Summary
- Registry identity assurance must distinguish the existence of a legal person, the identity of an individual, the individual's authority to act and the authenticity of the requested transaction.
- Resource fraud is documented: the RIPE NCC reported unauthorized access, fraudulent documents and two transfers later reversed, while ARIN publishes quarterly findings on suspected number-resource fraud.
- Current RIR practices combine corporate-register evidence, identity documents, multifactor authentication, video checks, sanctions screening and third-party data services, creating a growing verification supply chain.
- One proofing level for every action is disproportionate. Account viewing, contact updates, new resource requests, transfer release and disputed recovery present different risks and require different assurance.
- Small and cross-border operators face distinctive barriers from document coverage, transliteration, connectivity, device quality, legal-form differences and supplier assumptions about familiar registries.
- Privacy requires data minimization, short retention, protected transmission, clear purpose, restricted reuse and auditable deletion, especially for passport images, facial video and biometric templates.
- Registries should publish aggregate completion, rejection, manual-review, time and appeal evidence; keep the final decision with accountable staff; and preserve at least one viable route that does not depend on a single private identity provider.
Identity at a registry is a chain of claims
The phrase "know your customer" is too compressed for number-resource administration. A registry needs to answer several separate questions. Does the organization exist? Is the individual a real person? Is that individual authorized to represent the organization? Does the organization hold the registration rights at issue? Is the present request genuinely approved by the holder? Is a legal restriction relevant to the service requested?
One document rarely answers all of them. A passport can support the identity of a person but says nothing about corporate authority. A company-register extract can show that a legal person exists but may not identify the employee handling network operations. An account login can prove possession of credentials while leaving open whether those credentials were stolen. A signed transfer agreement can be authentic yet executed by someone without power to bind the company.
Controls should map to the claim. When an applicant creates a member organization, the registry may need establishment evidence and authority from a director. When an engineer updates a routing contact, strong account authentication and delegated role authority may be enough. When a party releases a valuable IPv4 holding, the registry should confirm the legal holder, the signatory's power and independent approval through an established channel. When an old account is recovered, historical continuity matters alongside current identity.
Conflating the claims produces both weak security and unnecessary burden. Collecting more facial data does not fix a defective corporate-authority check. Requiring a fresh company extract does not prove that a current login is controlled by the right person. A good design asks what failure would cause harm, then chooses evidence that addresses that failure.
This claim-by-claim approach also creates better reasons. A registry can say that personal identity was verified but signing authority remains unresolved. The applicant can correct the relevant problem instead of repeating every step. It makes supplier limits visible: an identity company may validate a document and face match, while the registry must still decide legal authority and resource entitlement.
Fraud is a real registry risk
The case for stronger checks is not hypothetical. The RIPE NCC's Registry Investigation Report describes attempts to gain control of resources through unauthorized account access and fraudulent documents. Two transfers were completed and later reversed. The report states that the RIPE NCC conducted 219 hijack investigations and reviewed 12 disputed transfers in 2022, followed by 201 hijack investigations and eight disputed transfers in 2023.
These counts require care. A hijack investigation is not proof that identity verification failed, and a disputed transfer is not necessarily fraudulent. The value of the report lies in the confirmed mechanism: compromised access and false documents can produce unauthorized registration changes. Correcting such changes consumes staff time and may affect routing, reputation and market transactions.
ARIN defines number-resource fraud broadly enough to include false documents used to obtain resources, secure a transfer, make unauthorized registration changes or hijack resources in its database. Its fraud reporting service investigates reports, and ARIN now publishes quarterly findings without identifying submitters. That publication practice recognizes that aggregate institutional evidence can be shared without exposing a reporter.
Account recovery creates another risk. ARIN locked accounts that had not enabled mandatory multifactor authentication by October 2024. Its account recovery guidance says a person may need a video conference, government-issued photo identification and security questions. At ARIN 55 in 2025, Registry Integrity and Oversight manager Reese Radcliffe said flagged requests to create an organization would require a Zoom call with the ticket submitter and the person signing the Registration Services Agreement, and that people who did not proceed generally did not appear for the call. He also said ARIN did not yet have numbers. That is qualitative operational evidence that attended checking may deter some suspicious applications, not a measured deterrence rate.
No single control is decisive. Fraudsters can use forged documents, synthetic media, compromised company email, corrupt insiders or social engineering. Legitimate users can fail a facial comparison or lose an old authentication device. The goal is not an infallible gate. It is layered evidence that raises the cost of unauthorized change while keeping correction available.
The RIR gate is already becoming a supply chain
The RIPE NCC's due-diligence rules require proof that a contracting natural or legal person exists and is validly represented. The published procedure lists identity documents for natural persons, corporate-register evidence for legal persons and additional proof where authority is uncertain. It also recognizes that legal forms differ and that entities in disputed areas may need alternative establishment evidence.
In 2021, the RIPE NCC announced that it would use third parties for sanctions screening, business information and automated identity-document validation. Its public explanation identified iDenfy for identity-document checks and described deletion of submitted identity information within 14 days. A related RIPE mailing-list response stated that the RIPE NCC remained the data controller under European data-protection law.
By 2025, a RIPE Labs account of membership KYC described automated monitoring supported by commercial business data, sanctions screening, transfer checks and investigation by a dedicated registry monitoring team. It named Altares Dun & Bradstreet as a source for corporate events such as name changes, mergers and acquisitions. This is no longer a single document check at entry. It is continuing reliance on several external data and verification services.
APNIC's public entry guidance also requires documentary support. Its Get IP page lists identity and employment verification material among application requirements. APNIC's privacy statement says applications can include proof-of-identity documents and that third parties may assist with corporate and identity verification.
ARIN's model uses more attended staff interaction in some cases, including video identity verification for organization and point-of-contact vetting. Different RIRs therefore combine people, public records, account controls and suppliers in different proportions. The common trend is stronger assurance and more dependencies.
That trend needs governance. The applicant should know which entity receives which data, what claim it verifies, how long it retains the material, how a result is challenged and what happens when the service is unavailable. Without that information, the registry gate is formally public-interest administration but practically a chain of private decisions.
Small operators do not look like scaled-down incumbents
Large network operators often have mature corporate records, legal staff, several authorized contacts, managed devices and reliable connectivity. A small ISP, community network, exchange entity or technical consultancy may have one director who is also the network engineer. Documentation may be held in a local language or issued by a municipal authority. The operator may connect from a region where mobile bandwidth is expensive or unstable.
Remote proofing can impose hidden equipment requirements. A modern phone, working camera, near-field capability, supported browser and uninterrupted video may be assumed. Identity-document capture can fail because of glare, worn lamination, unsupported scripts or a camera that cannot resolve security features. Facial comparison can fail because of lighting, image age, appearance changes or accessibility needs.
Time is also a cost. A large applicant can distribute repeated verification among staff. A founder handling deployment, customers and finance may lose days to a failed automated check and support correspondence. If the fee has already been paid or a transfer closing date is near, uncertainty becomes commercial leverage over the applicant.
Small operators are not entitled to weaker security over high-value assets. They are entitled to proportionate and usable routes. A registry can require strong proof while offering attended video, verified professional attestation, notarized material, in-person checking at a regional event, or another documented alternative. The evidence must address the same risk without requiring the same technology.
The design should also respect delegated technical roles. The person authorized to update routing records need not be a company director. Requiring directors to complete every operational action creates bottlenecks and encourages shared credentials. The registry should support explicit delegation, scoped privileges, expiry, multiple approvers for high-risk actions and rapid revocation.
Good identity design therefore supports small organizations rather than pretending every member has a compliance department. It creates a clear initial proof, then allows durable and auditable delegation so routine network administration does not repeatedly collect sensitive identity material.
Cross-border verification magnifies classification error
Regional registries serve legally diverse territories. Company numbers differ in length and meaning. Some public bodies are created by law rather than corporate registration. Sole proprietorships may not be separate legal persons. Names can appear in several scripts or transliterations. Addresses may not follow a familiar postal structure. Directors and beneficial owners may reside in different countries from the network operation.
A commercial data provider tends to be strongest where source registers are digitized, standardized and commercially accessible. A missing match can mean that the entity does not exist. It can also mean that the provider lacks coverage, the register is delayed, the spelling differs or the legal form is outside the supplier's model. Treating no match as fraud transfers the provider's geographic limits into registry policy.
The RIPE NCC procedure offers a more defensible principle: ordinary corporate-register evidence is preferred, but other proof may be considered where the usual source is unavailable. In areas claimed by more than one recognized state, it allows evidence from the authority chosen by the signing party. In a self-proclaimed territory, it may consider establishment evidence with additional supporting material. These provisions acknowledge jurisdictional complexity without abandoning verification.
Cross-border transfers add another layer. The sending registry may recognize the source holder under one legal record, while the receiving registry verifies the recipient under another. Names, merger history and authority need reconciliation. A shared rejection from one supplier is not enough. Each registry remains responsible for its side of the transaction and should communicate the precise unresolved claim.
Sanctions screening must be separated from identity proofing. A reliable identity can be subject to a legal restriction; an uncertain identity is not evidence of sanctions. Combining the two into one opaque risk result prevents an applicant from knowing whether to correct a document, establish authority or seek legal review.
Language access matters too. Instructions and reasons should be available in the service languages the registry claims to support. Applicants should be able to submit certified translations or original-script evidence without the software silently normalizing a legal name into a mismatch.
Risk tiering is stronger than universal maximal proof
The 2020 FATF guidance on digital identity, written for financial customer due diligence, recommends a risk-based and technology-neutral approach. An institution should understand the assurance of a digital identity system and decide whether it is appropriate for the relevant risk. Registries are not banks merely because they verify identity, but the proportionality principle transfers well.
NIST's 2025 Digital Identity Guidelines make the structure more explicit. Identity proofing, authentication and federation have separate assurance levels. The risk assessment considers harms from unauthorized access and harms introduced by the identity system itself, including exclusion, privacy loss and service barriers. Tailoring can add compensating controls rather than forcing one method on every user.
A registry should define transaction tiers. Reading public data needs no personal proof. Viewing confidential account material needs authenticated account control. Routine record maintenance needs delegated authority and strong authentication. Creating a contractual relationship needs establishment and representation evidence. Releasing a valuable resource, recovering a contested account or changing the legal holder needs stronger independent confirmation.
Risk can also change within a transaction. A normal contact update may become high risk if it replaces every established contact from a new device and is followed immediately by a transfer request. A new member application may be ordinary until corporate records conflict. Step-up verification is more proportionate than collecting maximum evidence from everyone at entry.
Tiering should be public at the level of principle. Members should know which actions require stronger proof and which alternative routes exist. Exact fraud signals can remain protected. The registry should document why each tier addresses a plausible harm and review it against actual outcomes.
The system should avoid permanent risk labels. A past failed camera session is not evidence that an operator is generally untrustworthy. A corrected corporate mismatch should not shadow later requests. Risk indicators need expiry, context and access controls.
A practical assurance matrix
At the lowest tier, a person creates an account, reads public material or subscribes to notices. Email confirmation, bot resistance and ordinary account security may be sufficient. Collecting a passport here would create privacy risk without protecting a resource.
At the routine operational tier, an established user changes technical contacts, route objects or reverse delegation within existing authority. Phishing-resistant multifactor authentication, scoped roles, notifications and audit history are more relevant than repeating identity-document capture. High-risk changes can require a second authorized approver.
At the organizational tier, a new member or resource holder must establish legal existence and representation. The registry can check a public register, founding law or equivalent source, identify the signatory and record how authority was established. A natural person can provide appropriate identity evidence through supported methods.
At the transactional tier, a transfer or merger requires evidence connecting the legal holder, authorized signatory, resource registration and transaction. Independent confirmation through an established contact and a waiting period for unusual changes can reduce takeover risk. The receiving party requires its own verification.
At the recovery and dispute tier, the registry should assume that some existing signals may be compromised. Historical contacts, contracts, corporate succession, payment history, previous attestations and attended checking can be combined. No single commercial score should settle the matter. Temporary controls should preserve the status quo while review occurs.
This matrix makes controls cumulative only where necessary. It also clarifies which evidence can be reused. A current verified corporate record need not be uploaded for every action. A passport image should not be retained indefinitely merely because the fact of successful verification remains relevant. The registry can record the result, method, date and assurance without keeping the most sensitive source material longer than justified.
Privacy is an operational requirement
Identity proofing collects unusually sensitive material: identity numbers, document images, addresses, dates of birth, facial images and video. A breach can expose information that cannot be changed as easily as a password. Privacy is therefore part of registry security, not an opposing interest.
The European Union's General Data Protection Regulation requires purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality. These principles provide a useful baseline beyond the jurisdictions where the regulation directly applies.
NIST SP 800-63A requires a documented privacy risk assessment for identity proofing and enrollment. It calls for protected channels, protection of stored information, notice about mandatory and voluntary attributes, retention assessment and redress. It also recognizes that third-party services create supply-chain risks.
For a registry, minimization begins with claim design. If the question is whether a signatory is over a legal age threshold, an attribute confirmation may be enough; retaining the full birth date may not be. If the corporate register already confirms a director, a second copy of the same record may add little. If the provider can return a signed yes-or-no validation result, the registry may not need the full document.
Retention should be specific. The fact that identity was successfully verified may need to remain while a contract or resource right continues. The document image may need only a short dispute period. Biometric templates may not be necessary at all. Each class should have a published retention rationale, access limit and deletion method.
Applicants should know whether their information crosses borders, which supplier receives it and whether the supplier can reuse it to improve another service. Consent is a weak basis where refusing means losing access to essential registry functions. The registry should rely on a clear lawful and contractual basis, offer proportionate alternatives and remain answerable for the processor.
Biometrics require measured restraint
Facial comparison can connect a live entity to an identity document and make remote impersonation harder. It also introduces false matches, false non-matches, spoofing risk and sensitive biometric processing. Its use should depend on transaction risk and measured performance.
NIST's current identity-proofing requirements set concrete expectations. One-to-one verification should meet stated false-match and false-non-match thresholds. Performance across demographic groups should be assessed, operational test results should be published in summary form, and a one-to-many result should not cause refusal without manual confirmation. NIST also requires testing against presentation attacks and manipulated media.
The NIST Face Recognition Technology Evaluation shows why vendor-wide claims are inadequate. Error rates vary by algorithm, demographic group, image quality and task. Poor lighting can increase false negatives, while false-positive differences can persist even with good images. A registry must assess the actual product in conditions resembling its users, not rely only on a laboratory headline.
Biometrics should not be the universal entry route. A person unable or unwilling to complete automated facial checking should have an attended or documentary alternative at comparable cost and time. Disability, appearance change, religious practice, device limitations and poor connectivity are operational design inputs, not suspicious behavior.
The registry should never use a biometric supplier's confidence score as the public reason for refusing membership or a transaction. A low score means that the method did not establish the claim at the required assurance. It should trigger another method or human review. Failure of one sensor interaction is not proof of false identity.
Biometric collection also needs strict deletion. Retaining raw video or reusable templates expands harm without necessarily improving future decisions. If retention is required for a defined dispute, access should be narrow, encrypted and time-bounded, with deletion evidence available to the registry's independent auditor.
Rejection evidence is missing governance infrastructure
Registries publish policy manuals, membership counts, resource statistics and some fraud findings. They publish much less about identity-proofing outcomes. Without completion and rejection evidence, members cannot tell whether a stronger gate prevents fraud efficiently or excludes legitimate operators.
The RIPE NCC's 2024 Annual Report disclosed nine new membership applications blocked and six official due-diligence warnings. Those figures are valuable but limited. They do not by themselves show why applications were blocked, how many total applications were assessed, whether applicants corrected the issue, which proofing route failed or whether an appeal changed the result.
A responsible evidence set should report applications started and completed; verification attempts by method; automatic pass, retry, manual review and refusal; median and upper-percentile completion time; broad reason categories; alternative-route use; supplier unavailability; abandonment after failure; appeals; reversals; and confirmed fraud detected. Results should be segmented carefully by document type, jurisdiction group, legal form and organization size where privacy permits.
Denominators are essential. Ten refusals among one hundred applications mean something different from ten among ten thousand. Abandonment should not be treated as success or fraud. A person may leave because the process is difficult, because the fee changed, or because the application was malicious.
Reason categories should separate identity-document authenticity, face mismatch, corporate existence, representative authority, sanctions, duplicate application, unpaid fee and resource-policy eligibility. Combining them into "due diligence failed" conceals which control is creating burden.
Publication need not expose individuals or defensive thresholds. Small cells can be combined. Sensitive fraud methods can be summarized. The objective is to let the membership test proportionality and supplier performance, not to teach evasion.
Independent evaluation should compare vendor reports with registry outcomes. A supplier may report that the software produced a result, while the registry records that the applicant needed repeated support or later human correction. Both operational completion and substantive accuracy matter.
Reasons and appeal protect both sides
Identity refusals require careful explanation. Too much detail can help a fraudster refine false documents. Too little leaves a legitimate applicant unable to correct an error. The answer is staged disclosure.
An initial reason can identify the failed claim and next step: document authenticity could not be established; the corporate record did not match; representative authority remains unconfirmed; or the transaction requires enhanced review. It should identify acceptable alternative evidence and a support route without revealing a defensive score.
A legitimate applicant who completes stronger authentication should receive more specific information about the data source and mismatch. The registry should allow correction of inaccurate records. Where a third-party source caused the problem, the applicant should not be sent away indefinitely; the registry should be able to assess primary evidence itself.
Appeal must reach someone with authority to depart from the supplier result and the first reviewer. The record should include evidence submitted, checks performed, reasons, supplier response, communications and timing. A successful appeal should correct the decision and any persistent risk marker.
Urgent cases need an accelerated route. A disputed account recovery or pending transfer can create operational and financial harm while identity is examined. Temporary freezes may preserve resources, but the registry should avoid changing the holder or route-security authority until the dispute is resolved.
The outcome should feed institutional learning. Repeated appeals involving one document class may indicate poor supplier coverage. Repeated reversals of a corporate mismatch may show that the business-data source is stale. A registry that treats every correction as an isolated exception will never improve the gate.
Alternatives must be equivalent, not punitive
An alternative route is not meaningful if it takes months, costs substantially more or is available only after repeated automated failure. Registries should design alternatives at the same time as the preferred digital method.
NIST SP 800-63A recognizes attended remote proofing, on-site methods and trusted referees for people who cannot complete technology-heavy steps because of bandwidth, devices, ability or other barriers. The exact federal model need not be copied, but the principle is sound: stronger human evidence can compensate for a channel limitation.
For registries, alternatives could include a secure video session with trained staff, direct verification with an issuing authority, a qualified legal attestation, in-person review at an office or scheduled regional meeting, or a sponsoring member with defined liability. Each route should produce a comparable assurance record.
Alternative evidence should be listed by claim. A statute can establish a public body where a company extract does not exist. A power of attorney can establish representation. Historical contracts and established contacts can support recovery. Cryptographically verifiable government credentials may reduce document copying where available, but they should add a route rather than eliminate others.
Costs should be transparent. If enhanced manual review is needed because the registry's chosen supplier lacks coverage, charging the applicant a penalty would be difficult to justify. If an applicant creates unusual complexity or repeated unsupported claims, a published fee may be reasonable. The distinction should be visible.
Service levels should also be comparable. A human route cannot always match an instant automated check, but the registry should publish expected times and monitor whether certain groups wait systematically longer. Accessibility and language support belong in the service design.
A private supplier must never hold the final veto
Identity companies offer document libraries, facial comparison, liveness checks, sanctions data, device intelligence and corporate information. Their scale can improve fraud detection. It can also concentrate power.
A provider may lack coverage for a jurisdiction, change an acceptance rule, suffer an outage, discontinue a product or be acquired. Contractual restrictions may prevent the registry from explaining a result or exporting evidence. Several nominal suppliers may rely on the same data source or cloud service.
The registry should retain final authority. A supplier result is evidence, not judgment. Staff must be able to review source material, accept an alternative and record an independent decision. The contract should permit outcome auditing, demographic and geographic performance assessment, security testing and regulator access where required.
Portability is essential. Data formats, assurance records, configuration, reason codes and deletion evidence should be exportable. The registry should know how it will move to another service without forcing every member to repeat identity proofing. A reduced in-house route should remain available during transition or outage.
Concentration testing should trace dependencies below the brand. If document validation, sanctions screening and corporate data all depend on one external identifier or infrastructure provider, separate contracts do not create resilience. Critical dependencies should have continuity plans and defined recovery objectives.
The registry should publish the role of each supplier, processing location, retention and material changes. It need not reveal defensive configuration. Members need enough information to understand who participates in a consequential decision and where their sensitive data travels.
Procurement should be tested as a continuity control
Identity procurement is often assessed through accuracy claims, security certificates and price. A registry needs a wider test because the service sits in front of membership, transfers and account recovery. The contract should be treated as part of institutional continuity.
The first requirement is defined purpose. Each supplier function should correspond to a particular claim, such as document authenticity, live presence, corporate existence or sanctions status. Broad fraud products that combine unrelated signals into one score are harder to govern. The registry should know which input caused escalation and should prohibit use of its applicant data for unrelated commercial enrichment.
The second requirement is evidence access. The registry needs enough underlying information to review a result without becoming dependent on the supplier's conclusion. This does not mean retaining every biometric image. It means receiving documented reason categories, validation sources, confidence limits, timestamps and a secure route for case review. If a supplier cannot explain a material failure to the accountable institution, its result should not support final refusal.
The third requirement is measured service. Availability targets should cover the whole applicant journey, not only an interface response. Reports should include successful completion, retries, unsupported documents, false failure found on review, processing time and support escalation. Performance should be examined by the populations and devices actually served.
The fourth requirement is controlled change. A supplier should give advance notice of new document rules, facial-comparison components, retention practices, subprocessors and hosting regions. Emergency security updates may move faster, but the registry must be able to identify which version affected a decision. A commercial release must not silently change membership access.
The fifth requirement is exit. Before signing, the registry should demonstrate that it can export assurance records, preserve decision evidence, direct new applicants to another route and continue urgent recovery. A migration test should include revoked credentials, open appeals and deletion obligations. Exit clauses that have never been exercised offer weak reassurance.
The sixth requirement is failure containment. If the provider is unavailable, already verified holders should retain safe access to unrelated services. High-risk new transactions can pause, but routine record visibility, support and time-sensitive security functions should not disappear merely because one proofing component is down.
The seventh requirement is independent assurance. Security testing should address document transmission, account access, administrative privilege, subcontractors and deletion. Performance assessment should address both fraud detection and legitimate-user failure. The registry's auditor should be able to inspect relevant evidence rather than accept a marketing summary.
Procurement cannot solve every governance problem. It can, however, prevent a commercial service from acquiring authority by default. The decisive test is whether the registry remains capable of understanding, reviewing and continuing the function when the supplier is wrong or absent.
Identity assurance needs a member-visible service record
Each completed proofing event should produce a concise record for the member. It should state which claims were established, the assurance method, date, expiry or review trigger, data retained by the registry, supplier involvement, and the route to correct an error. It should not expose defensive details or reusable document numbers.
This record reduces repeated collection. A member can see that organizational existence and representative authority remain current while a new high-risk transaction requires only additional approval. Staff can distinguish an expired role from an unverified identity. Auditors can assess whether the applied tier matched the action.
The member should also see delegations: who can administer contacts, who can authorize transfers, whether two approvals are required and when a role expires. Clear delegation is a fraud control because unusual privilege changes become visible. It also helps small operators avoid shared accounts.
Corrections should preserve history without perpetuating harm. If a legal name is updated or a false mismatch is reversed, the active record should be accurate and old sensitive evidence should follow its retention limit. A corrected risk marker should not continue to influence later decisions invisibly.
The service record is not a public identity profile. Access belongs to the holder, authorized staff and reviewers with a defined need. Public registration data should remain governed by separate disclosure rules. The purpose is to make assurance understandable to the party subject to it.
Identity proofing must remain separate from policy entitlement
A verified person or company is not automatically entitled to a number resource. A resource request may still fail technical or policy conditions. Conversely, a legitimate entitlement should not be lost merely because one digital proofing method failed.
Separating these decisions improves accountability. The identity record can state that legal existence, personal identity and representative authority reached defined assurance. The resource decision can state whether the requested action meets applicable policy. A sanctions decision can identify the legal basis and service affected. Each has its own evidence and review.
This separation also prevents excessive reuse. Detailed network plans submitted to establish resource need should not be fed into an identity supplier. Passport images should not influence resource-policy evaluation. Fraud indicators should be limited to authorized security and integrity functions.
WHOIS and RDAP publication require another boundary. Identity proofing may collect private material to establish a holder, but the public registration service should disclose only fields justified by its purpose and access rules. Verification does not imply that a passport name, home address or document number belongs in public registration data.
The institution should maintain an auditable link between the verified holder and the public record without exposing the evidence itself. Changes to that link deserve strong authorization and notification. Public data accuracy can improve while private identity exposure decreases.
Continuous assurance should focus on change
Identity is not settled permanently at onboarding. Companies merge, dissolve or change directors. Staff leave. Email domains expire. Credentials are stolen. Resources move. Continuous assurance is reasonable, but repeated maximal proof is not.
The RIPE NCC's 2025 KYC account describes monitoring of legal details and corporate events. Such monitoring can identify changes that need review. The risk is treating every commercial-data alert as conclusive. A provider's merger signal should lead to confirmation, not automatic reassignment or termination.
Registries should define events that trigger re-verification: a legal-name change, transfer, account recovery, complete contact replacement, long dormancy, contradictory public record or credible fraud report. Ordinary logins should rely on authentication rather than repeated identity capture.
Members should receive notice and time to correct stale information. Sudden suspension can harm routing and security services. Where risk is immediate, the registry can restrict high-impact changes while preserving access to essential records and support.
Delegated authority should have a lifecycle. Organizations should review roles periodically, remove departed staff and maintain more than one trusted contact. The registry can provide alerts and reports without demanding a director's document every time.
Continuous monitoring also needs limits. Open-ended commercial surveillance can collect more information than registry purposes justify. Sources, trigger categories, retention and human review should be documented. A person should be able to correct a false corporate event or mistaken identity link.
What NRS can advocate without becoming the identity gate
Number Resource Society has a legitimate advocacy interest in how identity gates affect its members and other operators. It can research failure patterns, document exclusion, convene affected businesses, campaign for proportionate safeguards and represent a member that has authorized it in RIR governance. It does not establish holder identity, approve a transfer, maintain identity evidence, operate a registry account, issue a routing attestation or decide a dispute.
Accurate identity supports those functions, but the evidence and decision remain with the competent RIR or other lawfully authorized operator, subject to courts and independent review where applicable.
Each RIR or other authorized registry-service operator should maintain a public assurance policy that separates legal existence, personal identity, representative authority, transaction approval and legal restriction. Each registry action should have a proportionate tier, accepted evidence classes, alternatives, retention and review. NRS can compare those published policies and submit evidence-led recommendations; it cannot turn a member's power of attorney into authority over the registry or over another holder.
Each executing registry should prefer authoritative attributes over document accumulation. A verified claim from a public source can be recorded without retaining unnecessary images. Reusable credentials can reduce repeated disclosure where they are independently assured and not tied to one supplier. Members should be able to choose among methods approved by that registry that reach equivalent assurance.
The executing registries should publish aggregate outcome evidence and commission independent testing. Their accountable boards, memberships and independent reviewers should examine supplier concentration, privacy incidents, rejection disparities, appeal reversals and service continuity. High refusal or abandonment in one jurisdiction should trigger operator investigation. NRS may analyse the resulting evidence, survey members and advocate correction, but it neither audits the provider on the registry's behalf nor certifies the result.
Each executing registry should retain a staffed route for hard cases. Skilled human judgment is not a failure of digital service where law, language or evidence is genuinely complex. The failure would be making that route inaccessible or unaccountable.
Finally, an RIR or authorized operator should be able to change identity suppliers without changing who can be a member. A vendor's coverage model must never become the unstated geography of Internet number governance. NRS can press for that portability; it is not itself the supplier, procurement authority or fallback verification service.
What the 2020-2027 period shows
The period began with growing confidence that digital identity could support remote due diligence. FATF's 2020 guidance emphasized risk-based use rather than one mandatory technology. In 2021, the RIPE NCC publicly added commercial sanctions, business-data and identity-document services. By 2024 and 2025, mandatory multifactor authentication, video recovery checks and dedicated registry-integrity functions had become more visible.
The same period exposed the limits. Confirmed fraudulent documents reached transfer processes. Remote media became easier to manipulate. Supplier chains expanded. Privacy and biometric performance received more detailed technical treatment. NIST's 2025 revision responded with stronger fraud, redress, customer-experience, third-party and demographic-performance requirements.
By 2027, a credible registry should be able to answer basic questions with evidence. Which actions require which assurance? How many applicants complete each method? Who is sent to manual review? Why are applications refused? How often are refusals reversed? How long is sensitive material retained? Which supplier dependencies can halt service? What alternative remains during an outage?
If those answers are unavailable, stronger identity checking may still stop some fraud, but its legitimacy and net effectiveness cannot be assessed. Security that measures only detected abuse and ignores legitimate exclusion is incomplete.
The warning signs
The first warning is a single proofing route for every applicant and transaction. It suggests that procurement convenience, not risk, defines the control.
The second is unexplained abandonment. If many applicants begin but do not finish, the registry should not assume they were malicious. It should investigate channel, language, device, fee and document barriers.
The third is a generic refusal that staff cannot override. That means the supplier has the practical veto.
The fourth is indefinite retention of identity images or biometric data. The burden of justification should rise with sensitivity and time.
The fifth is repeated disparity by jurisdiction, document type, age, skin tone, disability or organization size without operational testing and correction. Difference does not prove discrimination, but ignoring measured difference is indefensible.
The sixth is service coupling. If failure of an identity vendor disables routine routing-data maintenance or route-security actions for already verified holders, the gate is too broad.
The seventh is category confusion. Identity uncertainty, sanctions, payment, policy ineligibility and suspected fraud should not collapse into one adverse label.
Strong identity should preserve entry, not privatize it
Internet number resources carry operational and economic value. Registries should not release or alter them on the strength of a password and an uploaded file alone. Corporate existence, individual identity, representative authority and transaction approval deserve serious verification.
The method determines whether that protection remains legitimate. A universal biometric check can impose unequal barriers. A commercial corporate-data match can mistake weak coverage for non-existence. A vendor outage can stop service. An opaque score can become a refusal that no one at the registry can explain.
Risk-tiered assurance is the better design. It applies strong evidence where unauthorized action would cause serious harm, uses authentication and delegation for routine operations, and offers attended or documentary alternatives where automated proof fails. It minimizes and deletes sensitive data, measures rejection and appeal, and keeps the final judgment with the registry.
The positive case for NRS in this debate is that an independent membership and advocacy organization can expose where identity controls exclude legitimate operators and can press competent institutions for evidence, reasons and remedy. That case does not depend on NRS becoming a thinner registry, an identity provider or a future fallback service. Accurate holder identity makes accountable registry administration credible, but the executing RIR or other authorized operator must control its evidence standards, reasons and continuity, while an institutionally independent reviewer or court provides the relevant remedy.
The registry gate should be difficult for an impostor and navigable for a legitimate small operator. It should recognize cross-border legal diversity without accepting unverifiable claims. It should benefit from private technical expertise without granting a private company final authority. Strong identity is not the maximum amount of data a registry can collect. It is the minimum reliable evidence, applied in proportion to risk, with a clear route to correction when the gate is wrong.

