Summary

  • The 2003-2005 transition moved inetnum and aut-num objects, autonomous system numbers and provider-independent space from the RIPE Database to the AFRINIC Database, terminated RIPE NCC Standard Service Agreements with African members, and placed responsibility for new reverse-DNS delegation squarely on the receiving registry.
  • No instrument located in this research makes registry data, reverse-DNS delegations or member records independently portable. Continuity appears only as a general expectation placed on the receiving registry, not as a trigger a third party can pull.
  • A 2019 audit made public around January 2021 quantified 2,371,584 misappropriated free-pool IPv4 addresses and a further 1,799,168 compromised legacy addresses - evidence that the ledger itself is the asset most exposed when the institution holding it is weak.
  • The test of continuity is operational rather than institutional: whether WHOIS and RDAP records stay queryable and complete, whether reverse delegations for transferred resources still resolve, whether members can obtain their own records, and whether any external party retains a fallback role. None of those was confirmed by the sources examined.

What moved, and what the paperwork actually says

AFRINIC was incorporated in Mauritius in 2004. The ICANN Board gave provisional approval on 30 September 2004, and in April 2005 ICANN recognised AFRINIC as the fifth Regional Internet Registry under the ICP-2 criteria. AFRINIC became the fifth member of the Number Resource Organization on 27 April 2005 (AFRINIC).

Before that, African network operators obtained addresses and autonomous system numbers from APNIC, ARIN and the RIPE NCC. The RIPE NCC handled IPv4 allocations and assignments for African countries north of the equator between October 2003 and April 2005, and stopped allocating to the African region in April 2005 (RIPE NCC).

The mechanics matter more than the dates. The RIPE NCC terminated Standard Service Agreements with African members, and AFRINIC concluded new contracts with those members. An NDA covering local internet registry information was signed by AFRINIC as part of the transition (RIPE NCC, AFRINIC).

The AFRINIC-ERX project transferred inetnum and aut-num objects, plus ASNs and provider-independent space, from the RIPE Database to the AFRINIC Database, and all referenced objects were transferred or copied. The project's own transfer documentation sets out that procedure (AFRINIC-ERX data transfer). AFRINIC also inherited registration records from ARIN and APNIC when its operations began (RIPE NCC, registry transition material, AFRINIC-ERX transfer documentation).

One detail deserves to be read twice. Where resources moved from the RIPE NCC to another registry, the associated DOMAIN objects in the RIPE Database were deleted, and responsibility for requesting new reverse-DNS delegation fell immediately on the receiving party (RIPE NCC). Reverse DNS is not administrative decoration. It is the mapping between a block of numbers and the names that operators put into filters, monitoring systems and abuse-handling workflows. Deleting the delegations and handing the re-application duty to the new registry is a clean legal outcome and a fragile operational one.

Read together, the record describes a transfer of custody rather than a transfer of risk. The data left one database and arrived in another. The relationship left one contract and arrived in another. Nothing in the described sequence created a second home for either.

Four control points, and who held each

Answering "who controlled prevention, detection, response and remedy" requires separating four functions that the word "registry" collapses into one.

Allocation authority. IANA, administered by ICANN, holds ultimate responsibility for allocated and unallocated IPv4, IPv6 and ASN space, and delegates blocks to regional registries under globally agreed policy (ICP-2).

Recognition authority. Under ICP-2, proposals to recognise or derecognise a regional internet registry originate from the NRO Executive Council after a majority vote, with ICANN retaining final authority (ICP-2, AFRINIC).

Registry operation. The day-to-day authority - editing objects, approving transfers, operating WHOIS and RDAP, holding the member relationship - sits with the recognised registry itself. After 2005 that was AFRINIC.

Continuity obligation. ICP-2 states that a registry must maintain continuity procedures, redundancies and record sharing so that another registry can perform its services if necessary, must keep auditable records, and sets out a derecognition and handoff process in which a derecognised registry must cooperate with ICANN and other registries to transfer operations to a designated successor or interim entity (ICP-2, AFRINIC).

That fourth point is where the design is weakest, and the weakness is structural rather than personal. The continuity duty is written as an obligation on the registry - keep procedures, keep records, cooperate in a handoff. It is not written as a right held by anyone else. There is no escrow the community can demand, no pre-agreed failover operator that can open the vault without the incumbent's cooperation, and no data-portability right that a member can enforce when the incumbent is a company in receivership.

Section 9 of the NRO Memorandum of Understanding establishes an Advisory Appeals Panel to hear complaints that a registry, the NRO or an NRO sub-organisation failed to follow documented global policy-development processes (ICP-2). That is a policy-process remedy. It is not a data-escrow mechanism, and it does not answer the question of who runs the registry on a Monday morning if the operator cannot.

What the record itself shows about exposure

The strongest evidence that the ledger is the vulnerable asset comes from AFRINIC's own audit. Commissioned in July 2019 and made public around January 2021, it found 2,371,584 IPv4 addresses from AFRINIC's free pool misappropriated. About 1,060,864 of those were reclaimed and placed in a 12-month quarantine; 1,310,720 linked to two organisations remained pending reclamation. A further 1,799,168 legacy IPv4 addresses were compromised: 394,496 consolidated, unsubstantiated changes to 467,968 reversed, and 936,704 still disputed. Remedial measures included additional verification layers (AFRINIC, audit coverage).

The figures are worth pausing on for what they say about design. Misappropriation was possible because a small number of authorised people could alter registry objects, and detection depended on later diligence rather than continuous external verification. The remedy was procedural - more verification layers - not architectural. The same property that made the misappropriation possible, a single authoritative copy under one institution's administrative control, is also what makes institutional failure a continuity event rather than a paper event.

Receivership, a suspended election, a declared company

The institutional side of this question stopped being hypothetical. AFRINIC and Cloud Innovation Ltd have litigated since about mid-2019. On 19 July 2022 the Supreme Court of Mauritius ruled in favour of Cloud Innovation, setting aside AFRINIC's preliminary objection. AFRINIC was placed in receivership, and on 15 October 2024 the Court of Civil Appeal heard an appeal concerning the receivership order. On 10 February 2025 the Bankruptcy Division terminated the initial Official Receiver's appointment, appointed Mr Gowtamsingh Dabee as receiver, and extended the board-election deadline to 25 April 2025 (AFRINIC, court coverage).

ICANN intervened in the governance of its own recognised registry. It wrote to the Court Appointed Receiver on 6 June 2025 demanding transparency and fairness in the board election, filed an application with the Supreme Court of Mauritius on 19 June 2025, obtained an order that the receiver issue a communique to members about an erroneous registration, and wrote again on 25 June 2025 warning of a possible compliance review over alleged fraudulent conduct. The election was suspended on 23 June 2025 and eventually held from 10 to 12 September 2025 (AFRINIC, court coverage).

On 25 July 2025 the President of Mauritius declared AFRINIC a declared company under section 230 of the Companies Act, following a winding-up petition by Cloud Innovation Ltd. The declaration suspends existing court cases involving AFRINIC and triggers a government-commissioned investigation into its affairs (AFRINIC, court coverage).

Three things should be kept separate here. An interim or procedural order is not a merits decision. A receivership is not a dissolution. And a declared-company investigation is not a finding of wrongdoing against any party. What the sequence does establish, without needing any finding of fault, is that a recognised registry can spend years under external control while remaining the sole custodian of the region's number records.

The continuity test that remains unrun

The useful conclusion is not that the handover was negligent. It is that the question was never operationalised. The observable test is concrete and can be run today by anyone with a terminal:

  • Do AFRINIC WHOIS and RDAP endpoints answer, and do they return complete objects for blocks transferred in the ERX project?
  • Do reverse-DNS delegations for transferred resources still resolve, and who actually holds the zones?
  • Can a member or legacy resource holder obtain a complete, dated extract of its own registration records?
  • Did the RIPE NCC retain any fallback role over the objects it transferred, and is that role written down anywhere?
  • Is there a named successor or interim operator that could perform registry services if the current one could not?

A finding that all five are in good order would falsify the concern that continuity depends on the incumbent institution. A finding that the first two hold and the last three cannot be answered from public documents would confirm it. On the sources examined here, none of the five was confirmed to be in good order.

What the record does not show

The gaps are as important as the findings, and they should be treated as open questions rather than conclusions. No 2004-2005 handover agreement between the RIPE NCC and AFRINIC was located. The AFRINIC-ERX data-transfer specification, including the precise treatment of DOMAIN objects, was not located in primary form. The termination terms of the Standard Service Agreements and any transition obligations owed to African members were not located. The scope of the transition NDA, and whether it restricted member disclosure, is unknown.

The current custodian of AFRINIC registry data, reverse-DNS delegations and member records during receivership and the declared-company process is not established. The full terms of the section 230 order were not located. Whether the RIPE NCC retained any fallback reverse-DNS or registry obligation is not established. Member-record portability under AFRINIC's registration service agreement and bylaws was not established. And the audit trail and chain of custody for the 2019 audit findings were not established.

The honest synthesis is narrower than a verdict and more useful than a complaint. A registry handover is a chain-of-custody problem wearing a governance costume. It can be executed flawlessly on the day and still leave the region exposed for decades, because the thing that needs to survive is not the institution's competence but the record's independence from it.