Summary
- NRS's role in this subject is advocacy, research, campaigning, convening and authorized member representation. The operational acts belong to RIRs, authorized registration-service providers and competent legal authorities; citing an NRS position is neither evidence that NRS performs them nor an endorsement by BTW.
- Each recognized holder of IP address space or an autonomous system number should maintain one current control claim that links the named legal entity, its ultimate controller, its authorized registration representatives and its real operational relationship to the resource. The claim is a verified statement about authority, not a public declaration of property ownership.
- Separate companies should remain separate registration entities when law, financing or operations require it. For membership voting, scarcity allowances, related-party transactions and claims of independence, however, entities under common ultimate control should be grouped unless they can demonstrate genuinely independent decision rights under a published test.
- Incorporation evidence is necessary but limited public evidence. Verification must traverse ownership and control chains, identify the natural person or public body at the end, test non-equity control, confirm who may issue instructions, and establish whether the holder operates the network, delegates operations under contract or merely lends its name.
- Public RDAP should expose only decision-useful facts: the named holder, relevant roles, current claim status, assurance level, verification date, verifier identity, material-change status and a protected challenge route. Passports, dates of birth, home addresses, signatures, cap tables and confidential contracts belong in access-controlled evidence custody, not in a public response.
- FATF beneficial-ownership guidance, Legal Entity Identifier relationship data and Companies House identity verification offer bounded comparisons. They show the value of multi-source verification, reusable identity assurance, relationship exceptions and a public verification result, but number governance needs an additional operational test because routing authority and resource use do not follow company ownership automatically.
- A control claim must change over time. Acquisitions, insolvency, delegated operations, key-person departure, changes in public authority, disputed authority and prolonged dormancy should trigger review. A stale but once-accurate claim is not current accountability.
- The rule succeeds only if it constrains institutional power as well as applicants. Evidence collection must be purpose-limited, retention must be bounded, verifiers must be replaceable, adverse findings must carry reasons and review, and the registry operator must publish aggregate concentration measures without revealing protected personal data.
The role boundary is part of the evidence
NRS's own stated positioning supplies the first boundary for this analysis. It is a membership and advocacy organization pressing for decentralization, exit, portability, redundancy and fewer discretionary choke points. Heng Lu's note on why NRS exists says directly that NRS does not sell products or implement commercial solutions; its role is to change the direction of governance. NRS may therefore publish research, organize campaigns, convene affected operators, support members and represent an organization that has granted it authority. It may not turn that representation into registry authority over anyone else.
The implementation layer is separate. RIRs, authorized registration-service providers and competent legal authorities remain responsible for any authoritative registry record, allocation, transfer recognition, RPKI or RDAP operation, technical failover, binding review, insolvency act or legally compelled remedy relevant to this article. The NRO coordinates the five RIRs; it is not another name for NRS. IANA numbering services perform their defined coordination role; they are not an NRS department. Courts and lawful public authorities retain the powers their legal systems actually give them.
BTW's role is separate again. BTW reports the observable structure, checks primary sources and labels proposals as proposals. It does not convert NRS advocacy into fact, campaign on NRS's behalf or infer authority from alignment. That reality-not-advocacy discipline is why the institutional nouns in this article matter: a recommendation from NRS, an act by an RIR and an order from a court are three different things.
Shell amplification is a governance failure, not a filing error
Shell companies are often discussed as if legal form itself were suspicious. That is too crude. A holding company may isolate liabilities. A local subsidiary may satisfy licensing law. A joint venture may separate decision rights between investors. A public-sector operator may have several statutory bodies with distinct mandates. None becomes illegitimate merely because its operations depend on another entity.
The governance problem begins when legal multiplication is treated as independent control. If ten entities under one controller each obtain a membership vote, a scarcity preference, an exemption threshold or a place in a supposedly diverse committee, the institution has counted paperwork rather than power. The same error can distort transfer-market disclosures. A seller and buyer may appear unrelated although both are directed by the same person. Several bidders may look competitive while acting as one economic group.
Internet number registration is especially exposed because legal identity, operational use and routing authority can diverge. A parent may own the holder. A managed-service company may run the routers. A hosting customer may use addresses. An outside consultant may control the registry account. An upstream network may originate the routes. A single public organization name does not explain these relationships.
One verifiable control claim does not collapse them. It gives the institution a disciplined way to distinguish them. The claim identifies who holds the recognized registration, who ultimately directs that holder, who can instruct changes and who operates or delegates the resource. Decisions can then use the layer that matters instead of assuming every incorporated name is an independent center of action.
The claim attaches to a holder, not to every address
The unit of accountability should ordinarily be the recognized resource holder. One organization may hold many prefixes and autonomous system numbers. Requiring a separate ownership investigation for every address would multiply records without increasing assurance. A holder-level control claim can cover a defined portfolio, with resource-level exceptions where authority or operations differ.
The word one therefore means one current claim for one recognized holder version. It does not mean one resource per company, one company per person or one network per corporate group. Nor does it prevent multiple historic claims. When control changes, the former claim remains in an auditable history and a new current claim takes effect at a defined time.
The claim should be version-bound. It identifies the legal holder and the resource set to which it applies, then records any exclusions. A university may operate its main allocation directly while a research consortium controls a specialized block under a documented delegation. A municipal group may have one statutory controller but several independent technical authorities. These cases need explicit overlays, not a false choice between one undifferentiated group and hundreds of isolated address records.
This holder-centered design also limits collection. The registry operator verifies a corporate and operational relationship once, reuses the result across covered resources, and asks for new evidence only when the relationship changes or a risk-based review is due. Verification becomes proportionate to authority rather than proportional to the number of individual addresses.
A complete claim has five linked propositions
A robust control claim should answer five questions that are related but not interchangeable. First, which legal person or public body is the recognized holder? This anchors notices, contracts, dispute rights and continuity. The legal name, jurisdiction, formation reference and current status should be validated against an authoritative or credible source.
Second, who ultimately controls that holder? For a private company, the answer may be one or more natural persons, a listed parent with dispersed ownership, a trust arrangement or another legally recognized structure. For a public body, it may be a ministry, municipality, statute or public corporation rather than a private individual. Control includes voting rights, appointment powers, vetoes and other decisive influence, not only share percentages.
Third, who is authorized to instruct the registration service? A director may control the company but delegate routine registry acts to named officers. Authority must be specific enough to distinguish ordinary updates, transfer requests, security changes and emergency actions.
Fourth, what is the holder's operational relationship to the resource? It may run the network, contract with an operator, provide addresses to customers under policy, hold resources during a documented transition or maintain them for public continuity. A bare assertion that the company is involved in technology is not enough.
Fifth, how can a contradictory claim be raised and resolved? Verification without a challenge route turns an initial judgment into permanent fact. The claim needs protected notice channels, evidence-preservation duties and a status vocabulary that distinguishes current, under review, disputed and superseded states.
Registration is not a universal title registry
The control claim must not overstate what Internet number registration proves. RFC 7020 describes the Internet Numbers Registry System as the structure used to distribute globally unique IP address space and autonomous system numbers. Its concern with uniqueness and accurate registration does not convert every entry into the equivalent of land title under one global property law.
Different regions use contracts, membership rules, policies and legal concepts that may characterize the holder's interests differently. Transferability, revocation, legacy status and rights against third parties can vary. A registry service operator should state that its claim verifies recognized registration control for identified institutional purposes. It should not announce that it has determined ultimate legal ownership against the world.
This boundary protects both accuracy and legitimacy. A court can decide a corporate or property dispute without being told that a technical registry has preempted it. A network can make routing decisions without treating the control claim as a command to accept a route. A security system can use RPKI objects according to their technical meaning rather than treating corporate identity as cryptographic routing authority.
The registry operator still needs a firm current state. It can say which holder it recognizes, which representatives may act and which evidence supports that status. Precision about the nature of the decision makes the claim stronger, not weaker. It prevents a useful accountability record from expanding into a jurisdictionless theory of property.
Legal existence is the first check, not the last
An incorporation certificate establishes that an entity was formed. A current company-register extract may establish that it remains registered and identify directors or persons with significant control where the jurisdiction collects them. Neither alone proves that the entity independently controls a number resource or that the person presenting the document can bind it.
Verification should begin by resolving the legal identity across reliable records. Names, registration numbers, jurisdiction, status, registered address and governing documents must be reconciled. Differences need explanation because transliteration, reorganizations and historical names can create innocent mismatches. A verifier should not reject a legitimate holder merely because one source abbreviates its name.
The inquiry then moves beyond existence. Who can appoint the board? Who exercises veto rights over disposal of major assets? Is ownership held through nominees, trusts or layered companies? Does a management agreement give another party decisive power? Does insolvency law place authority with an office holder? Is a state entity controlled by statute rather than shares?
The result is not a demand for one corporate form. It is a reasoned map from the named holder to the decision authority that matters. If the chain ends in a natural person, that identity is verified. If it ends in a public body or widely held listed company, the claim records the applicable endpoint and why no single natural controller was identified. An exception should explain reality, not create a blank field.
Ultimate control requires more than a percentage threshold
Ownership thresholds are administratively useful. They are also easy to misunderstand. A person below a numerical threshold may control a company through agreements, preferred rights, debt covenants, family coordination or the power to appoint key directors. Conversely, an investor above a threshold may lack operational control in a tightly regulated or jointly governed structure.
The registry operator should use a cascading test. It first identifies persons or bodies with direct and indirect ownership above a published threshold. It then asks whether any person exercises control through voting arrangements, appointment or removal rights, vetoes over resource disposition, contractual management, financing dependence or coordinated action. If no natural person qualifies, it identifies the senior managing officials responsible for the claim while recording that management is not being equated with beneficial ownership.
This approach resembles the functional emphasis in the Financial Action Task Force's 2023 guidance on beneficial ownership of legal persons. FATF emphasizes adequate, accurate and up-to-date information and reports that a multi-pronged approach is more effective than reliance on one source. The registry operator need not become an anti-money-laundering body to learn from that institutional design.
Its purpose is narrower: detect common control relevant to number-resource decisions. That purpose should determine the evidence collected and the consequences imposed. A control finding may aggregate votes or trigger related-party review. It should not be repurposed automatically for unrelated investigations or published as an accusation of wrongdoing.
Operational relationship is the missing second axis
Beneficial ownership answers who controls the holder. It does not answer who operates the resource. A parent company can control a subsidiary while an independent network team runs the allocation under a long-term contract. A public authority can own an operator while technical autonomy is assigned by statute. A company can hold a prefix while customers use portions under documented services.
The claim should classify the operational relationship rather than demand that every holder employ every engineer. Useful classes include direct operation; operation by a controlled affiliate; contracted operation with retained holder authority; delegated customer use under enforceable terms; transitional custody during merger or provider failure; and dormant but justified retention. Each class carries different evidence.
For direct operation, the verifier can examine network contacts, routing arrangements, incident responsibility and authority over relevant service changes. For contracted operation, it should establish the contract's scope, the holder's retained rights, the operator's authority and the exit arrangement. For delegated use, it should determine whether the holder can account for the delegation and respond to abuse or security notices without exposing customer lists publicly.
Routing observations can support but not decide the classification. An origin AS seen for a prefix may belong to an upstream provider, customer or mitigation service. RFC 9255 cautions that the “I” in RPKI does not stand for identity; RPKI is designed for authorization. Operational evidence must therefore be interpreted with contracts, delegation records and current authority, not converted into a simplistic rule that the route origin owns the address space.
A shell test should identify mismatch, not stigmatize structure
The strongest shell indicator is not a brass-plate address or a small payroll. It is an unexplained mismatch among legal holder, controller, authorized representative and operator. A special-purpose company may have no employees yet still be a legitimate financing vehicle whose parent and operating company are fully disclosed. A large company may have thousands of employees while allowing an outside consultant to exercise unrecorded control of its number account.
Review should therefore use combinations of evidence. Repeated addresses, directors, contacts, payment sources, devices or service providers can justify questions but should not by themselves prove common control. Shared corporate services are normal. The decisive issue is whether the same person or group can direct the relevant entities or whether purportedly separate parties coordinate the resource decision.
The holder should be asked to explain anomalies. If five applicants share one representative and one operating contract, they may be a transparent corporate group. The proper result may be five valid holder records grouped for voting and related-party analysis. If they deny any relationship despite identical authority documents and synchronized transactions, enhanced review is justified.
This distinction prevents the control rule from becoming an anti-small-business filter. New networks, community organizations and companies in jurisdictions with limited digital records may require alternative evidence. The standard should test control with equivalent rigor, not demand one wealthy-country document set. Reasons and review matter because false consolidation can be as unfair as unrecognized concentration.
FATF offers a method, not a mandate for maximum disclosure
FATF's beneficial-ownership work is a useful comparator because it confronts layered legal persons, nominee arrangements and stale records. Its 2023 guidance supports a multi-pronged approach in which company-held information, registries and other sources reinforce one another. For number governance, the lesson is that self-declaration, a company register or a registrar's private file should not be the sole source of truth.
The analogy has limits. FATF standards are directed at preventing misuse of legal persons for financial crime and ensuring access for competent authorities. A number-resource body does not inherit every financial-sector purpose, investigative power or disclosure rule. It should not gather wealth information, transaction histories or unrelated family details merely because a bank might do so under a different legal duty.
The better adaptation is structural. Define the person or body whose control matters. Use more than one credible source where risk warrants it. Record how the conclusion was reached. Require timely updates. Make false declarations consequential. Give authorized reviewers access to sufficient evidence while limiting general publication.
This method also avoids a false choice between privacy and verification. Privacy does not require accepting an untested declaration. Verification does not require placing every source document online. The institution can keep an evidence boundary: a public statement of status and provenance, a protected verification record, and a legally governed route for deeper access when a dispute or public duty requires it.
Companies House demonstrates reusable identity with protected evidence
The United Kingdom's current Companies House identity-verification regime provides a narrower comparison. Official guidance states that directors and people with significant control must verify identity and use a personal code to connect the verified person to company roles. The same verified identity can be associated with more than one appointment. That is directly relevant to shell amplification: one person does not become many independently verified people merely by holding roles in several companies.
The privacy boundary is equally important. The Companies House personal information charter states that supporting information supplied for identity verification does not form part of the public register. Guidance for authorized service providers describes a public verification statement while underlying records remain available for accountable inspection rather than general browsing.
The registry operator should borrow the separation, not the exact legal regime. A controller can verify once at an appropriate assurance level and link that verified identity to each holder role. The public can see that verification occurred, the responsible verifier and the relevant dates. The personal evidence remains protected.
Number governance then adds what company registration does not necessarily establish: operational relationship, authority over number-service instructions, resource-specific conflicts and consequences for membership concentration. A company-role code proves a verified person is linked to a filing. It does not by itself prove that the company operates a network or may authorize a transfer.
LEI relationship data shows how to record qualified answers
The Legal Entity Identifier system distinguishes basic entity identity from relationship information intended to answer “who owns whom.” GLEIF's Level 2 materials record direct and ultimate parent relationships and also provide structured reporting exceptions. This is useful because real corporate groups do not always fit a complete, publicly available parent chain.
A qualified answer is better than a blank. A holder may lack a consolidating parent under applicable accounting rules. Disclosure may be legally restricted. No known person may meet the control test. A newly formed entity may still be assembling validated evidence. Each condition should have a defined meaning, supporting basis, review date and consequence.
Exceptions must not become a shelter for convenience. “Information unavailable” is not equivalent to “no controller exists.” The verifier should distinguish inability to obtain evidence, legal prohibition, absence of a qualifying parent, disputed control and temporary pending review. High-impact privileges can be withheld or grouped conservatively while a material uncertainty remains, without erasing the holder's existing registration.
The LEI comparison also supports portability. Relationship data should not be trapped inside one registrar's private format. A holder changing registration-service provider should be able to carry the verified claim, its status and the permitted evidence references. The receiving provider may perform risk-based revalidation, but portability should not force repeated exposure of personal documents when a trusted, current verification remains valid.
Public RDAP should publish proof of checking, not the private file
RFC 9083 defines JSON responses for RDAP and includes entity entities, roles, public identifiers, statuses, events, notices and remarks. Those structures can present a narrow control-claim result without forcing sensitive evidence into public registration data.
A public response should identify the named holder and appropriate organizational contacts. It can state that a current control claim exists, its assurance class, the verification date, the responsible verification organization, the next review window and whether a material change or dispute is pending. An event can mark verification or supersession. A notice can explain the meaning and limits of the status. A protected link can direct a legitimate challenger to the review channel.
The response should not name every ultimate controller by default. It should not expose personal identity numbers, full birth dates, residential addresses, signatures, identity images, account-recovery details, unredacted governance documents or private contracts. Public disclosure of a controller may be justified under applicable law or a specific transparency duty, but it should not arise merely because RDAP can carry an entity entity.
The public vocabulary must also avoid false certainty. “Control verified” means the evidence satisfied a stated standard at a stated time. It does not certify good character, guarantee all filings are true or eliminate the possibility of hidden arrangements. A precise notice lets relying parties use the result without treating it as an unlimited warranty.
The protected evidence bundle should be small and reconstructable
The protected record must let an independent reviewer reconstruct the conclusion. It need not become a permanent archive of every document the holder possesses. A minimum bundle includes the validated legal-entity reference; a control-chain map; evidence supporting direct, indirect and non-equity control; the identity-verification result for relevant natural persons; authority instruments for registration representatives; the operational-relationship classification; declared conflicts; source dates; verifier decisions; and a change history.
Where the verifier relies on an authoritative digital assertion, it can retain the assertion, issuer, validity and verification result rather than a new copy of the underlying identity document. Where a full document is necessary, access should be encrypted, logged and separated from routine support. Highly sensitive fields can be redacted if the retained portion is sufficient to prove the decision.
Every item needs a purpose. A passport may help verify identity; it does not prove corporate control. A shareholder register may show ownership; it does not prove that a consultant may change RPKI settings. A routing observation may show current announcement; it does not prove legal authority. The bundle is strong because distinct evidence supports distinct propositions.
Retention should follow the duty. Decision records and non-sensitive relationship history may need to survive for the life of the registration and a defined dispute period. Raw identity images may justify much shorter retention when a reusable verified assertion exists. Deletion should be evidenced so that minimization is demonstrable rather than promised.
Assurance should rise with the consequence of the claim
Not every act needs the same level of verification. Updating a public helpdesk telephone number presents a different risk from changing the recognized holder, transferring a scarce IPv4 block, replacing an RPKI authority or casting a decisive governance vote. The control claim should therefore have assurance classes linked to permitted acts.
At a baseline level, the verifier establishes legal existence, representative authority and a plausible operational relationship. Higher assurance adds validated ultimate control, independent evidence sources, stronger identity proofing, two-person authorization for consequential changes and a recent review. Exceptional acts can require transaction-specific confirmation even when the standing claim is current.
The 2025 NIST SP 800-63-4 Digital Identity Guidelines provide a useful vocabulary for identity proofing, authentication and federation. Their risk-based separation of functions helps prevent a common error: treating a strong login as proof that the right company controls the resource. Authentication can show that the same account holder returned. Identity proofing connects a person to a real identity. Corporate authority and operational control require additional evidence.
Assurance must also be accessible. Remote-only biometric checking, one document type or one language can exclude legitimate holders. Equivalent in-person, institutional and assisted routes should exist, with measured error and redress. A security standard that systematically rejects some regions will drive applicants toward intermediaries and weaken the direct accountability it sought to create.
Verifiers need competition, common rules and visible responsibility
The registry operator should not make one permanent institution the exclusive custodian of every controller's identity file. Qualified registration-service providers and independent verification organizations can perform checks under common rules. Competition can improve language support, regional knowledge, response time and privacy practice.
Plural verification cannot mean plural standards. Every accepted claim needs a common result format, minimum evidence duties, conflict checks, retention rules, audit rights and responsibility for error. A verifier should sign the result and remain identifiable after a holder changes provider. The receiving provider must be able to validate the signature, status and scope without obtaining unnecessary raw evidence.
High-risk claims may need a second review or central conflict check. That function should compare verified controller references and group relationships without revealing personal details to ordinary staff. It should detect when the same verified controller appears behind multiple holders seeking independent privileges. The match result can be disclosed to the relevant decision maker as common control, with protected access to the reasoning if challenged.
Verifier incentives matter. A provider paid by the applicant may be tempted to accept weak evidence. Random audit, mandatory error reporting, financial responsibility, suspension and public performance measures can counter that pressure. The central institution should also be audited; otherwise it can criticize retail verifiers while operating an opaque matching service of its own.
Control claims require event-driven maintenance
Annual confirmation is useful but limited public evidence. A claim should be reviewed when an event changes one of its propositions. Relevant events include acquisition, merger, sale of controlling interests, insolvency, appointment of an administrator, dissolution, change of statutory authority, replacement of senior representatives, termination of an operating contract, transfer of substantial resource use, compromise of an authenticator or a credible competing claim.
The holder, controller and registration provider should each have defined notice duties. Relying solely on the holder creates a blind spot when the holder is being taken over or impersonated. Corporate-register feeds, returned notices, security alerts and verified complaints can trigger review without automatically deciding it.
During review, the institution should preserve continuity. A pending corporate update should not make an address block disappear or stop lawful routing. The claim can enter “change pending” status. Ordinary low-risk updates may continue, while transfers, votes or security-authority changes are subject to additional approval. A narrowly tailored hold is better than either blind acceptance or total suspension.
Time matters. A controller who left two years ago should not remain the hidden source of account recovery. A dissolved company should not continue to cast membership votes. A temporary operator should not acquire permanent authority through inattention. Service standards should measure time from credible notice to triage, evidence request, provisional protection and final reasoned decision.
Restructuring should preserve history without preserving fictional independence
Corporate groups reorganize for ordinary reasons. A parent may insert a new holding company, combine subsidiaries, move operations across jurisdictions or spin out a business. The control-claim system should make such changes legible without treating every restructuring as a new allocation or every unchanged controller as irrelevant.
If the legal holder remains the same and ultimate control changes, a new claim version should identify the effective date and preserve the prior history. If the legal holder changes but control and operations remain continuous, the substantive holder-change rules still apply; continuity can simplify verification but cannot erase the legal substitution. If several holders merge, their records can remain distinct while governance grouping and authority are updated.
The hardest case is a nominal separation. A parent sells a minority stake, appoints familiar directors and retains vetoes over resource disposition while claiming that the subsidiary is now independent. The test should examine actual reserved rights and coordination, not the transaction label. Independence begins when decisive control genuinely changes.
Conversely, related companies can have meaningful operational autonomy. Common ownership may justify grouped voting while separate technical authority remains visible for incident response. The control claim should support more than one institutional view of the same facts. Governance concentration, legal registration and network operations are distinct questions; a well-designed record lets each use the relevant relationship.
Leasing and delegated use must not become invisible control transfer
IPv4 scarcity has increased arrangements in which a recognized holder allows another organization to use addresses without changing the holder of record. Such arrangements vary by regional policy and contract. A control claim should not declare them universally valid or invalid. It should ensure that the recognized holder's operational relationship remains intelligible.
A legitimate delegation should identify the covered resource, duration, operator, authority over routing and security entities, abuse responsibilities, notice channels and exit conditions. The holder should retain whatever control its recognized status requires. If the customer can transfer, re-delegate or permanently exclude the holder without further authority, the arrangement may resemble a concealed holder change and deserves review.
Public disclosure should remain proportionate. RDAP may need a role contact or status that directs operational inquiries. It does not need the customer's commercial terms or every end user's identity. Protected evidence can establish that the delegation exists and that responsibilities are assigned.
The same rule applies to managed RPKI. A service provider may create and publish entities for the holder, but the control claim should identify who authorizes that service and how authority returns on exit. RFC 6480 explains that resource certificates and signed entities support verifiable routing authorization; it does not make the hosting provider the ultimate controller of the holder. Contracted technical power must be explicit, bounded and reversible.
Governance aggregation should be purpose-specific and reviewable
Once common control is verified, the registry operator must decide what follows. The result should not be automatic consolidation for every purpose. Legal holder records can remain separate. Billing may remain separate. Operational contacts may remain separate. The question is where independent treatment would let one controller multiply institutional power or evade a substantive limit.
Membership voting is the clearest case. Entities under common ultimate control should ordinarily form one voting group or face an aggregate cap. Committee-diversity claims should disclose the group so several affiliates are not presented as independent constituencies. Scarcity allowances, small-holder thresholds and transaction exemptions should be calculated across controlled entities where the underlying rule is intended to limit concentration.
Related-party transfers require disclosure and possibly a different review, because price and competition evidence carry different meaning when both sides share control. Public statistics can report concentration by verified group while continuing to list the legal holders of resources accurately.
These consequences need reasons and appeal. A family relationship alone should not prove coordinated control. A minority investor should not lose independence solely because it owns stakes in several networks. Public-sector entities under one government may have legally insulated mandates. The grouping test should identify the exact decision right that connects them and permit evidence of genuine separation. Purpose-specific treatment is more defensible than a permanent label that all institutions must accept.
Privacy is a control on the verifier, not a reason to avoid verification
The institution's own appetite for data can become a governance risk. Controller files may expose home addresses, identity documents, family relationships, signatures and security channels. A breach could endanger individuals and make account takeover easier. Broad staff access could turn an accountability measure into commercial intelligence.
Data minimization should therefore be a design rule. The Information Commissioner's Office summarizes the principle as collecting data that is adequate, relevant and limited to what is necessary for the stated purpose. Applied here, that means the registry operator first names the decision: verifying controller identity, representative authority or operational relationship. It then collects only evidence that supports that proposition.
Purpose separation should be technical as well as legal. Staff handling a routine RDAP correction should see the public claim result, not identity images. A governance officer assessing vote aggregation may need the common-control match, not the controller's address. An independent reviewer may receive a fuller record under logged, time-limited access. Bulk export of controller evidence should be prohibited except under a defined legal duty with recorded authorization.
Individuals need notice, correction and protection routes. If a person is wrongly identified as controlling a holder, the claim can affect reputation and institutional rights. The person should be able to contest the link without first publishing more personal data. Security-sensitive controllers may need protected contact methods or lawful nondisclosure, while the institution still records a verified endpoint.
Cryptographic commitments help with integrity, not truth
A cryptographic commitment can show that evidence or a decision record has not changed since a stated time. Signed attestations can let a receiving registrar verify the issuer and scope. Append-only witnessed events can expose silent rewriting. These are valuable controls for portable claims.
They do not prove that the underlying statement was true. A hash of a false declaration is an enduring false declaration. A signature proves which key signed, not whether the signer understood a nominee arrangement. A timestamp proves existence, not current validity. Institutional verification still requires source assessment, authority tests and review.
The right design uses cryptography to narrow disputes. A verifier signs a structured result that identifies the holder version, covered resources, controller-reference class, operational class, assurance, source dates and expiry. Raw evidence is encrypted separately. Public systems can check the signature and revocation status. An authorized reviewer can compare the protected evidence with the signed conclusion.
Key governance must be explicit. If one provider can alter claims and the verification keys that validate them, portability is weak. Signing authority should use separated roles, rotation, revocation and independent witness records. The holder must be able to leave a provider without losing proof of prior verification. Integrity technology is most useful when it supports institutional separation rather than decorating centralized discretion.
Challenges need graduated protection and reasoned decisions
Anyone should be able to signal an apparent error, but not every allegation should freeze a holder. An open intake can accept evidence while protecting the complainant from unnecessary disclosure. Triage should distinguish simple data correction, representative compromise, hidden common control, disputed corporate authority and urgent risk of irreversible change.
A credible challenge triggers preservation and targeted safeguards. The registry operator may require a second authorization for transfers, prevent the disputed controller from changing recovery channels or mark a material relationship as under review. Existing registration and lawful network operation should continue unless a specific risk requires a narrower intervention.
Both holder and affected controller should receive the substance of the claim, subject to lawful protection of sources. They need time to respond, access to the evidence relied upon or an adequate summary, and a decision stating the control test, facts found, uncertainties and consequences. An independent reviewer should be able to alter both the conclusion and the interim safeguards.
Malicious challenges need consequences, but a high penalty for an unsuccessful report would suppress useful correction. The institution should distinguish good-faith error from fabricated evidence or repeated harassment. It should publish aggregate outcomes: how many claims were corrected, how long reviews took, how often interim restrictions were used and how many decisions changed on review.
The challenge route is not an optional customer-service feature. It is the mechanism that keeps verification from becoming self-authenticating. A claim remains legitimate because it can be tested against evidence under fair rules.
Five cases show what the rule would change
A transparent corporate group. One telecommunications parent has four regulated subsidiaries in different countries. Each subsidiary is the recognized holder of local resources and has a local network team. The parent appoints every board and controls major transfers. Four holder records remain accurate. One verified control group is used for registry operator voting and concentration measures. Local operational relationships remain separate. No private passport data appears in RDAP.
A genuine joint venture. Two infrastructure companies each own half of a new operator. Reserved matters require both, while day-to-day number operations belong to an independent management team. The claim identifies joint ultimate control, the exact veto structure and the operator's authority. Neither shareholder is presented as the sole controller. Governance rules can treat the venture as related to both parents for conflicts without assuming either can act alone.
A nominee holder. A newly incorporated company applies through a consultant, shares payment and contact details with several existing holders and provides no credible operating arrangement. Corporate records prove existence, but evidence shows the consultant can direct all resource actions while the stated director cannot explain the network. The claim is not verified at the required level. The institution asks for the true authority and operational relationship rather than accusing the company merely because it is new.
A managed public-sector network. A ministry is the legal holder, a statutory digital authority controls policy and a private contractor operates the network. The control endpoint is the public authority established by law, not a fictional natural beneficial owner. The contractor is recorded as operator with bounded authority and tested exit. Public data identifies accountable organizations and service contacts without exposing individual civil servants.
A disputed acquisition. A buyer announces that it controls a resource-holding company, but the seller contests completion and a court proceeding begins. The current claim enters disputed-change status. The existing holder record remains reachable. High-consequence changes require independent approval. The final decision follows authoritative legal and corporate evidence, while the history shows when each claim was made and what interim limits applied.
These cases illustrate why binary “verified company” status is too weak. The institution needs structured distinctions among legal existence, ultimate control, representative authority and operation. It also needs restraint: unresolved control does not automatically prove fraud, and common ownership does not erase separate lawful entities.
Measures should reveal concentration and verifier performance
The registry operator should publish measures that allow outsiders to judge whether the rule changes outcomes. Useful figures include the share of active holders with current claims; resources covered by each assurance class; median age of control evidence; percentage of claims with documented operational relationships; number of controlled groups spanning multiple holders; and voting concentration before and after aggregation.
Verifier measures should include completion time, requests for excessive evidence, abandonment by region, false-match findings, corrections, successful reviews, security incidents and portability of attestations. Results should be segmented carefully enough to expose exclusion without revealing small groups or personal identities.
The institution should also measure what it does not know. It can report claims pending because no natural controller was identified, legal disclosure was restricted, corporate sources conflicted or operational evidence was incomplete. A declining unknown rate may indicate improvement; a sudden zero may indicate that reviewers are accepting convenient answers.
Independent sample audits should trace a public claim back to protected evidence and test whether each item served a stated purpose. Red-team exercises can attempt shell amplification through layered companies, common representatives, nominee directors and coordinated transactions. Privacy audits should attempt unauthorized access and unnecessary linkage. A control regime earns trust by detecting both applicant evasion and institutional overreach.
Adoption should begin with high-consequence privileges
Requiring every existing holder to complete an enhanced review on one date would create delay, unequal burden and superficial checking. Adoption should start by defining the claim, public vocabulary, evidence boundary, verifier duties and review rights. Existing data can then be mapped without pretending that legacy fields already prove ultimate control.
New holder recognition, holder change, high-value transfer, new voting eligibility and new security authority should require the full claim first. Existing holders can enter a staged schedule based on consequence, age of evidence, resource scale and known corporate change. A holder that has not yet completed enhanced review should retain public reachability and ordinary continuity, while privileges that depend on independent control may remain unavailable until verified.
The registry operator should test the standard across corporate groups, community networks, universities, public bodies, insolvencies and jurisdictions with weak digital registries. Alternative evidence routes must be established before enforcement. Verifiers need common training, but their judgments should be audited against outcomes rather than scripted document lists.
Portability should be tested from the beginning. A sample holder must be able to move its signed claim result to another qualified provider, preserve history and limit repeat disclosure. If the first implementation binds every private document to one provider's account, it has reproduced the dependence that accountable registration is meant to reduce.
The boundary of the claim must remain visible
A 0.99 confidence judgment supports the institutional design, not a claim that every jurisdiction defines control identically or that one evidence set fits every holder. Corporate, trust, insolvency, privacy and public-sector law differ. The registry operator will need jurisdiction-sensitive guidance and independent legal review for contested cases.
The claim also cannot guarantee that hidden control never exists. Nominees can lie, records can be stale and influence can be exercised informally. The proper promise is a proportionate, reviewable and evidence-backed conclusion whose uncertainty is recorded. Requiring reasons, updates and challenges makes evasion harder and correction possible.
Nor should verified control become a universal reputation score. It says who directs a holder and how that holder relates to a resource. It does not rate political acceptability, financial strength, network quality or lawful speech. Function creep would deter truthful disclosure and concentrate excessive power in the verifier.
These boundaries are not concessions. They are the conditions under which strong verification can coexist with plural legal systems and personal privacy. A narrow claim can be enforced more consistently than an unlimited demand to know everything about every entity.
One claim makes institutional plurality honest
Number-resource governance needs legal entities because law acts through them. It needs operational organizations because networks are run by people and systems that may sit elsewhere. It needs ultimate-control information because institutional power can hide behind formally separate names. The mistake is to force one field to represent all three.
One verifiable control claim gives each layer a place. The legal holder remains named. The ultimate controller is verified under a functional test. Authorized representatives are bound to defined acts. The operator or delegation is described. A public result supports accountability. Protected evidence supports review. History shows change.
That design does not prohibit corporate groups, managed networks or privacy. It prevents them from being used as excuses for false independence. A controller may organize several companies, but cannot automatically turn one will into several votes or several unrelated scarcity claims. A holder may protect a person's identity documents, but cannot replace verification with secrecy. A provider may compete to perform checks, but cannot privatize the meaning of a valid claim.
Institutional legitimacy depends on seeing power at the level where it is exercised and disclosing only what the public needs to evaluate the result. One holder, one current verifiable control claim is a practical rule for achieving both. It makes plurality possible without allowing incorporation to manufacture independence, and it makes verification credible without making sensitive lives public.
Sources and analytical limits
The central number-resource boundary comes from RFC 7020's account of globally unique Internet number registration. RFC 9083 supports the discussion of RDAP entities, roles, events, statuses, notices and remarks. RFC 6480 and RFC 9255 support the distinction between resource and routing authorization, identity and operational control.
Comparative institutional lessons come from FATF's 2023 beneficial-ownership guidance, GLEIF materials on Level 2 parent relationships and reporting exceptions, Companies House identity-verification guidance, NIST SP 800-63-4 and public data-minimization guidance from the Information Commissioner's Office. None is treated as directly binding on a registry service operator. Each addresses a different legal and operational field.
The proposed assurance classes, public claim fields, grouping consequences, challenge protections and adoption sequence are institutional recommendations derived from those comparisons. They should be tested against applicable law, holder diversity and actual error rates before fixed thresholds are adopted. The durable principle is narrower: every recognized holder should have one current, reviewable claim about real control and real operation, while the evidence exposed publicly should be no broader than the accountability purpose requires.
NRS and BTW role sources
- Number Resource Society — NRS's own public positioning as a global non-profit membership organization that campaigns, supports businesses and represents members in RIR governance.
- Heng Lu, “On Why NRS Exists — and Why Decentralization Is No Longer Optional” — the source doctrine defining NRS as an advocacy group, not a product vendor or commercial implementation body.
- Heng Lu, “On Why BTW.Media Exists — and Why Reality, Not Advocacy, Is the Product” — the editorial boundary requiring BTW to describe observable structure and proposals without campaigning for them.

