Summary
- ARIN's draft January 2026 Board minutes report that a periodic review of Registration Services Department documentation, workflow and structure found none of the audited tickets out of compliance with the NRPM and found the department operating efficiently.
- Draft April minutes describe a separately commissioned, incident-focused Baker Tilly audit after the December 2025 4.10 allocation error. They report inconsistencies in every area examined, while also saying the ten assessment criteria were recently created and had not previously been a focus.
- Those findings are not like-for-like. The public January record centres on ticket-level policy conformance; the April record centres on structural controls tested against a new criteria set. Neither public record supplies the population, sample, denominator or complete exception taxonomy needed to compare them.
- ARIN can preserve both findings and make follow-through legible with a versioned audit crosswalk joining each engagement to its trigger, objective, period, unit, governing rule, exceptions, severity, recommendation owner, due date, implementation, retest and the transactions eventually covered by any Registry Control Plane.
The contradiction appears only after the labels are stripped away
Two statements in ARIN's 2026 Board record invite an easy headline.
In January, trustees heard that an audit of Registration Services Department tickets had found none out of compliance with the Number Resource Policy Manual. The department continued to run efficiently. In April, trustees heard that an outside audit had found inconsistencies in every area it examined.
Placed in adjacent cells, the sentences look like a clean before-and-after reversal. But the public minutes do not describe the same engagement, the same commissioning trigger or the same test. Treating them as a single score would erase the information that determines what each result can support.
The 13 January draft minutes call their item the 2025 ARIN RSD Audit Report. ARIN's CXO described a recurring exercise: every two years an outside company reviews departmental documentation, workflow steps and structure. The reported ticket finding concerned compliance with the NRPM. The record does not disclose how many tickets existed, how many were selected, which period they covered or how selection was performed.
The 19 April draft minutes locate their audit elsewhere. It followed the December 2025 resource-issuance incident, ARIN hired Baker Tilly, and Mike Cullen presented a draft report. The minutes say inconsistencies appeared in all areas examined. They immediately qualify that sentence: the ten criteria had recently been created and had not previously been a focus.
That qualification does not make the April finding trivial. It makes its boundary essential. A newly articulated control can expose a genuine structural weakness without proving that staff previously violated an established rule. A conforming ticket can likewise show that the recorded allocation decision followed the NRPM without proving that the inventory, authority separation and deletion safeguards around it were sound.
The December incident shows the gap between a policy result and a control result
ARIN's 12 December incident report supplies the operational reason to keep those tests apart.
The address block 23.150.164.0/24 had been correctly allocated to one customer. During a 4.10 allocation process on 2 December 2025, it was removed and reissued to another. ARIN describes a manual, partially offline inventory process using an electronic black book and spreadsheet separate from the primary system. Removing the block also removed associated registry services, including its ROA and reverse DNS. A third-party provider then announced the block under the incorrect registration.
ARIN says it did not detect the condition automatically. The original customer reported it on 9 December, after the incorrect state had persisted for about seven days. ARIN restored the original resource, issued a replacement /24 to the other customer, coordinated withdrawal of the route and completed corrective work that day. The public report contains no customer technical-impact statement, so the record does not establish an outage or measured routing loss.
The incident is not adequately explained as a careless click. ARIN's own account identifies an execution path in which inventory outside the primary system, weak business-rule enforcement and single-party action could combine. It also says immediate controls were completed: tickets containing a network delete were limited to experienced analysts, received dual review and were checked by a second reviewer at set times.
That distinction matters for the audit records. A ticket may contain fields and approvals that conform to policy even while the surrounding system permits a resource to be deleted from a hybrid inventory state. Conversely, a structural audit can find inconsistent application of newly stated control criteria even if no sampled ticket breaches the NRPM. The tests overlap operationally, but their findings cannot be subtracted from each other.
A crosswalk should carry the denominator with the conclusion
ARIN does not need to publish customer data, security-sensitive procedures or complete working papers to make the record comparable. It needs to publish the coordinates of each conclusion.
For every audit or control review, a durable crosswalk should identify:
| Coordinate | Minimum evidence-safe disclosure |
|---|---|
| Engagement | Stable report identity, commissioning body and whether the document is draft or final |
| Question | Trigger, objective, audit period and intended assurance claim |
| Test set | Population, sample size, selection method and unit of analysis |
| Standard | NRPM section, policy version, control statement or criteria version in force for the test |
| Finding | Control area, exception definition, count, denominator and bounded severity |
| Action | Recommendation, accountable owner, target date, implementation state and dependency |
| Assurance after action | Retest method, result date and remaining exception |
| Architecture link | Transaction, application and enforcement point covered by the Registry Control Plane |
The absence of those fields is visible in both draft-minute records. January refers to Exhibits W and X and to recommendations without enumerating them publicly. April refers to a draft report, ten criteria, examined areas and recommendations without listing the criteria, counts or severity. Neither omission proves that the Board lacked detail. It means the public reader cannot reproduce the boundary of the reported finding.
A crosswalk would prevent several attractive but unsupported claims. The January sentence does not show that every RSD ticket was tested or that every departmental control was effective. The April sentence does not show ten failures, one failure per criterion or a severe defect in each area. The new criteria cannot be treated retroactively as if their mere later articulation proved an earlier mandatory breach. Nor does the public record establish that the two presentations were one combined Baker Tilly report.
The Registry Control Plane is a proposal, not yet an answer
The April discussion moves from audit finding to architecture. ARIN staff proposed a Registry Control Plane between applications. Board- and executive-defined rules could be enforced centrally, reducing the chance that one application path or one actor could execute a sensitive change without the intended controls. Centralised auditability is part of the stated rationale.
The same minutes preserve substantial uncertainty. Trustees asked what the control plane would do, which system, application or integration would come first, how it would integrate and what outside development would displace. Staff said specifications—particularly cost and time—still needed definition.
The proposal should therefore be judged as a design direction, not described as approved, funded, procured, deployed, tested or effective. Its audit value will depend on transaction coverage. A control plane that records a resource deletion but does not reconcile the inventory authority behind it may create a better log of the wrong action. One that blocks deletion but allows an undocumented bypass may move the single-party risk instead of removing it.
The crosswalk should name the covered transaction at the same granularity as the incident: allocation under 4.10, removal from inventory, revocation or removal of ROA and reverse DNS state, reissue, and any exceptional override. It should also say which application originated the request, which rule version evaluated it, which identities approved it and which independent evidence confirmed the post-change state.
Draft records require precise verbs
Both Board pages label the minutes as draft. That status does not make them unusable; it determines how firmly they should be described. The records report what was presented and discussed. They are not substitutes for the underlying audit reports, and the checked public pages do not expose the referenced exhibits.
ARIN's current Board-meetings index captured on 31 August lists January and April 2026. April says staff intended to present next steps at the next Board meeting in August. The index observation does not prove that no August meeting occurred or that no work progressed. ARIN's meeting procedures explain the governance framework, but do not close that evidence gap.
The policy reference is also live rather than ornamental. The NRPM is the community policy manual against which the January ticket result was reported. A useful crosswalk would pin the relevant version and section rather than say merely “policy compliant.” Otherwise a later reader cannot distinguish a change in practice from a change in the rule.
Sources
- ARIN resource issuance incident report, 12 December 2025, for the 4.10 issuance error, hybrid inventory mechanism, seven-day detection interval, immediate controls and remediation direction.
- ARIN Board draft minutes, 13 January 2026, for the periodic 2025 RSD audit description and the reported ticket-level NRPM finding.
- ARIN Board draft minutes, 19 April 2026, for the incident-focused draft audit, new criteria, reported inconsistencies and Registry Control Plane discussion.
- ARIN Board meetings index, for the public 2026 meeting-record listing observed on 31 August.
- ARIN Board meeting procedures, for the framework governing Board meetings and records.
- ARIN Number Resource Policy Manual, for the policy authority named in the January audit finding.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

