ordered event history, active restrictions, pending requests, dependent-service choices and verification evidence at an agreed assurance level.

Each field needs a version, source authority, effective time and sensitivity class. Public facts can appear through RDAP or related services. Protected identity and dispute material moves through secure channels. Highly sensitive evidence may remain with an escrow custodian and be disclosed only when a valid trigger occurs.

Restraint limits concentration and breach impact. A portability system that centralises every customer document creates a new target and may violate data-protection duties. Sufficiency means the receiving provider can authenticate the holder, reconstruct current authority, continue selected services and explain why a change was accepted. It does not mean collecting information unrelated to those functions.

The holder should be able to inspect its portable record, challenge errors and receive a signed export at any time. Regular export makes departure ordinary rather than an emergency favour. Independent tests should confirm that another qualified provider can ingest the record without manual reconstruction by the incumbent's senior staff.

Escrow preserves evidence but does not deliver service

ICANN's July 2025 correspondence asked about AFRINIC backups and proposed discussion of regular RIR registration-data escrow with trusted providers. That was an important intervention. If the only complete record disappears with a failing institution, no continuity model can restore authority confidently.

Escrow answers a narrower question than portability. It can preserve files and transaction history. It does not automatically authenticate a current holder, activate a receiving provider, publish RDAP, maintain reverse DNS, issue RPKI material or resolve a court restriction. Deposited data may be stale, incomplete, encrypted under unavailable keys or difficult to restore within the time that operators need.

A credible arrangement therefore tests deposit frequency, completeness, integrity, decryption, documentation, release triggers and restoration time. The escrow custodian must be independent enough to release material when the institution is unable or unwilling, but unable to use the data for ordinary commercial service. Several geographically and legally separated custodians may be warranted for the most critical elements.

Escrow should support both institutional emergency and holder portability. A receiving provider normally obtains a current export through the outgoing provider. If that route fails, a supervised release can provide the minimum record. Every release is scoped, logged and reviewed. Data survival becomes one layer in an operational continuity design rather than the whole promise.

Identity and authority must survive the institution

The hardest continuity problem is not copying a table. It is proving who may instruct a change when the institution that maintained the contact record is unavailable or distrusted. A portable model needs several independently maintained authority factors: current organisational officers, protected recovery contacts, strong credentials, verified corporate evidence and a history of authorised changes.

No single stale email address should control a valuable resource portfolio. Holders should register more than one representative with different roles and channels. High-impact acts can require approval from two authorised people or one person plus an external organisational proof. Recovery contacts should be tested periodically without publishing them.

The receiving provider must verify continuity of holder identity, not create a new holder because the usual account is inaccessible. If evidence conflicts, the resource enters a bounded protected state. Existing public records and services continue where safe, while high-risk changes wait for review. The dispute should affect only the contested act and resource set.

Authority evidence also needs portability before crisis. A holder that waits until the portal is inaccessible to discover that its only contact left the company has already failed the test. AFRINIC recovery should include a member campaign to verify multi-channel authority and issue portable, independently verifiable receipts.

RDAP and WHOIS need continuity without contradictory answers

Public registration services allow networks, security teams and counterparties to identify recognised organisations and contacts. During provider substitution, those services should continue to return one coherent current state. Different service endpoints may exist, but discovery must lead users to the same accepted record.

A provider switch should update the serving-provider reference and any authorised contact changes without changing the resource's history. Caches and replicas need defined convergence times. Stale responses should carry a version or last-update time that lets users recognise them. A temporary emergency response should identify its bounded status without implying that the resource changed holder.

RDAP's structured responses are useful for expressing roles, links and events, but a technical format cannot settle authority by itself. The common rules must define which service signs the current result, how conflicts are resolved and when a replica stops serving stale data. WHOIS compatibility may remain necessary for users that have not moved to RDAP, but it should derive from the same accepted state.

Continuity tests should query public services from several regions before, during and after a simulated provider move. Success means availability, consistent holder identity, correct role changes and explainable version order. Returning an HTTP response is not enough if two endpoints disagree about control.

RPKI continuity requires stricter boundaries than public registration

RPKI connects resource authority to cryptographic entities used by relying networks. Moving registration service must not casually move private keys, create overlapping certificates or leave both providers able to authorise routes. The holder's chosen RPKI model matters: hosted service, delegated certification or another approved arrangement can place key and publication duties in different locations.

The portability record should state the current certificate authority relationship, publication location, authorised prefixes and autonomous system numbers, key-custody model, active route origin authorisations, revocation status and planned cutover. The outgoing and incoming providers need an ordered handoff with explicit authority termination.

Where keys cannot or should not move, the receiving side issues a successor under controlled conditions and the old authority is revoked at the right time. Overlap may be tightly bounded where required to avoid validation failure, but dual uncontrolled issuance must never be an informal convenience. Relying-party observation should confirm the intended result from outside both providers.

Emergency continuity is harder. A temporary operator may need authority to keep publication available while lacking authority to make arbitrary routing changes. The emergency charter should distinguish serving existing entities, renewing time-limited material, accepting holder changes and revoking compromised authority. Each power needs a trigger and independent approval.

Reverse DNS and routing registry data need explicit choices

Registration service often sits beside reverse DNS delegation and Internet routing registry data. Holders may assume these dependencies will move automatically, while providers may treat them as separate products. A portability request should list each service and let the holder choose move, continue temporarily, delegate elsewhere or end.

Reverse DNS continuity requires preservation of the resource-to-zone relationship and secure control over delegation changes. A provider switch should not silently alter name servers. If the old provider continues service briefly, the arrangement needs an expiry and emergency contact. Tests should verify resolution from independent networks and confirm that stale delegations are removed only after the new service is ready.

Route objects and set memberships can influence filters built by network operators. The handoff should identify maintained entities, authentication method, maintainers, references and downstream set relationships. Duplicate or abandoned maintainers can create security and operational confusion even when the resource record itself is correct.

Separating dependencies prevents an all-or-nothing move. A holder may change account and RDAP service while retaining delegated RPKI, or move RPKI while keeping reverse DNS temporarily. The authoritative record must show the chosen division so that no provider claims more authority than it has.

Court orders and disputes must travel as restrictions, not captivity

Portability cannot become a method for escaping a valid court order, active ownership dispute or security hold. Equally, the existence of one dispute should not let an incumbent freeze every unrelated service and resource indefinitely. The portable state must carry restrictions with exact scope, issuing authority, effective time, review status and expiry condition.

The receiving provider accepts the restriction as part of the current authoritative state. It does not relitigate the matter merely because service moved. If the provider believes the order does not bind it or conflicts with another obligation, a defined recognition and review route applies. The holder receives notice to the extent law permits.

This approach separates institutional exit from factual erasure. A holder can leave poor service while a contested transfer remains blocked. Clean resources in the same portfolio can move when the restriction is severable. Existing route-security entities may continue while a high-risk change waits for decision.

Courts benefit from exact records. They can see which act is proposed, which provider controls it, which state preceded it and what continuity impact a restraint would have. Portability should make lawful orders more precise, not less effective. The strongest design protects both reviewable legal authority and operator continuity.

Jurisdiction should be visible rather than hidden inside geography

Changing service provider can change contract law, data location, enforcement routes and exposure to government demands. Portability does not abolish jurisdiction. It requires that jurisdictional consequences be disclosed and assigned to the correct relationship.

Each provider should publish its legal entity, controlling persons, service locations, governing contract, data-handling commitments, subcontractors, complaint forum and approach to conflicting legal demands. Holders can then select service suitable for their operational and public duties. The common authority rules still bind every provider.

Some acts remain connected to AFRINIC's incorporation, regional recognition or the holder's own jurisdiction. A provider cannot promise that choosing it removes those connections. Nor should AFRINIC claim permanent service exclusivity merely because its legal home is Mauritius. The relevant question is which law applies to which act, evidence and party.

Conflicting demands need a narrow protocol: verify the authority, identify the affected resource and service, preserve current state, notify permitted parties, seek review and avoid irreversible action while jurisdiction is unresolved. This is more credible than treating an address block as if it were physically located in one court territory.

Qualified providers must be capable of failure-safe service

Portability is only as strong as the receiving providers. Qualification should test identity assurance, record protection, incident response, export quality, service continuity, legal capacity, financial security, conflict controls and ability to retire authority cleanly. Admission should be based on demonstrated function rather than political sponsorship or geographic pedigree.

Every provider should pass a migration test before serving live holders. It must ingest a realistic record, identify stale or conflicting evidence, preserve history, continue selected dependencies, reject a stale instruction and produce a complete signed exit package. The test should include its own loss of staff or primary infrastructure.

Qualification must not create a cartel. Requirements should be proportionate, public and appealable. Smaller specialist providers may use shared infrastructure if control, liability and subcontracting are transparent. A supervised entry tier can limit portfolio size while capability is proven.

Performance should remain visible after admission. Metrics include correction time, export completeness, switch success, security incidents, complaint outcomes, service availability and concentration. Repeated failure should restrict new business and ultimately trigger orderly removal. Existing holders must retain exit even when a provider is sanctioned.

AFRINIC could qualify as a provider within this model and may remain the preferred choice for most regional members. Portability tests its service proposition without denying its accumulated expertise.

Emergency continuity should be bounded and reversible

The second draft of the proposed RIR Governance Document includes an emergency-continuity concept under which other RIRs and ICANN could authorise a temporary operator when an RIR cannot adequately provide affected services. It calls for published scope and rationale, community engagement and eventual review. As of mid-2026, that broader revision remained under development rather than a final replacement for ICP-2.

This is an important recognition that RIR continuity cannot depend only on internal recovery. The design still needs operational detail: which services receive priority, how authority is activated, which data and keys are available, how the temporary operator is supervised, how extensions work and how service returns.

Emergency authority should be narrower than ordinary RIR governance. A temporary operator maintains affected services and protects current state. It does not rewrite regional policy, redistribute contested resources or entrench itself. Material acts receive additional review, and every extension carries evidence.

Reversibility matters as much as activation. When AFRINIC restores capability, the emergency operator must deliver current records, retire credentials and cease publication according to an ordered handback. An independent post-event report should reconcile every act. A continuity measure that cannot return authority cleanly is a takeover mechanism, not a safeguard.

Ordinary portability fills the space before emergency

Emergency continuity is designed for severe institutional inability. Many damaging service failures fall below that threshold. A member may face months of delay, inaccessible account recovery, unresolved record error or poor support while AFRINIC remains broadly operational. Other RIRs and ICANN are unlikely to activate regional emergency arrangements for one holder.

Ordinary portability gives the holder a proportionate remedy. It can move defined service to a qualified provider after authentication, notice and a bounded objection period. The authoritative state remains intact. AFRINIC can correct a legitimate concern without holding the member indefinitely.

This normal route also prepares the emergency route. Common exports, provider interfaces, versioned events, qualified recipients and routine cutovers are exercised regularly. In a crisis, continuity uses capabilities already proven with consenting holders rather than documentation first opened during institutional failure.

The relationship resembles fire safety. Emergency services remain necessary, but buildings also maintain exits used and inspected under ordinary conditions. A door that is legally promised but never opened is weak protection. Registry portability makes exit an operating capability before the region depends on it.

Public-sector holders need continuity choices before crisis

Government networks, hospitals, universities, research networks and public utilities may rely on number resources for services that cannot wait for a long institutional dispute. Procurement rules, public records law, national security duties and continuity obligations may also constrain which provider can hold identity evidence or operate critical services.

A portable model lets a public body choose a qualified provider with suitable legal and operational arrangements while remaining within one authoritative number system. It can designate a standby provider, maintain tested exports and preapprove emergency contacts. These arrangements should be visible to oversight bodies without exposing sensitive network details.

Public-sector continuity also needs priority rules. Priority should reflect service consequence, not political influence or portfolio size. A hospital network may require faster restoration of reverse DNS or RPKI control than a dormant holding company, but both retain the same right to accurate records and due review.

Annual exercises should include public-sector scenarios: office closure, leadership turnover, restricted procurement, national disaster, conflicting government demands and loss of a primary contact. The test asks whether authority can be recovered without bypassing law. Waiting until an emergency to negotiate jurisdiction, evidence and payment is not resilience.

Small operators must not receive only a theoretical exit

Large networks can retain counsel, maintain multiple contacts and build custom continuity. Small access providers and community networks are more likely to depend on the default portal, one staff member and standard support. They need portability most and may be least able to use a complex version of it.

The basic service should therefore include a plain export, clear dependency inventory, predictable fees, assisted identity recovery and access to at least one qualified receiving provider. No incumbent should charge a punitive departure fee or require bespoke negotiation. Debt can follow ordinary contract remedies unless a narrow rule makes it relevant to the specific act.

Provider qualification costs should not be passed to small holders through mandatory premium packages. A common minimum can be funded through ordinary registry fees or a shared continuity levy. Higher assurance and bespoke services may cost more, but practical exit must remain available to every recognised holder.

Success metrics should be segmented by holder scale. A system that works only for multinational operators has not reduced regional concentration risk. Test cases should include stale contacts, limited English proficiency, low-bandwidth access, a mixed resource portfolio and a request submitted outside the provider's local business hours.

A portability stress test should precede claims of resilience

AFRINIC and any qualified provider should complete an independently observed annual exercise. The test portfolio should contain realistic resource records and dependencies without endangering production networks. Ordinary staff should handle it through normal service channels. Senior intervention should be recorded rather than used invisibly to rescue the result.

The exercise begins with a holder-authenticated export and provider-switch request. It tests evidence completeness, objection handling, receiving-provider readiness, authoritative version control, public-service convergence, dependency choices and post-cutover access. A second scenario activates temporary emergency service after simulated loss of the primary institution.

Time limits should follow consequence. Public RDAP and WHOIS continuity may tolerate only brief disruption. High-risk changes may pause safely while identity is resolved. Existing RPKI publication may need continuous availability even when new authorisations are restricted. The test should publish both targets and observed outcomes.

An exercise passes only when independent evidence shows one current authority at every stage, no holder identity change, no lost history, no unbounded dual control and a clean closure. Delivery of a backup file is not a pass. The receiving side must use it to provide defined service.

Seven failure cases reveal whether recovery is structural

The first case is loss of the member portal for several days while public registration remains available. Can authorised holders submit urgent corrections through a verified alternate channel? The second is corruption of a recent transaction set. Can replicas and receipts identify the last good state without erasing accepted changes?

The third is a court order restraining a defined AFRINIC act. Can the restriction be applied narrowly while unrelated holder service continues? The fourth is suspected compromise of a RPKI service key. Can publication and revocation be managed without giving a temporary operator unrestricted route-authorisation power?

The fifth is insolvency or sudden inability to pay critical vendors. Are data, domains, certificates and service contracts insulated long enough to activate continuity? The sixth is loss of several key staff members. Can another team reconstruct authority from records rather than private memory?

The seventh is an ordinary voluntary switch by a dissatisfied but undisputed holder. Can the move finish within the promised time while AFRINIC remains fully operational? This last case is especially revealing. An institution that can support only emergency replacement but not normal exit still controls continuity as a favour.

Results should state which acts succeeded, failed or required extraordinary intervention. Scenario variation prevents rehearsed theatre. Repeated failure should change qualification, funding and remediation priorities.

Metrics should measure holder control and coherent public state

The primary metric is end-to-end time from a valid switch or continuity trigger to independently verified service. Stage measures include authentication, export, objection, receiving readiness, authoritative commit, public convergence and dependency completion. Long-tail cases should be visible rather than hidden by averages.

Quality measures include record completeness, version consistency, active-restriction accuracy, holder access, absence of conflicting current authority and correct retirement of outgoing credentials. Public services should be queried from diverse networks. RPKI outcomes should be observed by relying systems rather than inferred from an internal success message.

Continuity measures include recovery point, recovery time, percentage of critical services restored, duration of temporary authority and completeness of handback. Holder-experience measures include notice clarity, stable requirements, complaint time and unexpected manual steps.

Market measures also matter: number of qualified providers, concentration of served resources, switching rates, failure rates and effective cost for small holders. High switching is not automatically good, and low switching is not proof of satisfaction. The key is whether a safe switch is available and tested.

Every metric needs a denominator and an independent evidence source. Claims such as all critical services restored are meaningless unless the service list and excluded functions are named. Resilience should be an observed property, not a description chosen by the incumbent.

Liability should follow the failed role

Portability divides functions among the common authority layer, serving provider, escrow custodian, identity verifier, emergency operator and holder. Accountability must follow that division. A provider that loses an export should not blame the common record. An authority that commits a conflicting state should not shift responsibility to the provider that submitted a valid instruction.

Contracts should define correction duties, indemnities, insurance or reserves, evidence custody and compensation for missed service levels. Baseline remedies can be automatic for measurable delay or data failure, while larger proven losses follow review. Liability caps should not make deliberate misconduct or gross custody failure economically harmless.

The holder also has duties: maintain current contacts, protect credentials, disclose control changes and respond to verification. Failure can justify a bounded pause. It should not let providers confiscate practical control forever.

Independent review resolves role disputes and preserves continuity while responsibility is determined. The reviewer can order temporary access, record correction or limited service without deciding every damages claim. Public aggregate outcomes reveal whether one role repeatedly fails.

Clear liability makes portability more credible and less political. Providers compete on service while knowing the cost of bad custody. The common authority remains answerable for coherence. Holders know which promise applies when something breaks.

Governance of the common layer must resist provider capture

A portable service market still depends on common rules and authoritative ordering. Providers should not control those rules in proportion to the resources they serve or the fees they collect. Otherwise the largest companies can exclude rivals, weaken exit or write qualification standards around themselves.

Governance should separate provider interests, holder representation, technical expertise, public-interest oversight and independent review. Conflicts are disclosed. Decisions affecting switching, fees or qualification require reasons and impact analysis. The operator of the common authority should not secretly sell privileged service.

AFRINIC members should retain meaningful regional influence over policies that affect allocation and use. Portability does not require institutional merger or loss of local knowledge. It requires that service captivity not be used as the mechanism for preserving regional voice.

The common layer should be narrow enough to audit: resource identity, current holder, current provider roles, ordered events, active restrictions and verifiable receipts. Expanding it into every customer-service function recreates the same concentration at a new level. Reducing it to a loose directory permits conflicting claims. Constitutional restraint is a technical resilience control.

A transition can strengthen AFRINIC rather than bypass it

The first phase is evidence readiness. AFRINIC identifies critical services, publishes recovery targets, verifies backups, begins protected escrow, documents key custody and gives every holder a portable account export. No provider choice is required yet. Independent restoration tests establish the baseline.

The second phase is interoperability. A small number of qualified organisations implement the common record and signed event rules in a test environment. They demonstrate import, public-service convergence, dependency selection and authority retirement. AFRINIC participates as both recognised institution and serving provider.

The third phase is a voluntary pilot with low-risk, undisputed holders. Portfolios move registration service while holder identity and public authority remain constant. Metrics, complaints and security findings are published. The pilot pauses if conflicting authority or unbounded key overlap appears.

The fourth phase adds emergency continuity and public-sector standby arrangements. Independent exercises activate limited temporary service and then return it. Only after clean repetition should the model expand.

This sequence preserves accumulated trust and avoids sudden fragmentation. It also gives AFRINIC a concrete recovery achievement: not merely becoming the sole gatekeeper again, but helping establish a regional system that can survive the temporary failure of any one provider, including itself.

The strongest objections can be tested rather than asserted

The fragmentation objection is serious. If portability produces competing holder records, it fails. The answer is one ordered authoritative state, version-bound changes and independent conformance testing. No provider receives power to create a parallel allocation history.

The security objection is also serious. More providers create more attack surfaces. Qualification, bounded roles, multi-party approval, revocable credentials and visible event history address that risk. The relevant comparison is not between a perfect monopoly and risky plurality; it is between concentrated compromise and controlled substitutability.

The legal objection asks whether existing agreements and global recognition permit service separation. Some changes may require contracts, policy and broader coordination. That is a reason for deliberate design, not for assuming permanent exclusivity is technically inevitable. Pilot scopes can begin with support and custody functions that do not alter recognition.

The cost objection asks who funds duplicate capability. Standby systems do cost money. So do years of litigation, emergency reconstruction and delayed service. Shared infrastructure and risk-based service levels can limit expense. Public reporting should compare cost with observed recovery benefit.

The regional-sovereignty objection fears outside control. A bounded model can preserve African policy authority while allowing holders to select qualified service and emergency support. Captivity to one legal entity is not the only way to preserve regional self-government.

The 2025-2027 test is whether reforms change the counterfactual

AFRINIC's board can point to audits, appointments, renewed policy meetings, improved technology and settled procedures. Those achievements matter. The resilience question asks what would happen if a comparable institutional shock occurred after the reforms.

Would operators again wait for courts, a receiver, foreign coordination bodies and exceptional staff effort to preserve service? Or would a preauthorised continuity arrangement activate from current escrow, bounded credentials and qualified providers? Could an individual holder move ordinary service before institutional failure? Would public records converge without uncertainty?

The emerging global discussion of RIR audits, emergency continuity and derecognition shows that the old assumption of permanent institutional health is no longer sufficient. Yet a regional emergency mechanism remains a high-threshold last resort. The NRS direction adds the missing middle: routine exit and provider choice under one authoritative truth.

By 2027, AFRINIC should be judged not only by whether it avoided another crisis but by whether it reduced the harm a crisis could cause. Prevention without substitutability leaves members exposed to rare but severe events. Substitutability without prevention wastes institutional capacity. A mature recovery programme combines both.

Recovery becomes credible when failure is survivable

AFRINIC deserves a fair assessment of its restored board and the staff who maintained service through extraordinary conditions. Institutional criticism should not erase successful continuity or presume that another collapse is inevitable. The purpose of portability is precisely to avoid making resilience depend on a prediction about the next leadership team.

A holder should be able to say: this is the same resource, the same recognised organisation and the same ordered history; only the qualified service provider has changed. In an emergency, a temporary operator should be able to preserve defined functions without taking over policy. When AFRINIC recovers, authority should return through a tested handback. At every stage, relying networks should see one coherent current state.

That is a higher standard than restoring the old normal. It treats the years of receivership, litigation and governance interruption as evidence about institutional concentration rather than a one-time deviation caused only by particular people. It also gives AFRINIC a constructive role in the next settlement.

Without portability, members are asked to trust that governance repair will prevent every future compound failure. With portability, trust remains valuable but is no longer the only continuity control. The first is a bet on durable management. The second is an architecture for surviving disappointment.

Sources