Summary

  • A card payment system is a shared collection of rules, standards, and decision agreements that connect issuers, acquirers, merchants, and cardholders. It creates interoperability but does not replace banks, processors, contracts, courts, or public regulation.
  • Private rules can coordinate a global network if the conditions for admission are security-related, consistently applied, and no more restrictive than necessary. Incumbency, nationality, or institutional convenience are not substitutes for an objective risk test.
  • Internal enforcement requires notification, evidence, reasoning, proportionality, and a review path. An appeal controlled by the same institution can correct errors, but it cannot be the only constraint on a network whose decision affects market access.
  • External competition law is important because a technically uniform rule may still suppress merchant choice, tie one service to another, protect the position of established entities, or obscure prices. The European Union's restrictions on card payment scheme behavior show how law can preserve interoperability while limiting overreach.
  • Number registries and card payment systems share a dependence on accurate shared records, authenticated entities, and consistent rules. They differ in transaction frequency, money movement, resource scarcity, routing, territorial structure, and the feasibility of parallel authoritative services.
  • The transferable design is a disciplined rulebook: defined powers, non-discriminatory access, separation of services, reasoned sanctions, independent review, legal accountability, and portable service relationships without double registration claims.

A rule is infrastructure, expressed as an obligation

TheEuropean Union's Interchange Fee Regulationdefines a card payment system as a single set of rules, practices, standards, or implementation guidelines for card transactions, together with the entity responsible for the functioning of the system. It explicitly separates this concept from the infrastructure that supports operation. The distinction is easily overlooked because consumers see a single brand at the point of sale. Behind the brand, however, several legal and technical functions remain separate.

An issuer issues a payment instrument and maintains the relationship with the payer. An acquirer serves the merchant. A processor performs authorisation, clearing or settlement messages. Banks or other regulated institutions hold accounts and bear defined financial obligations. Merchants decide what to sell and, within legal and contractual limits, which payment methods to accept. The system provides shared semantics: what a valid message means, which entity must act, what evidence is relevant, and how exceptions are allocated.

The rulebook is therefore not a commentary alongside the network. It is part of the network's productive capacity. A message can only move at electronic speed because entities have previously accepted how it will be authenticated and interpreted. A disputed transaction can only be resolved at scale because time limits, reason codes and burdens of evidence are shared. Security controls can only be coordinated because the consequences of non-compliance are sufficiently predictable to change behaviour.

This is the first relevant lesson for number registries. Technical records do not remain coherent through goodwill alone. Entities need shared definitions for allocation, transfer, registration, authority, custody, and correction. Yet the existence of a rulebook alone says nothing about whether its author uses power fairly. Rules create coordination; discipline creates legitimacy.

The four-party model shows why delineated roles matter

In a typical four-party card arrangement, payer and merchant do not contract directly with the system for every function. Issuer and acquirer stand on opposite sides, while the system sets common conditions that connect them. Clearing and final settlement may involve additional entities. The model distributes responsibility rather than concentrating every action in an institutional centre.

This distribution protects clarity. A system can decide whether a message meets its standards without deciding whether the underlying purchase was wise. An issuer can authorise against an account without guaranteeing the merchant's product. An acquirer can submit a transaction without becoming a merchant itself. A court can decide fraud or contract claims without rewriting all network records. Public authorities can regulate consumer protection, prudential risk and competition without operating every authorisation service.

Card rules sometimes blur these boundaries, particularly when a system also offers processing, token, security or data services. That is precisely why separation has become a regulatory concern. The useful institutional principle is not that all functions must be performed by different firms. It is that each exercise of power must be assigned to a defined role and judged under the rules appropriate to that role.

Number administration needs the same discipline. A registry records an allocation or transfer under the applicable policy. A network originates a route. A relying party evaluates routing security information. A contracting party makes a commercial promise. A court applies law within its jurisdiction. Conflating these facts into a claim of universal control would make the record less reliable, not more. The registry's authority is stronger when its boundary is explicit.

Acceptance creates value while concentrating power

Payment networks exhibit strong indirect network effects. Cardholders value a card that many merchants accept. Merchants value access to a payment method used by many customers. Issuers and acquirers favour a network with wide reach. As participation grows, the shared rulebook becomes more useful. It also becomes harder for a single entity to reject a rule change without losing access to customers or merchants.

This dual effect explains why private coordination cannot be judged solely by voluntary contract. A bank may have signed the membership agreement, and a merchant may have signed with an acquirer, but the economic significance of consent changes when a small number of systems provide access to a large share of retail demand. Exit may be legally possible but economically punitive. A network-wide rule can shift bargaining positions far beyond the system's direct customers.

The response is not to treat every system requirement as coercion. Uniform security and messaging standards are why the network works. Nor is it to assume that size makes all rules efficient. The central question is whether a restriction is necessary for a legitimate network function, whether the same objective could be achieved less restrictively, whether the burden is evenly distributed, and whether affected parties can challenge the institution's reasoning.

Number registries also sit in a dependency network. An accurate registration becomes more valuable as operators, security teams, counterparties and other registries use it. The resulting dependency gives the maintaining institution significant power. Member consent remains relevant, but it cannot carry the entire legitimacy argument. Heavily depended-upon records need duties proportional to the dependence they create.

Security qualifications are only valid if they address a real risk

Not every applicant should receive direct access to a payment network on identical terms. Issuing and acquiring can create settlement risk, fraud losses, consumer harm, money-laundering exposure, and operational disruption. A system may require financial capacity, technical competence, security controls, legal authorisation and reliable settlement arrangements. Non-discrimination does not mean indifference to risk.

The difficult question is whether a qualification tests risk or merely preserves the incumbent class. Australia's payment reforms offer a useful example. When theReserve Bankexamined access restrictions in the early 2000s, it asked whether the participation boundaries restricted competition more than necessary to protect financial safety. Its access regimes for the designated Visa and Mastercard systems were calibrated to that balance. The principle was not universal access. It was disciplined exclusion.

A defensible rule identifies the harm, the evidence connecting the requirement to that harm, and the reason why a less restrictive control would be inadequate. Capital can address settlement risk. Certification can ensure technical compatibility. Insurance or guarantees can cover some contingent losses. Supervision can manage conduct risk. A categorical label such as bank, member, local operator or established institution is weaker when a newcomer can demonstrate equivalent safeguards through another route.

This test translates well to number administration. Authentication, corporate authority, anti-abuse measures, fee payment and data accuracy can justify conditions. A rule that favours a particular institutional form, geography or historical relationship requires a separate explanation. The registry should be able to state what operational risk each condition controls and why the condition remains proportionate given changing technology and markets.

Non-discrimination is a method, not a slogan

Identical wording can produce unequal access. A requirement may apply to everyone but be tailored to the systems, balance sheets or business models of established entities. Conversely, differential treatment may be justified if entities create materially different risks. Non-discrimination requires both consistent treatment of comparable cases and reasoned differentiation among unequal cases.

Regulation in the European Union uses this structure repeatedly. Minimum conditions in network industries are generally required to be transparent, objective, proportionate and service-related. In card payments, the Interchange Fee Regulation prohibits territorial discrimination in processing rules, requires scheme and processing undertakings not to distinguish between affiliated and unaffiliated users, and requires that differences relating to co-badging be objectively justified and non-discriminatory.

The significance lies in the burden of proof. A system cannot simply answer a challenge by noting that the same clause appeared in every contract. It must connect the clause to a legitimate function and demonstrate consistent application. Decisions should be reproducible across applicants, regions and commercial affiliations. Exceptions should be recorded, because unexplained exceptions reveal the actual rule more accurately than the formal text.

For number registries, this means publishing decision criteria so that an applicant can anticipate what evidence is required. It also means monitoring outcomes. If similarly positioned operators experience materially different review times, documentation requirements, or transfer outcomes, the institution needs an explanation grounded in the circumstances of the cases. Aggregated publication can reveal structural inequalities without disclosing confidential records.

A global rulebook needs local legal humility

Card payment systems operate across borders, but their rules do not float above national law.Mastercard's published rulesstate that customers must comply with applicable law and are not obligated to take any action that is clearly prohibited by law; the company may require another lawful activity.Visa's public rulessimilarly operate through entity agreements subject to legal and regulatory obligations. The exact clauses change, but the hierarchy is clear: network participation does not create immunity from law.

This hierarchy creates complexity. Consumer rights, payment licenses, sanctions, insolvency, privacy and competition rules vary. A globally consistent service may require local adaptation. The risk is using localisation as a path to preference or using global uniformity as a reason to disregard mandatory law. Good system governance distinguishes a jurisdiction-specific legal requirement from a commercial preference and documents why a deviation exists.

External law also provides remedies that private review cannot. A entity can challenge a contractual decision in court. A regulator can investigate market behaviour. A competition authority can prohibit a restrictive rule even if every direct member approved it. Legislatures can set public limits on fees, steering or access. These institutions do not need to operate the network in order to constrain it.

Number registries have the same need for humility and a more difficult geographic jurisdiction. Their service regions cover many legal systems while number use and corporate groups cross regional boundaries. A registry should state which law it applies to which action. It should not turn a service region into territorial sovereignty nor treat transnational coordination as exemption from binding law.

Merchant steering reveals the competition hidden in technical rules

A rule can look like a consistency requirement while redistributing commercial choice. Before competition law intervention, payment systems used restrictions that limited merchants' ability to steer customers to cheaper methods. In 2010, theUnited States Department of Justicechallenged Visa, Mastercard and American Express rules that prevented merchants from offering discounts, rebates or information that favoured cheaper cards. Visa and Mastercard agreed to a remedy that expanded merchant steering; the case against American Express continued separately.

The European Union later prohibited system or licence rules that prevent merchants from steering customers to a preferred payment instrument. It also limited the broad 'honour all cards' rule. A merchant cannot generally be required to accept every product merely because it accepts another card of the same brand, though safeguards against issuer discrimination for cards of the same regulated category remain.

These interventions did not reject honour-all-card rules entirely. They separated two effects. Requiring acceptance regardless of a single issuer's identity can protect network universality and cardholder confidence. Requiring acceptance of every more expensive product can tie different services and weaken merchant bargaining power. The regulatory task was to preserve the first effect while limiting the second.

Number administration needs comparable attention to bundling. A registry may legitimately require accurate holder data before providing related authentication or routing security services. It should not make an unrelated commercial service a condition of basic registration without clear necessity. Nor should it use control over an indispensable record to exclude compatible verification, transfer facilitation or directory services provided by others.

Separation prevents the rulemaker from favouring itself

Article 7 of the European Union's Interchange Fee Regulation requires organisational, accounting and decision-making independence between card payment schemes and processing undertakings. It prohibits bundled presentation of scheme and processing prices, cross-subsidisation, and discriminatory treatment that favours affiliated undertakings. It also requires that schemes allow authorisation and clearing messages for a single transaction to be handled by different processors, and restricts business rules that hinder interoperability.

The provision addresses a recurring institutional problem. When the entity that sets participation rules also sells a contestable adjacent service, it can design technical requirements that make its own service the default. A nominally neutral standard may include proprietary interfaces, short transition periods, bundled fees or certification costs that competitors cannot meet. Users may not be able to tell whether they have purchased coordination or been forced to accept processing services.

Separation does not require hostility to integration. An integrated provider can be efficient and innovative. The discipline is to expose prices, decisions and interfaces sufficiently to test whether the rulemaking function is being used to favour the commercial function. Independent accounting and decision responsibility make this test possible.

The analogy for number registries should be applied closely. Core functions such as uniqueness and registration may naturally be centralised in one service area. Adjacent identity verification, mediation, hosting, security analysis and operational support can be contestable. If a registry provides these, it should publish interfaces and avoid tying them to recognition in the shared record unless the tie is demonstrably necessary.

Rule changes require notice, because trust is an investment

Payment entities build systems, train staff, price services and sign customer contracts based on system requirements. A technically small rule change can require significant implementation effort. Published card rules therefore use effective dates, regional supplements, bulletins and implementation periods, though the adequacy of notice can still be challenged. The governance principle is that a network should not induce non-compliance by surprise.

Notice is only the start. A meaningful change process describes the problem, identifies affected roles, discloses the expected burden, allows evidence from entities, and explains the final decision. Emergency changes may require shorter notice when fraud or security risk is imminent, but an emergency power should have a narrow trigger, a documented decision, and later review. Temporary controls should not silently become permanent architecture.

Dependency interests are diverse. A large issuer can absorb a software change that overwhelms a small entity. A processor may need lead time for certification. A merchant may face change through an acquirer with a contractual amendment. The institution should therefore test transition costs across the network rather than treating formal notification of direct members as sufficient communication to all affected.

Number registries should apply the same discipline to authentication rules, transfer documentation, fee structures, access to registration data, and changes to security services. Operators need sufficient time to maintain service continuity. Retroactive rules should be exceptional and legally justified. A registering institution protects trust when it makes changes visible before it makes compliance impossible.

Enforcement must distinguish between correction, protection and punishment

Card payment systems can reject messages, allocate transaction losses, require remediation, impose fees, restrict activity, or terminate participation. These measures have different purposes. Message rejection protects immediate technical integrity. A chargeback allocates responsibility according to transaction rules. A remediation order aims at future compliance. A financial assessment can deter or punish. Suspension protects the network but can also destroy a entity's business.

Legitimacy requires the institution to name which purpose it is pursuing. A protective measure may need to be fast, based on preliminary evidence, especially when a security breach is involved. It should then be narrow, time-limited and reviewable. A punitive assessment requires notice of the alleged breach, access to the decisive evidence, an opportunity to respond, and a reasoned outcome. Termination should cite both authority and proportionality analysis.

Published Visa rules describe allegation, investigation and non-compliance assessments, offering internal avenues for certain arbitration or compliance complaints. Mastercard's rules allow a customer to request review of certain non-compliance assessments within a specified period, while granting senior franchise personnel broad discretion over whether and how to act. The existence of review is important; the breadth of retained discretion shows why mere publication does not eliminate governance problems.

For a number registry, the distinction is crucial. Correction of inaccurate contact data is not the same as suspension of authentication services. Freezing a contested transfer is not the same as withdrawing a completed registration. Collection of unpaid fees is not the same as adjudicating entitlement. Each action needs its own trigger, evidence, duration, effect and review path.

An internal remedy is necessary but cannot validate itself

Network institutions often have specialised knowledge that courts and general regulators lack. Internal review can correct a factual error quickly, interpret technical standards consistently, and protect confidential security evidence. It is rational to require a entity to use this route before escalating many disputes.

But a remedy is not independent simply because a different employee reads the file. The reviewer should be institutionally separate from the original investigator, disclose conflicts of interest, consider the same evidentiary record plus permitted new material, and issue reasoning against published standards. Time limits must give the entity a realistic opportunity to respond. Fees for review should not make the remedy illusory for smaller members. Urgent protective measures should be reviewed promptly even if full examination takes longer.

There must also be an external boundary. A system's declaration that an internal decision is final may mean it is final within that private process; it cannot extinguish legal rights or the jurisdiction of a competent court. Competition authorities, financial regulators and courts remain available under law. Their role is especially important when a dispute concerns the fairness of the rules themselves rather than their application to a single transaction.

Number registries should publish the same distinction. Operational review, independent community review, contractual arbitration, and judicial challenge are not interchangeable. A entity needs to know which decision each forum can change, whether the challenged measure is suspended, and how the registry will implement an adverse decision without compromising record integrity.

Reasoning transforms discretion into a contestable decision

A shared rulebook can still contain standards such as excessive risk, reputational harm, security concern or behaviour contrary to network interest. Some openness in language is inevitable because fraud and operational threats change. The institution's duty is to make its application contestable.

A reasoned decision identifies the rule, the material facts, the accepted evidence, significant counterarguments, the conclusions drawn, and the remedy chosen. It explains why a less intrusive measure would not meet the risk. Confidential information can be summarised or handled under restricted review, but secrecy should not conceal the entire case. A entity cannot correct its conduct or challenge an error if it receives only an outcome.

Reasoning also improves the institution. Similar cases can be compared. Reviewers can detect drift. Entities can adjust controls. Public summaries can reveal interpretation without exposing customer or security information. The collected decisions become a practice that constrains arbitrary change more effectively than a general fairness promise.

For number registries, the reasoning obligation should extend to denied allocations, rejected transfers, service restrictions, registration corrections, and membership sanctions. Some facts will be private. The guiding principle need not be. A registry can state that evidence of corporate authority failed a published test, describe what was missing, and indicate the path to remedy without disclosing personal documents.

Competition law asks whether coordination exceeded the necessary level

Payment systems require horizontal coordination between institutions that would otherwise compete. Shared acceptance, message formats and risk rules can increase output and reduce transaction costs. The same coordination can restrict price competition, exclude newcomers, or protect a network's adjacent services. Competition law examines both sides.

The most useful question is counterfactual: what would happen if the challenged rule were absent or narrower? If authentication fragmented, fraud increased and cross-acceptance failed, a uniform requirement might be justified. If merchants could still identify cards and complete transactions while receiving cost information and steering customers, a restriction on that choice is harder to defend. If independent processors can meet the same technical standard, tying system access to one's own processing appears less necessary.

ThePayment Systems Regulator of the United Kingdomreported in 2025 that Mastercard and Visa faced ineffective competitive constraints on the acquiring side of the market and did not provide acquirers with sufficiently clear and detailed fee information. The finding is a reminder that rivalry between two large networks does not discipline every fee or service. Competition must be assessed at the actual decision level.

Number registries require an even more careful counterfactual because uniqueness restricts direct duplication. Two services cannot plausibly register the same number under different holders and call the result competition. Yet competition can exist in authentication, customer service, transfer facilitation, confirmation, and organisational affiliation if a coordinated registration state is maintained. The impossibility of competing truths does not justify a monopoly over all surrounding services.

Price transparency is governance, not a quarrel over a price

A entity cannot judge fairness if it cannot see what it is buying. Card pricing can combine interchange fees, scheme fees, processing fees and optional service fees across many transaction categories. Complexity can reflect genuine differences, but it can also obscure price increases, make comparison expensive, and weaken merchant bargaining power.

European separation rules require that scheme and processing prices not be presented as a single bundled amount. Acquirers must provide merchants with specific information about merchant service charges, interchange fees, and scheme fees, unless the merchant requests a different presentation. The UK review went further, examining whether fee information was clear enough for acquirers and merchants to understand the charges and the reasons for changes.

Transparency does not mean every entity pays the same amount. Volume, risk and service level can justify differences. It means that price categories are attributable to defined functions; discounts and exceptions follow published principles; compulsory and optional services are distinguishable; and the institution can explain a change in terms of cost, risk, investment or another stated objective.

Number registries should disclose the same structure. Membership fees, per-resource fees, transfer fees, extended confirmation and optional support should not merge into an unexplained levy. Cross-subsidisation can be a legitimate policy choice, but it should be visible and approved through the institution's accountable budget process.

Number registries share the rule dependence, not the payment economics

RFC 7020describes the Internet Numbers Registry System as the structure used to distribute globally unique IP address space and autonomous system numbers. Its objectives include managing finite pools, supporting hierarchical allocation, and maintaining accurate registration to ensure uniqueness. Regional Internet Registries administer policies in continental-scale service regions, while local registries and operators exercise other functions.

This structure resembles card payment systems in limited but important respects. Both coordinate many legally separate entities. Both rely on authenticated instructions and accurate shared records. Both need shared semantics across boundaries. Both can impose significant costs through admission, delay, suspension, or correction decisions. Both become more valuable as more others rely on their output, increasing the power of the institution that maintains the shared rules.

The differences are equally critical. Number registration does not authorise retail payment or settle money. An IP prefix is not a payment account. Routing announcements are made by networks under local policy and can diverge from the registry. Number resources are globally unique and, in the case of IPv4, constrained by a finite address space. Registry regions are administrative structures, not merchant markets. There is no ordinary consumer choosing a registry at a checkout.

The comparison therefore supports standards for institutional behaviour, not the adoption of interchange fee caps, chargeback rules, or financial licences. Number registries need their own legitimacy based on their technical function, community authority, contracts, applicable law, and operational performance.

The registry rulebook should start with a map of powers

Payment governance becomes understandable when scheme, issuer, acquirer, processor, merchant and regulator are separated. Number governance needs an equally concrete map. The policy community sets allocation and transfer rules through its accepted processes. The registry implements those rules, maintains accounts and registration data, verifies eligibility, provides defined services, and records changes. Members approve corporate affairs to the extent the bylaws give them that power. Courts and public authorities act under external law. Networks decide routing.

Every high-impact rule should state which of these capacities it supports. A registry cannot turn a corporate membership vote into a technical policy if the two have separate processes. A community consensus cannot authorise conduct prohibited by law. A court order should be implemented according to its scope, not expanded into a general institutional preference. An operational emergency power should not be used to settle a commercial dispute.

This map also reveals conflicts. If the same executive function proposes a rule, interprets it, investigates a breach, imposes a sanction and decides the appeal, formal compliance may conceal concentrated discretion. Separation does not have to replicate a state judiciary. It can use independent reviewers, member-elected oversight, public reasoning, conflict rules and external remedies proportional to the decision.

The strongest rulebook is not the longest. It is the one that makes authority traceable from purpose to action to review.

Access should be open to capability, not protected status

Participation in a registry may require a genuine operational or administrative relationship. The institution may need a contracting entity, verified representatives, fees, technical contacts, and compliance with data obligations. Scarcity policy may limit who receives new resources. Transfer policy may require proof from both sides. These are substantial controls, not mere barriers.

The lesson from card payment systems is to frame each condition in capability terms where possible. Can the applicant authenticate instructions? Can it maintain accurate contacts? Can it respond to abuse and security inquiries? Can it meet applicable policies and financial commitments? Can it maintain continuity if a service provider fails? A familiar organisational label may correlate with these capabilities but should not replace their assessment.

Direct and indirect participation can coexist. Payment institutions can access a network through a sponsor. Smaller network operators can obtain resources through local or upstream registries. Indirect access can reduce costs but also gives the sponsor power over access and portability. The shared institution should monitor whether sponsorship conditions create undue lock-in or obscure the end-user's registered position.

Access decisions need published time frames and reasoning. Slow, unpredictable review can exclude as effectively as a formal ban. Data on acceptance, rejection, correction requests and elapsed time should be reported by case category and region, while protecting confidentiality. The institution can then test whether apparently neutral standards produce systematic disadvantage.

Portability must preserve one truth while enabling service choice

Competition in payments often depends on the ability of merchants, issuers or acquirers to change provider without losing access to the wider acceptance network. Co-badging, processor choice and merchant steering weaken unnecessary dependencies on one commercial route. The shared scheme rules remain, but the surrounding services can change.

Number services face a stricter uniqueness constraint. A holder cannot resolve dissatisfaction by asking two unrelated services to claim conflicting registrations for the same prefix. That would destroy the record value that competition is meant to protect. Portability must therefore change the service relationship while maintaining a coordinated holder state and attributable history.

A credible portability design would define eligibility, authentication, pending status, synchronization, finality, and correction. The previous service should not be able to prevent the move for an unrelated commercial reason. The receiving service should accept the same minimum evidence under equivalent rules. Any dispute should be visible and narrow. Associated routing security and reverse DNS services should migrate through an orderly handover rather than being treated as proof of ownership.

Here the payment analogy ends and number-specific engineering begins. A card payment entity can route transactions through competing networks in some situations. A globally unique prefix cannot support competing current holders. Service competition is only possible around a disciplined common state.

Member votes are a safeguard, not the entire legitimacy test

Many number registries are member organisations with elected boards, open meetings or community processes for policy development. These arrangements are important. They give operators influence over budgets, directors and rules. They can reveal institutional knowledge that a distant state regulator would lack.

But payment networks show why entity governance can underrepresent outsiders. System members may not share the interests of merchants, consumers, processors, or newcomers. Registry members may not represent every end-user, legacy holder, security researcher, downstream customer, or network affected by the record. Large members can participate more consistently than small ones. A vote can authorise a policy while its application remains opaque.

Institutional legitimacy therefore has multiple cumulative sources: clear purpose, lawful authority, inclusive rule-making, objective implementation, reasoned decisions, review, transparency, and measurable performance. No single source excuses weaknesses in the others. A community vote does not cure discriminatory case handling. A technically accurate record does not cure arbitrary suspension. A judicial remedy does not excuse the absence of a timely internal correction path.

Card payment systems are useful precisely because their private rules are not asked to validate themselves. Their entities, users, regulators, competitors and courts all supply different checks. Number institutions should embrace the same plurality while protecting the technical coherence of the registry.

Remedies should be tailored to the decision challenged

A single review body cannot sensibly decide every number dispute. A rejected policy proposal raises questions about community decision-making process. A denied allocation asks whether published criteria were applied to evidence. A transfer dispute may involve corporate authority or contract. A service restriction may involve security facts. A member election belongs to corporate governance. A court order raises questions of legal scope and jurisdiction.

The first design step is classification. The notification should identify the decision, the authority, the effective time, the immediate consequence, and the available forum. The review panel should be competent for that category and have no material conflict of interest. The rules should state whether review suspends the decision. Security conditions may continue during urgent review, while an irreversible transfer or termination may warrant suspension unless delay creates demonstrable risk.

RIPE NCC's Conflict Resolution Arrangementsillustrate a specialised path for certain service and registration disputes with impartiality requirements and the possibility of judicial challenge under applicable law.ARIN's Policy Processincludes petitions for procedural outcomes. These examples are not identical, and neither should be described as a universal court of appeal. Their value lies in assigning a path to a defined institutional act.

A mature registry publishes anonymised outcomes, tracks reversal rates, and examines whether the same official repeatedly generates avoidable complaints. Review is not only a benefit to the complainant. It is a feedback mechanism for first-instance administrative quality.

External oversight should constrain power without operating the registry

Public oversight is most effective when it targets institutional risk rather than taking over technical administration. Competition authorities can examine exclusion, bundling and discriminatory access. Data protection authorities can regulate personal data. Courts can decide contract, corporate authority and lawful orders. Financial or sanctions authorities can regulate conduct within their mandates. None needs to choose prefix lengths or maintain routing contacts.

The payment experience illustrates this layered approach. The European Union did not replace card payment systems when it capped certain interchange fees, protected merchant choice, required separation, and limited discrimination. The Australian central bank did not become a card issuer when it imposed access regimes. The United States did not write every transaction rule when antitrust enforcement opened merchant steering. Public law changed the boundary of private discretion while preserving shared operational standards.

For number registries, oversight should likewise preserve technical competence and global coordination. Broad national orders that fragment registration can harm uniqueness. Equally, an institution cannot cite global coordination to resist all legal accountability. The right answer is a precise interface: disclosure of the action, the legal basis, the affected record, the review path and the implementation method.

Institutional independence is not freedom from law. It is the ability to exercise a limited function without capture, combined with accountability for how that ability is used.

Five hard cases test whether the rulebook is disciplined

The first case is a technically capable newcomer that does not possess the established legal form. A disciplined institution identifies the actual settlement or registry risk and permits equivalent safeguards where law allows. A protective institution merely repeats the category requirement.

The second is a tied service. If the rulemaker's processing, verification or security product receives faster certification, lower fees, or mandatory status, separation has failed. The institution should publish comparable interfaces and decisions.

The third is an emergency suspension. The initial restriction may be based on limited evidence, but it needs a narrow effect, a named reviewer, a short review period, and a restoration plan. Emergency language cannot become unlimited punishment.

The fourth is a rule change that disproportionately burdens small entities. Formal notice is not enough. The institution should examine alternatives, transition assistance and staged compliance while maintaining the objective standard.

The fifth is an adverse decision affirmed internally under a clause declaring it final. The entity must still be informed what legal, contractual or judicial rights survive. Private finality can close an internal review; it cannot extinguish external law.

Applied to number registries, these cases reveal more about legitimacy than a general statement of bottom-up governance. They ask whether power is constrained at the moment it affects an operator.

A public scoreboard can turn principles into evidence

A registry that applies scheme rule discipline should report more than uptime and member counts. Access metrics should include complete applications, correction requests, approvals, rejections and median decision time by category. Consistency metrics should compare documentation requirements and outcomes for materially similar cases. Change metrics should show notice periods, emergency actions, and transition exceptions.

Enforcement metrics should distinguish technical rejection, protective measures, remediation, financial consequences and termination. Review metrics should show appeals lodged, decisions changed, average duration, and whether the original measure remained in effect. Service separation metrics should disclose mandatory and optional services, use by affiliates, certification times and attributable prices. Portability metrics should show completed moves, failed synchronisation, and unresolved conflicting states.

Qualitative publication is as important as quantities. Anonymised decisions can explain how open standards were interpreted. Independent audits can test selective evidence. Entity surveys can reveal whether fear of retaliation suppresses complaints. Competition reviews can examine whether adjacent providers face equivalent technical conditions.

No scoreboard proves legitimacy by itself. Metrics can be gamed, and rare high-impact cases can disappear in averages. Their value lies in making institutional claims falsifiable. A network that says access is non-discriminatory should be able to show patterns consistent with that claim and explain the exceptions.

Conclusion: Private coordination deserves authority through restraint

Card payment systems demonstrate that private rules can coordinate a global system of exceptional scale. They also show why interoperability cannot be the final answer to a governance question. The same rulebook that enables strangers to transact can exclude a newcomer, tie a service, obscure a fee, or impose a sanction. Scale magnifies both benefit and danger.

The durable arrangement is neither full public operation nor unchallengeable private contract. It is a limited institution surrounded by discipline. Access conditions address demonstrable risks. Comparable entities receive comparable treatment. Rule changes respect dependencies. Enforcement names its purpose and provides reasoning. Remedies have genuine separation. Courts, regulators and competition authorities preserve external boundaries. Competing services can compete where a common state does not require exclusivity.

Number registries should adopt this discipline without pretending to be payment systems. Their authority derives from globally unique registration, technical history, accepted policies, organisational commitments, applicable law and reliable service. Their task is not to move money or regulate commerce. It is to maintain a coherent administrative record while respecting the operators that depend on it.

Private network governance is legitimate when its rules enable coordination and its constraints make power contestable. A shared rule can bind a global system. It deserves trust only if the institution that writes and enforces it is also bound.

Sources