Summary
- Proportionality is a method to test means against ends. A registry does not have to be a government for its board, members, contracting parties, or external auditors to require a legitimate purpose, evidentiary suitability, necessity, and a fair balance.
- The four steps are cumulative: establish a legitimate, authorised purpose; demonstrate a rational connection with reliable evidence; compare less harmful measures that could achieve the purpose; weigh the expected benefit of the measure against the direct and indirect harms.
- The difficulty of exit counts. A holder cannot obtain the same unique number range from a competing registry, so ordinary market choice cannot discipline excessive restrictions at the level of the common recognition layer.
- Registry remedies must be disaggregated. A warning, a request for correction, a freeze on changes, a restriction on new applications, a temporary service limitation, a transfer lock, a contract termination, and a revocation have different effects and should not be treated as a single blanket sanction.
- Network evidence must be used for the proposition it can support. Registration records, observed BGP announcements, RPKI objects, contracts, and court orders answer different questions; one should not stretch one as proof for another.
- An urgent provisional measure can be proportionate if delay threatens uniqueness, security, or third parties, provided the scope is narrow, unaffected functions continue, evidence is preserved, and prompt independent review follows.
Proportionality is a discipline of means, not a label for moderation
The word "proportional" is often used to mean reasonable, appropriate, or not too strict. These descriptions express a preference but do not reveal how a decision was made. A structured test is more demanding. It requires the institution to identify the purpose, link the measure to evidence, compare alternatives, and consider the impacts.
This discipline is important because infrastructure institutions can confuse the importance of their mission with the necessity of a particular sanction. Protecting the exact registry record is important. It does not follow that every inaccuracy justifies immediate revocation. Fraud prevention is important. It does not follow that suspicion concerning a requested change justifies discontinuing unrelated services. Purpose and remedy are separate statements.
Proportionality also requires specificity as to the interest affected. The holder may suffer a loss of registration services, customers may suffer disruption, and the registry may face risks to accuracy or uniqueness. A general statement that the public interest favours administration cannot balance these different impacts.
The test must be recorded at the time of decision, not constructed only after a challenge. A contemporary analysis shows what evidence was available, which options were feasible, and why the chosen scope was deemed necessary. Later information may justify a new decision, but it should not be used to cover the weakness of the original decision.
The public law test can be adopted without assuming statehood
The four-step formulation is familiar in judicial review. In theBank Mellatcase, the UK Supreme Court examined whether the purpose was sufficiently important, whether the measure was rationally connected to it, whether a less intrusive measure could have been used without unacceptable impairment, and whether the severity of the effects outweighed the contribution of the measure to the purpose.
This judgment concerned a government measure and statutory rights. It does not automatically apply to a membership organisation or a private registry. Jurisdiction, applicable law, and the source of the review remain determinative. A court may apply contract law, association law, competition law, or another area of law, rather than public law proportionality.
Adopting the structure remains valuable nonetheless. Private institutions often adopt stricter controls than the minimum a court would impose. Contracts may require proportionate enforcement. A board may instruct staff to compare alternatives. Members may approve a sanctions policy. An arbitrator may interpret an express requirement. A regulator may examine exclusionary conduct where competition law applies.
The distinction must be stated openly. Proportionality here is a governance standard supported by the characteristics of the relationship, not a claim that every decision of the registry is an administrative act. This restraint makes the proposal more transferable from one jurisdiction to another, because it does not depend on winning a submission on public status.
Difficult exit creates a problem of private power
Ordinary market discipline assumes a dissatisfied customer can leave. Number registration complicates this assumption. A globally unique IP prefix or autonomous system number cannot simply be recreated at another provider while the original registration remains authoritative. Dual recognition would undermine the coordination function.
RFC 7020describes the system of Internet number registries and the hierarchical distribution of unique number resources. It also distinguishes registration from routing operations. A registry does not control whether networks accept a route, but its recognised registration can matter for transfers, contact publication, reverse DNS, and routing security services.
This creates a dependency on a narrow layer. The holder can change upstream provider, equipment, or consultant. It may not be able to replace the institution responsible for the relevant registration relationship without a coordinated transfer or a future portability arrangement. The exit threat therefore provides less restraint than in a competitive sales service.
Difficult exit does not make the registry the owner of the network. It creates the reverse obligation: to maintain the function that cannot be replaced. If an institution uses control over registration to enforce behaviour unrelated to uniqueness, accuracy, or authorised service duties, the absence of alternatives worsens the concern.
Step one: define a purpose sufficiently important for the consequence
The first step asks what the measure serves and whether that purpose falls within the institution's competence. Valid purposes can include preserving unique registration, verifying eligibility for changes, protecting registration accuracy, preventing documented fraud, enforcing payment obligations, complying with a binding court order, and containing a credible security compromise.
The purpose must be expressed at the level the evidence supports. "Verify that this representative can transfer this range" is more useful than "protect the Internet". "Collect outstanding contractual fees" is clearer than "enforce community values". Precision enables assessment of suitability and alternatives.
The importance must also match the consequence. A minor formatting error may justify a correction, but not the loss of a long-held resource. Repeatedly forged documents may justify a stronger restriction because they directly undermine verification of eligibility. The same general category, registration accuracy, contains risks of very different severity.
Competence must be traceable to the policy, agreement, corporate authority, or law. A commendable purpose does not allow staff to invent a sanction outside the governing instruments. If the problem reveals a gap, the institution must use the authorised change path rather than stretch a single decision to create new law for the holder.
Mission statements are too broad to do the work
Administration, security, stability, and public interest are important institutional values. They are not self-executing powers. A mission statement can explain why an organisation exists but leaves open what measure it can impose on which actor.
Overly broad purposes weaken every subsequent step. Almost any restriction can be described as remotely contributing to stability. If that suffices, the rational connection becomes trivial and less harmful alternatives vanish from view. The institution can always say the mission outweighs the loss of a holder.
A clean purpose has an observable failure condition. If the goal is accurate authority data, success means the relevant identity and authorisation are reliably established. If the goal is payment, success means the debt is settled or the service relationship ends according to agreed terms. If the goal is preventing an unauthorised transfer, success means the existing state is preserved while authorisation is checked.
The decision should also identify the goals it does not pursue. A registry investigating forged contacts should state whether it alleges fraud, contractual non-cooperation, or merely incomplete information. These statements carry different stigma and justify different consequences. Clear boundaries protect the holder and prevent the institution from shifting its theory when the initial ground proves weak.
Step two: demonstrate a rational connection through evidence
A rational connection requires more than a temporal association. The institution must explain how the facts indicate the identified risk and how the chosen measure reduces that risk. The quality, coverage, and uncertainty of the evidence matter.
Suppose an organisation does not respond to a verification message. That fact can support a concern that the listed contact is outdated. It does not by itself establish that the organisation no longer exists, lacks authority over every resource, or has committed fraud. Targeted contact update and verification through another channel fit the observed problem better than immediate revocation.
Repeated submission of materially inconsistent corporate documents is stronger evidence, but the institution must still determine whether the discrepancy reflects restructuring, translation, judicial naming conventions, or deception. A finding of fraud requires evidence directed at intent or forgery, not merely administrative complexity.
The measure must match the evidence. Freezing a pending transfer can prevent an unauthorised change while verification continues. Suspending the ability to request additional resources can encourage compliance with an audit. Revoking RPKI certificates, disabling reverse DNS, and deleting registration entries together may provide no additional protection if the sole issue is unpaid training fees.
The rational connection is therefore both factual and functional. It tests what the evidence proves and which service surface the remedy actually changes.
Network resource evidence has narrow limits
Internet number disputes attract technical evidence that appears decisive because it is machine-readable. Its significance remains limited. A registration record identifies a recognised status and contacts according to the registry's rules. It does not necessarily determine ownership under any law. A BGP observation shows that a route was visible from selected vantage points at a given time. It proves neither contractual authorisation nor beneficial ownership.
An RPKI Route Origin Authorisation indicates that the resource holder has authorised an autonomous system to originate certain prefixes within defined bounds. It does not guarantee that the route is secure, desired, or accepted by all networks. The absence of a ROA does not prove the underlying registration is abandoned. Reverse DNS delegation answers a different operational question.
Contracts, corporate documents, identity documents, invoices, and court orders also support defined statements. A corporate document may prove legal existence but not the authorisation of the person requesting a transfer. A contract may show an agreement between the parties but not bind a third party or decide a question reserved for a court.
Proportionality fails when one form of evidence is stretched to support a broader conclusion. The decision record must list each proposition, the evidence supporting it, known gaps, and the reason the remedy responds to that proposition. Technical confidence cannot cure a category error.
Step three: compare effective less harmful measures
Necessity does not require the institution to imagine all theoretical alternatives. It requires a serious comparison with credible measures that would achieve the purpose without unacceptable loss of effectiveness. The analysis must occur before the strictest option is selected.
Registry enforcement offers many gradations: requests for information, warning, correction period, enhanced verification, restriction of a pending change, temporary account lock, restriction on new applications, supervised transfer, preservation of evidence, partial service suspension, contract termination, and revocation. Different combinations can isolate risks.
The least harmful measure is not always the weakest. If credentials are compromised, an immediate temporary freeze may be less harmful than allowing an unauthorised transfer and later trying to reverse it. If a holder systematically ignores payment requests, another identical reminder may be ineffective. Necessity demands the least harmful option that still works, not endless ineffective patience.
Alternatives must be tested for time, enforceability, and circumvention. A correction period may be appropriate if the defect is curable. Independent verification can clarify contested authorisation. Security-sensitive evidence can be examined under confidentiality. A bond or phased transfer can protect competing claims. The institution must explain why the rejected alternatives fail and what information could change that conclusion.
A sanctions ladder should preserve distinctions
Institutions often publish a sequence from warning to termination. A ladder is only useful if it preserves the nature of each step. Suspension of new applications is not the same as suspension of maintenance of existing registrations. A transfer lock is not the same as a finding that the holder lacks rights. Contract termination is not identical to immediate technical deletion.
The currentRIPE NCC Termination and Revocation Procedureseparately describes grounds, termination, service consequences, and revocation. Its details operate within the RIPE NCC's own agreements and documents, but the structural separation is valuable across institutions. It forces the decision-maker to ask which consequence follows from which ground.
ICANN registry documents offer another limited comparison. TheRegistry Suspension Explanationdescribes suspension as a restriction on new sponsorships and inbound transfers while certain existing name functions remain available. TheTermination Guideaddresses transition of sponsored names after accreditation termination. Domain names and number resources are not interchangeable, but the principle of continuity is relevant: discipline the intermediary without unnecessarily blocking users.
A registry sanctions policy must specify the operational effect of each step. Labels like "suspended" or "closed" are limited public evidence when multiple technical and contractual functions can be changed independently.
Step four: weigh total benefit against total harm
The final step asks whether the expected contribution to the purpose justifies the severity of the effects. This is not a repetition of necessity. A measure may be the only effective one and still be too harmful relative to the benefit sought.
The benefit side must include probability and magnitude. Preventing an imminent unauthorised transfer of a large range may have high expected value. Enforcing a minor administrative preference carries less weight. Claims of systemic risk must identify how the individual case contributes to that risk.
The harm side includes more than the contracting holder. Customers, downstream networks, security systems, employees, creditors, and counterparties may be affected. Harm can include service disruption, inability to update contacts, transfer delay, routing validation consequences, loss of reverse DNS, reputational stigma, and legal costs.
Reversibility matters. A short lock with rapid review differs from permanent revocation. Scope matters. One prefix differs from an organisation's entire portfolio. Timing matters. Immediate effect differs from a phased change after customer notification.
The balancing must be transparent about distribution. A registry may gain administrative convenience while thousands of users bear the cost of migration. Convenience can be relevant but rarely alone justifies a serious infrastructure disruption. The written conclusion must identify who bears which costs and why that distribution is fair.
The contract provides a direct path to proportionality
The clearest foundation is an express clause. A service agreement or enforcement policy can require measures that are proportionate to the nature, severity, duration, and repetition of the non-compliance, taking into account third-party continuity. It can specify notice, correction, emergency restriction, and review.
Express wording avoids the debate over whether a court will imply the obligation. It also gives staff an operational standard before litigation. The clause should not simply say the registry will act reasonably. It should require the four questions and a recorded explanation for consequential measures.
Where the contract confers wide discretion, applicable law may impose limits. TheBraganzacase shows a private law path in English law to examine the purpose and rationality of certain contractual decisions affecting both parties. It does not establish a global proportionality rule, and other agreements or jurisdictions may lead to different results.
TheUNIDROIT Principlesprovide a non-binding transnational reference for good faith, fair dealing, and inconsistent behaviour where applicable or adopted. Proportionality can make these broad obligations justiciable by asking whether the power was exercised for the granted purpose and without avoidable excess.
Competition law explains why market power matters
Competition law does not make every monopoly act unlawful. It distinguishes possession of market power from its abuse and requires a jurisdiction-specific analysis of market definition, dominance, conduct, and effect. A registry should not be lightly declared an essential facility in every jurisdiction.
The competition perspective is nonetheless useful. TheEuropean Commission's Article 102 overviewnotes that a dominant undertaking has a special responsibility not to distort competition and identifies conduct such as refusal to supply an indispensable input for competition on a neighbouring market. The Commission'sGuidance on enforcement prioritiesuses an effects-based analysis for exclusionary conduct.
For number governance, the relevant warning is leverage. Control over a single registration point should not be used to force purchase of contestable neighbouring services, punish critics, favour established members, or block a legitimate change of service provider. A restriction related to a specific registration may be legitimate; a restriction related to an unrelated commercial advantage deserves stricter scrutiny.
Competition analysis also values less restrictive access conditions and objective criteria. Proportionality provides an internal equivalent before legal intervention. The registry identifies the narrow coordination purpose, tests whether the restriction is necessary, and records the impact on downstream competition.
### Modern regulation of private platforms confirms the direction
Digital platform regulation shows that legislators can impose proportionality obligations on private service providers without turning them into governments. The European Union'sDigital Services Actrequires providers to apply and enforce restrictions in their terms of service with due regard to relevant rights and describes proportionate risk mitigation obligations for the largest services.
The DSA does not automatically govern RIR enforcement. Content hosting, platform operation, and running Internet number registries are different activities. Its value lies in institutional design: concentrated private intermediaries can be required to justify their decisions, take rights into account, and tailor restrictions to identified risks.
Registry governance can functionally adopt the same discipline. The interests are continuity, accurate recognition, contractual fairness, non-discrimination, and the freedom to operate networks lawfully. The relevant evidence concerns identity, authorisation, resource history, service obligations, and technical risk, not content moderation.
The comparison also warns against using scale as an excuse. Large private institutions can create standard justification forms, decision categories, and remedy pathways. Volume supports structured proportionality because recurring cases reveal which alternatives work. It does not justify replacing judgment with the administratively most convenient penalty.
Scope must be calibrated by resource, account, and function
A proportionate decision identifies the smallest affected unit that contains the risk. The relevant unit may be a contact change, a transfer request, a prefix, an account ID, a service, a legal entity, or an entire portfolio. These levels should not be confused.
If authorisation for a transfer is disputed, freeze the transfer, not every maintenance function. If a credential is compromised, revoke it and issue a secure replacement rather than conclude the organisation has disappeared. If a resource was obtained through forged evidence, investigate the connected holdings based on evidence, not automatic guilt by association.
An account-wide measure may be justified if the risk is account-wide: systemic identity fraud, insolvency affecting the contracting party, pervasive forged records, or loss of all authorised control. The reasons must show the connection. An organisation-wide consequence cannot rest solely on administrative convenience.
Functional scope is equally important. WHOIS or RDAP contact publication, reverse DNS, RPKI, transfer authority, requests for new resources, and billing access serve different purposes. Preserving unaffected functions can reduce harm without weakening enforcement. A decision letter must list each changed function, its start time, duration, and restoration condition.
Time is part of proportionality
The same restriction may be proportionate for forty-eight hours and excessive for six months. Temporary locks are often justified by uncertainty; extended locks require progress, evidence, and review. An institution should never allow temporary to become indefinite until the holder gives up.
Every provisional measure needs a timeline. State the initial duration, the evidence sought, the responsible reviewer, and the next decision date. If more time is needed, justify it and reassess scope. Reciting the original concern is limited public evidence if the institution has not advanced the investigation.
Correction periods should reflect what correction requires. Updating a contact may be quick. Obtaining certified probate documents in multiple jurisdictions may take longer. A deadline should not be designed to make compliance formally available but practically impossible.
Expiry can also protect the institution. A lock that automatically ends unless renewed forces active ownership and prevents forgotten restrictions from distorting records. A serious measure should have a scheduled reassessment to confirm whether the expected benefit has materialised and whether collateral damage requires remediation.
Reversibility reduces risk but does not eliminate it
Provisional restrictions are often defended as reversible. This is relevant, but commercial and technical time cannot always be reclaimed. A delayed transfer can kill a transaction. A public suspension notice can harm reputation. A missed customer migration window can cause permanent cost.
The institution must assess practical reversibility, not just its ability to click an undo control. Can the records be restored exactly? Will RPKI stakeholders receive the corrected status promptly? Can a third party who relied on the provisional status be notified? Will the holder regain access and transaction timeline?
If full restoration is impossible, the safeguards must be stronger. The institution may use a confidential status, preserve outgoing services, avoid public claims before findings, or require expedited review. Security needs may limit disclosure but do not eliminate the need to minimise irreversible effects.
Post-decision correction also matters. If a restriction proves unfounded, the institution must correct the public records, notify known recipients of the adverse status where possible, and examine why the evidence was misread. Reversibility only becomes credible if recovery was designed before the restriction.
Non-payment should not silently become resource adjudication
Payment enforcement is necessary for a membership or service institution. Persistent non-payment may justify suspension or termination under the agreement. The proportionality question is how financial default interacts with unique registration and third-party continuity.
The institution must distinguish between disputed invoice, temporary difficulty, administrative error, and wilful refusal. It must identify the notices sent, amounts due, correction options, and the consequence authorised by the agreement. A billing dispute should not be described as evidence that the holder lacks historical authority over a resource.
Termination may end access to services, but the treatment of registration records must be explicit. If revocation follows under the governing documents, the institution must state the timeline, preserve evidence, and take account of downstream users. A structured transfer or succession arrangement can protect continuity without granting the defaulter unlimited free service.
The strongest measure should not be chosen solely because it is easy to administer. Fees support the institution, while unique registrations support the Internet as a whole. A proportionate design respects both by escalating predictably, separating debt from fraud, and preserving a path to correction before irreversible effects where circumstances permit.
False information requires a fault distinction
False information can result from error, outdated contacts, translation, corporate restructuring, contested succession, or forgery. A policy that treats every inconsistency as fraud will overreach. A policy that ignores intentional deception will fail.
The initial measure should preserve the status quo where the risk of change is imminent and seek clarification through secure channels. The institution may compare authoritative records, request an explanation, and isolate the contested act. It should disclose the material inconsistency unless doing so endangers a legitimate investigation.
Fault influences consequence. A good-faith holder correcting an outdated address presents a different risk from an applicant submitting forged documents after warning. Repetition, concealment, and materiality matter. So does the relationship between the false statement and the decision on the resource.
Even proven fraud should not lead to automatic portfolio-wide revocation without analysis. The institution must identify which decisions were influenced, which records remain reliable, and which third parties are innocent. Severe sanctions may be justified, but their scope must follow the proven contamination, not moral outrage.
Security emergencies justify speed, not unlimited scope
Credential theft, unauthorised access, or imminent double registration may require immediate action. The goal is containment. A temporary change freeze, revocation of a compromised credential, and out-of-band verification can be rationally connected and necessary before ordinary notice.
Emergency authority needs predefined triggers. Staff must identify the observed event, confidence, affected surface, and maximum initial duration. The holder must be notified as soon as disclosure no longer worsens the threat. A second decision-maker must review continuation.
Unaffected operations should continue where safe. A transfer lock need not disable route authority maintenance if the credential paths are separate and secure. If all credentials are compromised, the institution may need broader restriction but must explain the dependency.
The emergency record must outlast the event. After containment, the institution must determine whether the measure was correct, whether the duration was justified, and whether recovery was successful. An emergency that reveals a general weakness may support later reform through the authorised path; it should not silently create a permanent discretionary power.
Court orders must be read for their precise effect
A registry may receive an order from a court or competent authority. Compliance with binding law is a legitimate purpose, but proportionality still requires careful interpretation of scope. The institution must identify the entity, resource, action, effectiveness date, and any authority to request clarification or review.
An order to preserve records is not necessarily an order to transfer. An injunction against one party cannot decide the rights of another. A request for information is not a power to revoke. Cross-border effect may depend on recognition and applicable law. The registry must obtain proper legal analysis rather than expansively interpret the order as a precaution.
If the order leaves discretion, the institution must protect continuity and third parties. It may preserve the existing state, flag a dispute internally, prevent destructive changes, or notify affected parties within legally permissible boundaries. Confidentiality requirements must be recorded and reviewed rather than assumed permanent.
The registry should not represent obedience to an exact command as its own discretionary decision. Conversely, it should not attribute additional voluntary restrictions to the court. Clear attribution allows the holder to challenge the correct actor and prevents institutional power from hiding behind legal language.
Transfer disputes require preservation, not premature victory
Competing transfer claims create pressure to choose a winner quickly. The registry's first responsibility is usually to prevent an unauthorised or duplicate change while evidence is examined. A neutral lock can be proportionate if it is targeted, time-limited, and linked to an effective decision path.
The institution must define the proposition it can decide: whether the application meets registry requirements and shows authenticated authorisation. It may not be competent to finally determine beneficial ownership, breach of contract, insolvency priority, or liability for fraud. These questions may be reserved for arbitration or court.
Necessity favours preservation when reversal is difficult. The balance favours maintaining unaffected registration maintenance and network operation while the disputed transfer remains frozen. The reasons must identify the evidence each applicant must provide and what happens if external litigation continues.
A lock becomes disproportionate if it drifts without milestones, blocks unrelated services, or allows one party to win through delay. The institution must schedule a review, require progress, and allow a competent external order to resolve questions beyond its competence. Neutrality is active design, not indefinite inaction.
RPKI actions require special care
RPKI can influence routing decisions made by trust-anchor networks, so changes to certificates and Route Origin Authorisations have effects beyond the registry account. The exact outcome depends on publication, validation, and network policy, but revocation can cause routes to be seen as invalid or not found from the perspective of trust-anchor systems.
This consequence makes purpose critical. If an RPKI credential is compromised, targeted revocation and reissuance may be necessary. If the dispute concerns an unpaid invoice or a pending corporate document, revoking valid routing security material does not advance the purpose and harms third parties.
Registration status, eligibility for the certification service, and routing authorisation must be analysed separately, even if the governing documents link them. The institution must identify the dependency, expected effect on stakeholders, and recovery plan. It should avoid claiming that a certificate decision directly commands global routing.
If urgent revocation is required, notice and phased publication may be limited for security reasons, but post-assessment remains essential. The measure should cover only the affected resources and credentials. A broad portfolio revocation requires proof that the compromise or authority failure reaches the entire portfolio.
Reasons make proportionality review possible
A statement that a measure is proportionate proves nothing. The decision letter must show the four steps. It must state the purpose and authority, summarise the material facts, explain the evidence connection, list serious alternatives, describe the direct and collateral effects, and state why the balance favours the chosen measure.
Confidential evidence can be handled through a usable summary, a protected annex, or an independent reviewer. The holder needs enough to understand the case and propose a safer alternative. Security does not require blank reasons.
The letter must list every operational effect: resource ranges, services, credentials, transactions, start time, duration, correction conditions, and remedy path. Precision prevents staff and external actors from treating a narrow restriction as full loss of status.
Reasons also improve consistency. Reviewers can compare whether similar defects received similar measures and whether differences follow the evidence. Boards can see when staff repeatedly hit a policy gap. Members can evaluate overall enforcement without learning the protected case details.
Independent review needs power to preserve continuity
A review is meaningful only if the reviewer can examine the proportionality chain and prevent irreversible harm. It must have access to the relevant documents, evidence, alternatives analysis, and effects map. It must be able to request clarifications and, where authorised, suspend or reduce the measure.
Independence is relative to the decision. A separate manager can correct a frequent error. A standing committee can review consequential institutional judgments. Arbitration or court may be required for contractual and statutory rights. Competition authorities can address exclusionary conduct within their competence.
The level of review must be explicit. Technical expertise may justify deference on evidence evaluation but not blind obedience. Policy decisions may allow a range of reasonable balances. Factual error, improper purpose, unexplained inconsistency, and failure to consider an obvious less harmful measure deserve closer correction.
Urgent review must be available before the practical point of no return. A remedy delivered after customers have renumbered or a transaction has collapsed can be formally successful and operationally empty. Timelines, provisional powers, and notification rules must be designed based on actual infrastructure effects.
A decision form can operationalise the four steps
Before imposing a consequential measure, the institution should complete a concise decision dossier:
- Purpose:What specific harm or obligation is addressed, and where does the authority come from?
- Evidence:What facts are established, what uncertainty remains, and what proposition does each source support?
- Connection:How will each proposed restriction reduce the identified risk?
- Alternatives:What narrower measures were considered, and why would they be limited public evidence?
- Scope:Which resources, accounts, persons, services, and technical functions are affected?
- Time:When does the measure start, expire, or be mandatorily reviewed?
- Third parties:Which customers, counterparties, or trust-anchor networks may be harmed, and what continuity protection applies?
- Balance:Why does the expected benefit justify the remaining harm?
- Recovery:What must happen for the restriction to end, and how will records and services be restored?
- Review:Who can inspect the facts, reasons, and proportionality, with what provisional authority?
The form should be scalable. A minor warning may be brief. Revocation or broad certificate revocation requires detail. Standardisation reduces omissions without turning judgment into a tick-box exercise.
A remedy matrix is better than a linear escalation
A single ladder assumes every problem grows along one dimension, from minor to severe. Registry disputes are multidimensional. A security alert with low confidence but high impact may justify an immediate narrow lock. A billing error with high confidence but low impact may justify a correction notice. Repeated misconduct may increase duration without broadening technical scope.
A remedy matrix should classify at least five dimensions: severity of purpose, confidence in facts, breadth of affected resources, urgency, and reversibility. It should then map these dimensions to the available functions. Change authority may be frozen while ordinary maintenance continues. New applications may be suspended while existing entries remain intact. A credential may be replaced without terminating membership. A contested transfer may be blocked without prejudging ownership.
The matrix should include escalation and de-escalation triggers. Additional verified evidence may justify a broader restriction. Successful correction, reduced uncertainty, or independent confirmation should reduce it. A restriction should not remain strict simply because it started strict.
Published categories improve predictability but should not become automatic penalties. The decision-maker must always explain why the selected cell fits the case. Exceptional measures should be identified as exceptional, with a reason they do not create general precedent.
This design also exposes missing tools. If the only available options are warning and full revocation, the institution has created its own proportionality problem. Boards and members should authorise intermediate remedies before a crisis forces improvisation.
Member accountability should examine concentrated harms
Member participation can legitimise general rules, but majority support does not prove every application is proportionate. A widely beneficial reform may impose severe costs on a small class of legacy holders, small networks, or organisations operating in difficult legal environments. These costs must be identified, not averaged.
Impact analysis should show the number and type of affected holders, the services at risk, the expected compliance costs, third-party dependencies, and available alternatives. The institution should seek evidence from actors unlikely to dominate meetings: small operators, downstream customers, public entities, and technical teams responsible for migration.
Members should also receive aggregated enforcement information. The number of warnings, locks, suspensions, terminations, recoveries, and successful challenges can reveal whether sanctions policy behaves as promised. Distribution by ground and duration is more informative than a single total. Protected identities and security details should not be disclosed.
Accountability works both ways. Members should not pressure staff to spare influential organisations from ordinary scrutiny. Nor should they use a general vote to target an unpopular holder through a measure unrelated to the stated purpose. Conflict rules, recorded reasons, and independent review protect the institution from both forms of capture.
The governing body should revise the remedy matrix if challenges repeatedly identify excess or if staff repeatedly need emergency exceptions. A persistent discrepancy suggests the authorised tools no longer fit the risks.
Metrics should measure averted harm and inflicted harm
Institutions often measure enforcement by cases closed, debt collected, or records corrected. These numbers show activity, not proportionality. A comprehensive assessment measures the benefit achieved and the harm caused.
Benefit-side metrics can include averted unauthorised changes, verified contact corrections, restored compliance, reduced repetition, and time to contain credential compromises. Harm-side metrics can include duration of locks, number of interrupted unaffected services, customer disruption, reversals on review, failed recovery, and lost transactions because a decision missed its deadline.
Metrics need context. A high reversal rate may indicate poor initial decisions but may also reflect a healthy review panel and new evidence. Long locks may be justified in complex disputes, but the institution must identify who controlled the delay. Quantitative results should be accompanied by brief explanations of outliers and uncertainty.
The institution should retrospectively compare alternatives. Did targeted restrictions work as well as broad suspensions? Did correction periods improve records? Were emergency locks quickly scaled back? Evidence from closed cases improves later necessity analysis and prevents convenience from hardening into tradition.
Public reports can remain aggregated. Independent auditors should have access to case-level material under appropriate confidentiality. The purpose is not to evaluate staff. It is to learn whether the remedy actually advanced the goal at acceptable cost. Proportionality becomes credible when the institution is willing to test its predictions against outcomes.
Proportionality should also govern future portability
If number registration services become more portable, competition at the service level may improve while a single reconciliation state still protects uniqueness. Proportionality will remain necessary because a provider could use credentials, locks, or exit conditions to hinder switching.
A provider should restrict portability only for a defined risk such as contested authorisation, unpaid agreed fees directly related to exit, a binding order, or a credible security event. The restriction should be narrow, time-limited, and reviewable. It should not force purchase of unrelated services or delete acquired rights.
The common coordinator also needs proportionate limits. It can verify that a change does not duplicate a resource and that both parties authenticate the change. It should not use the reconciliation power to select the operator's business model or routing policy. Provider failure should trigger continuity and succession, not mass registration loss.
Competition does not eliminate governance. It changes where power sits. A four-step test should follow every non-substitutable control point, so portability does not replace an opaque gatekeeper with multiple nested gatekeepers.
The private label does not answer the substance
Private institutions can legitimately coordinate essential infrastructure. They can set conditions, investigate defects, and impose serious consequences. Their legal authority depends on the governing documents and applicable law, not merely an analogy. But when exit is difficult and collateral damage foreseeable, they must be able to explain why a particular measure is not broader, longer, or stricter than its purpose requires.
The four-step test provides that explanation. Establish an authorised and sufficiently important purpose. Connect it with reliable and proposition-specific evidence. Compare effective less harmful alternatives. Weigh the expected benefit against all direct and indirect effects. Then specify scope, time, recovery, and review.
This standard protects both institutional capability and holder continuity. A registry that can demonstrate proportionate enforcement is better placed to act swiftly against genuine fraud, defend difficult decisions, and resist pressure for blunt external control. Restraint is not weakness. It is the evidence that power remains tied to purpose.

