Summary

  • ARIN’s current Election Processes, effective 19 May 2026, place the Board Election Officer at four different points: explaining qualification criteria, consulting on material nominee issues, confirming the President’s review of the eligible-voter list and joining the President and General Counsel in certification of the tally and process.
  • The officer is not an external auditor. The Board appoints a sitting Trustee who is not a candidate. For 2026 it appointed Ron da Silva, who also sits on the Governance Committee and chairs the Risk and Cybersecurity Committee. Those roles do not prove a conflict or improper act; they locate election assurance inside the institution whose authority the election renews.
  • ARIN has meaningful safeguards: an outside Assessment Firm evaluates nominees, a Nomination Committee includes General Member representatives, excluded nominees may petition, the final voter list is reviewed by several officers, electronic ballots must come from eligible parties and published results include participation and candidate totals.
  • The public rulebook nevertheless names no independent election auditor, public cryptographic audit bundle or ordinary external merits review of certification. The same corporate chain designs and oversees the rules, participates in exception handling, certifies the electorate and tally, and finally confirms the result through the Board.
  • This article does not allege that ARIN’s 2026 election is fraudulent, invalid or badly counted. As of 17 August the vote had not happened. It asks a narrower institutional question: what evidence would let members distinguish valid internal certification from independent attestation without exposing secret ballots?

One office, four checkpoints

Election rules usually distribute their authority across pages. Candidate qualification appears in one section, voter eligibility in another and tally confirmation near the end. Read separately, each checkpoint looks like ordinary administration. Read as a control chain, the same office appears repeatedly.

ARIN’s Board Election Officer first explains the assessment criteria and guidance to the membership. The officer is then consulted on material issues found during nominee assessment. Before voting, the officer confirms that the President reviewed the final list of eligible voters. After voting, the officer joins the President and General Counsel in confirming the tally and certifying that the election followed the approved process. The full Board then confirms the results, and the President announces them.

The sequence matters more than the title. “Election Officer” can suggest an official standing outside the contestants, management and governing body. ARIN’s rules define something else. The Board appoints one of its own Trustees, provided that Trustee is not a nominee or candidate in the coming election. The office is therefore an internal oversight role with a candidate-specific independence condition. The officer must not seek office in that cycle, but remains a director of the corporation.

That arrangement can be sensible. A Trustee understands ARIN’s bylaws, fiduciary duties and governance machinery. Excluding candidates prevents the most obvious personal interest. Giving one person a continuous view across the process can stop responsibility from dissolving among staff, counsel, vendors and committees. Internal assurance is not worthless because it is internal.

But it should be named accurately. A non-candidate director can be independent of the candidate field while remaining institutionally dependent on the Board. The officer helps certify an election that renews colleagues, affects the Board’s composition and returns to the Board for final confirmation. That is a governance control. It is not an external audit opinion.

The 2026 appointment

The Board’s minutes for 13 January 2026 identify Ron da Silva as the Board Election Officer. The appointment appeared in a larger slate of committee and other-role assignments discussed in executive session and approved by acclamation. The same resolution placed da Silva on the Governance Committee and made him chair of the Risk and Cybersecurity Committee.

Those overlapping roles are not evidence of wrongdoing. Governance and risk experience may be exactly why the Board selected him. An election system is a risk system: it involves identity, credentials, confidential candidate material, system availability, incident response and institutional continuity. A Trustee familiar with those subjects may improve oversight.

The overlap also makes the control boundary visible. The Governance Committee’s charter gives it a role in reviewing election processes and Board-development criteria. The Board approves the process. A Trustee appointed by that Board becomes Election Officer. The officer participates in defined checks. The Board later confirms the result. The same institution is not doing only one task; it is present at design, operation, assurance and acceptance.

An internal loop can be rigorous. It can preserve records, resist pressure and correct errors. What it cannot do merely by adding checkpoints is become external. Independence is not a compliment awarded to careful people. It is a relationship between the reviewer and the power being reviewed.

Candidate assessment: external expertise inside an internal frame

ARIN’s strongest answer begins before the ballot. Its 2026 process assigns an Assessment Firm sole responsibility to qualify and assess nominees. For Board candidates, the firm conducts background checks and interviews. It applies the Bylaws, position requirements, skills material and Board guidance. It can rate a nominee Qualified, Qualified and possessing additional recommended skills, or Not Qualified.

That is genuine separation. The Nomination Committee is not simply allowed to remove an opponent because incumbents dislike the person. The outside firm performs the assessment, and the initial slate must carry the firm’s assessments without modification. A candidate assessed Not Qualified has opportunities to provide additional material, make a statement and use the petition route described in the process.

Yet “outside assessor” and “independent election auditor” are different functions. ARIN’s General Counsel and Chief Human Resources Officer arrange the review. When a material background issue may produce a Not Qualified assessment, those two officers and the Board Election Officer review the issue with the firm. The firm retains the assessment decision, but the institutional officers see and discuss the decisive material. The firm then delivers assessments to the CHRO. Staff transmits the initial slate to the Nomination Committee and Election Officer for process confirmation.

If those bodies fail to confirm by the deadline, the General Counsel may review the situation and take steps necessary for confirmation.

The safeguards should be credited: an outside professional judgment, candidate response, petition rights and multiple participants. The limitation should also be stated: this machinery evaluates people for the ballot. It does not independently attest that the voter roll, production voting configuration, ballot custody, tally or certification report was correct.

That distinction keeps this inquiry separate from the existing debate over confidential candidate files. Candidate privacy is legitimate. A background report may contain identity data, employment history, litigation, allegations and information about other people. Publishing the file would create harm and could discourage capable nominees. The election-audit question does not require publication of any such file. It asks whether controls at every stage are tested by an actor who does not report through the institution being renewed.

The electorate is also certified inside the chain

ARIN’s bylaws create three membership classes. General Members in good standing vote. Service Members do not. A General Member must designate a Voting Contact, and voter eligibility is fixed forty-five days before a ballot or election, subject to the published process for later contact-designation changes.

The 2026 process requires the Chief Experience Officer or a designee to create an initial eligible-voter list after the cutoff. By the end of the next business day, that official creates the final list in the presence of the General Counsel and Board Election Officer. The list goes to the President for review. General Counsel confirms with the President and Election Officer that the list was created consistently with the process and certifies that there are no known discrepancies or inaccuracies. The Election Officer then confirms the President’s review.

After those steps, the President directs publication of the eligible organizations’ names and addresses while personal contact data remain redacted.

This is more than one staff member exporting a spreadsheet. It gives named offices distinct acknowledgements and produces a public organizational list. Members can see whether they appear. Candidates can know which organizations form the electorate. Privacy is protected at the Voting Contact level.

But the language of the checks deserves care. The Election Officer confirms the President’s review; the rule does not say that the officer reconstructs eligibility independently from source records. General Counsel certifies that there are no known discrepancies; that formulation is not the same as a positive external assurance opinion based on a disclosed sample, controls and exception reconciliation. Presence when the final list is created strengthens custody. It does not by itself prove that every inclusion, exclusion, affiliation and contact authority was independently retested.

The distinction is practical, not semantic. A voter register can be wrong even when every official acts honestly: an organization may change status near the cutoff, a Voting Contact may represent several legal entities, two records may reflect one corporate group, a credential may be stale or a correction may arrive late. An auditable system needs a transition ledger showing the starting population, eligibility decisions, exceptions, corrections and final count. The public list is useful, but it is not a reconciliation.

A five-percent quorum proves less than its rhetoric

ARIN’s bylaws set quorum at ballots from at least five percent of eligible voters. The threshold answers an internal legal question: has enough of the defined electorate participated for the election to proceed under the corporation’s rule? If the rule is valid and the count is correct, reaching quorum matters.

It answers no larger question. Service Members have no election vote. Network customers and end users are not voters by virtue of dependence on an ARIN registration. A General Member ballot is cast by the organization through its designated contact. A contact may represent multiple organizations and, under the published process, may cast one ballot carrying the votes of each organization represented unless separate accounts are used.

The correct conclusion is not that the election lacks value. General Members choose corporate directors and Advisory Council members under the bylaws. Their votes authorize those offices within the corporation. The error begins when a valid corporate act is presented as a mandate from all networks, users, governments or people in ARIN’s service region. A stakeholder is affected; a principal authorizes. Those categories may overlap, but they are not interchangeable.

This is the central Heng Lu doctrine applied to ARIN. Participation is evidence, not sovereignty. Voting can authorize what the voting body is legally entitled to decide. It cannot turn a Virginia nonstock corporation into a public legislature over scarce assets merely because its technical service is regionally important.

From electronic ballot to Board confirmation

ARIN requires electronic voting through a system that confirms each vote is cast by an eligible party on the final voter list. The public process also states that quorum is determined by ballots cast, including blank or partial ballots. When voting closes, the CXO or designee prepares an election report and sends it to the President, Board Election Officer and General Counsel. The President and Election Officer, in cooperation with General Counsel, confirm the tally and certify process compliance. The Board then confirms the election-process results.

The most recent completed cycle shows how this becomes public language. ARIN’s 2025 results page says 772 General Members participated out of 1,637 eligible organizations, through 607 Voting Contacts. It publishes each candidate’s total and percentage. It also says President and CEO John Curran, Elections Officer Bill Sandiford and General Counsel Michael Abejuela confirmed adherence to approved procedures and the tally.

Those disclosures are valuable. They permit arithmetic checks on candidate totals and participation. Naming the certifiers creates accountability. Publishing the difference between voting organizations and Voting Contacts exposes an important feature of representation rather than hiding it.

Still missing from the current public process is the scope of assurance. Did the certifiers inspect raw system logs or receive a vendor report? Was production configuration compared with approved configuration? Was the eligible-voter file hashed before voting? Were attempted, rejected, blank and partial ballots reconciled? Were administrative actions logged? Did anyone outside ARIN reproduce the tally? Were incidents found, and what materiality threshold applied? The rulebook does not answer those questions.

This bounded absence must not be overstated. ARIN may use competent vendors, internal security controls, legal review or non-public reports. A public page’s silence does not prove that no control exists. It does prove that a reader cannot rely on that page to know the control’s identity, scope, result or limitation.

The independent system ARIN discussed in 2017

ARIN’s own historical record makes the question harder to dismiss. Minutes from January 2017 describe concern about the external election vendor and voting software. Trustee Bill Woodcock proposed that election results be preserved in a tamper-proof audit bundle that could be referenced later. He recommended a solution that was verifiable, digitally signed and independent. The President noted the complication created when one Voting Contact casts for multiple organizations and said staff would return with a concrete proposal.

The minutes do not establish what happened next. This fact package does not prove that ARIN rejected the idea, failed to implement it or operates without equivalent controls today. The proposal may have been implemented in another form, superseded by later technology or handled in contracts and records not included here.

Its existence nevertheless supplies a useful benchmark from inside ARIN’s own governance history. The desired properties were not vague appeals to trust. They were technical and testable: tamper resistance, future reference, verification, digital signature and independence. A 2026 assurance statement should make it possible to tell which of those properties exists now.

Internal control is not a euphemism for failure

It would be easy to flatten the architecture into an accusation: the Board certifies itself. That slogan loses more than it reveals. The Board does not personally administer every credential or calculate every result. Staff, counsel, an Assessment Firm, a Nomination Committee, an electronic system, candidates, Voting Contacts and the Election Officer perform different work. Petition rights and public records impose constraints. A non-candidate rule is meaningful.

The fair institutional defence is that accountability can come from layered internal duties. Trustees owe fiduciary obligations. General Counsel is professionally bound. Executives sign their names to certification. An external assessor controls nominee ratings. Member representatives sit on the Nomination Committee. Results are public. Members can recall a Trustee through the bylaws. The Board must keep the institution functioning and cannot outsource its ultimate legal responsibility to an auditor.

That defence has force. An external auditor should not decide who governs ARIN. Nor should a vendor acquire power to overturn member votes without a defined legal route. Independence can itself become unaccountable if the reviewer’s mandate, evidence and remedy are vague.

The answer is separation between decision and attestation. Members decide through valid ballots. Corporate officers administer and certify under the bylaws. The Board accepts the legal result. A qualified independent reviewer tests whether specified controls operated and publishes a signed opinion, exceptions and scope limits. The reviewer does not choose winners. It makes the evidence behind certification reproducible.

What an independent attestation could disclose

Ballot secrecy places a hard boundary around publication. No voter’s candidate choices should be exposed. A useful audit record does not need them. It can publish commitments and reconciliations rather than ballots.

Before voting, ARIN could publish a cryptographic commitment to the frozen eligible-organization file, together with the count and reason-coded reconciliation from the starting General Member population. The private list would remain protected while later review could prove that the same file drove the election.

The system record could identify the vendor, software and production version; the approved configuration; administrative roles; authentication method; opening and closing timestamps; change controls; backup and recovery state; and the digest of the ballot definition. Security-sensitive details can be withheld with a reason without reducing the entire system to “electronic voting”.

After voting, a signed control report could reconcile credentials issued, authenticated sessions, ballots started, ballots cast, blank and partial ballots, rejected attempts, late submissions and administrative interventions. Candidate totals should reconcile to the ballot rules. An incident register should say whether any availability, identity, configuration, custody or count event occurred and how it was resolved.

An independent reviewer could then state exactly what it tested, which records it received, whether it reproduced the aggregate tally, what it could not inspect and whether any exception could have affected the result. A challenge process should define who may question certification, what evidence is available, who decides and how quickly a remedy must occur before office passes irreversibly.

None of this makes the election a public referendum. It does something more modest: it allows the corporation’s own members to know what its certification means.

A prospective inquiry, not a verdict

As of 17 August 2026, ARIN’s calendar placed the election in the future. Voting was scheduled for 22–30 October, Board confirmation for 5 November and announcement for 6 November. Nominee assessments, the initial slate, petitions, final electorate, incidents, tally and winners had not completed the published sequence.

No conclusion about the integrity of that future vote is justified. This article identifies controls that should be visible before the event and evidence that should exist afterwards. If ARIN publishes a strong independent attestation, the structural assessment should improve. If the election proceeds cleanly but only the internal certification statement appears, the result may still be valid while the independence claim remains unproved.

That distinction protects both criticism and the institution. It prevents a structural concern from becoming an allegation against named people. It also prevents a successful election from being used to erase the concern without producing the evidence that answers it.