Summary

  • Version 3.4 of the recommended RIR Governance Document retains Article 1.3: if common Implementation Procedures have not been adopted, each RIR has discretion over how it demonstrates compliance, and the absence of a procedure does not prevent enforcement.
  • The draft adds Article 1.4, requiring a decision by an entity to follow the procedures relevant to that entity, including any applicable challenge or appeal. A common implementation procedure and an entity’s decision procedure are different records.
  • The public package does not prove adoption, a live case, a breach, or that any RIR lacks procedures. It also does not publish an inventory of adopted common Implementation Procedures.
  • Before any use of the framework, operators need a portable receipt linking the exact provision, procedure state, interim method, evidence, deciding authority, reasons, remedy, review and correction lineage.

Two adjacent clauses create the real implementation test

The difficult sentence in the Version 3 RIR Governance Document is not difficult because it is vague. It is difficult because it is direct. Article 1.3 says that the RIRs and ICANN may jointly develop Implementation Procedures, that those procedures should define minimum requirements and be published, and that they cannot override the document. Then it provides for the period before such procedures exist. Each RIR may decide how it demonstrates compliance. The absence of a procedure does not prevent enforceability.

Read alone, that provision prevents an obvious failure. A substantive obligation cannot be made optional simply because the institutions have not completed a common manual for applying it. A late procedure cannot become a veto over the document it is supposed to implement.

The next clause prevents the opposite failure. Article 1.4 says a decision by an entity under the document must be made according to the procedures relevant to that entity, including any challenge or appeal mechanism that applies. The changes-and-rationale paper identifies this as an addition in Version 3.

These clauses do not cancel one another. They describe different layers. An Implementation Procedure is a common minimum arrangement that the RIRs and ICANN may develop together. A decision procedure belongs to the entity authorised to make a particular decision. The common layer may not yet have been adopted. The actor-specific layer still determines who can decide, what process applies, and whether the result can be challenged.

That distinction is the draft’s first operational test. If it is lost, one reader can use procedure absence to suspend a duty, while another can use the same absence to justify unrecorded discretion. The text supports neither shortcut.

The enforceability sentence is inherited, not new

The news is not that Version 3 invented enforcement before procedure. The frozen Version 2 text already carried the Article 1.3 formulation. The accurate change is the combination: Version 3 retains that rule, adds Article 1.4, and places both beside a more detailed set of audit, compliance-review and registry-status mechanisms.

That lineage matters. Calling Article 1.3 new would turn a continuing design choice into a fresh expansion of power. It would also hide the reason Article 1.4 is useful. The new clause does not create enforceability. It makes the decision path harder to treat as incidental.

The public stage matters just as much. ARIN’s 1 September announcement describes Version 3 as the recommended draft and says further input and updates will be coordinated by the NRO Executive Council. The NRO’s next-steps account says the ASO Address Council delivered its work to the NRO EC for consideration. The ICP-2 process page calls it the ASO AC recommended/final draft and says it was submitted for review and discussion with ICANN.

None of those records proves that Version 3 has been adopted, entered into force or been used against an RIR. No allegation or finding follows from publishing a draft. This is an analysis of the mechanism the text anticipates, not a report of an enforcement event.

A missing shared procedure is a state, not a blank

The public Version 3 package does not enumerate an inventory of adopted common Implementation Procedures. That does not establish that no relevant procedure exists anywhere. It means a reader of this package cannot move from Article 1.3 to a named procedure register and see, provision by provision, which common minimum has been adopted, which version is current and who owns its correction.

That missing link should not be represented by an empty cell. It has operational meaning. If a common procedure has not been adopted for a provision, Article 1.3 points to an interim state in which the RIR chooses how to demonstrate compliance. The identity of that method then matters. So do its version, owner, publication time and scope.

Suppose a later review disputes an outcome. The dispute could concern the substantive obligation. It could concern the local method selected in the common procedure’s absence. It could concern the evidence the actor saw, the authority of the deciding body, the notice given, the reasons published or an appeal that later changed the result. A record that stores only “compliant” or “non-compliant” destroys those distinctions.

The correct null is explicit: no common procedure identified in this record. That statement neither voids the obligation nor certifies the interim method. It explains which branch of the decision chain was used.

Enforcement is a sequence of decisions, not a switch

Version 3’s later clauses make that sequence visible. Article 4.2 describes periodic audits and compliance reviews. A compliance review has an initiating path, an allegedly breached provision, a materiality screen and a report. Other provisions assign other decisions. The relevant actor depends on the clause.

Those details are useful here only as a warning against one-word enforcement. Initiation is not a finding. A materiality determination is not a final remedy. A report is not necessarily an appeal. A temporary operational action is not a permanent status decision. A document can be enforceable before a shared procedure exists while each of those transitions still requires an attributable actor and a preserved reason.

This is also why “ICANN enforcement” is too broad a label. The document gives roles to different entities in different provisions. A usable receipt must name the authority for the particular decision. Institutional nouns are not interchangeable with decision rights.

The same discipline protects the institution being assessed. A transparent chain allows an RIR to show that a disputed outcome rested on a defined provision, a bounded evidence window and a procedure appropriate to the deciding entity. It also allows a correction to change the result without pretending that the earlier record never existed.

The minimum receipt has ten fields

A pre-procedure enforcement receipt need not become a central case-management platform. It can be a small portable record attached to each consequential decision.

First, preserve document identity: version, exact provision, public-text hash and claimed effective status. A recommended draft and an adopted rule are different inputs.

Second, preserve procedure state: the common Implementation Procedure’s identifier and version, or an explicit statement that none has been adopted or identified in the record.

Third, name the interim method: the method an RIR uses to demonstrate compliance while the common layer is absent, together with its owner, version and publication state.

Fourth, separate allegation from finding. Record the initiating actor, alleged facts, obligation in scope and any materiality threshold. Do not let a request for review become a public conclusion by database default.

Fifth, bound the evidence. Name sources, collection times, event times, hashes, access constraints and known missing material. Sensitive evidence can be restricted while its identity and integrity remain inspectable.

Sixth, identify decision authority. Record the entity, office or body that made this particular decision and the provision or rule conferring that role.

Seventh, record the procedure actually used: notice, response, meetings, recusals, quorum and relevant time limits. “Procedure available” is not evidence that it was followed.

Eighth, publish the reasoned outcome: finding or no-action result, reasons, remedy, effective time and bounded operational consequence.

Ninth, identify challenge and appeal: route, deadline, reviewing actor and state—or a reasoned statement that no route applies.

Tenth, never overwrite correction lineage. Link a reversal, withdrawal, supersession or factual correction to the exact decision it changes.

The receipt does not decide whether an institution complied. It lets different observers inspect the same chain without manufacturing a procedure after the fact.

A draft can be testable before it is binding

The immediate task is not enforcement. It is readiness. Before any final text is used, the institutions can publish a procedure inventory, map provisions to decision actors and challenge routes, and specify the interim compliance method for every explicit gap. That work is reversible. It can be corrected as the text changes.

The more dangerous option is to wait for a disputed case and reconstruct the chain retrospectively. By then, method versions may have changed, evidence windows may have closed, and participants may disagree about which procedure was relevant. A later narrative cannot reliably recover state that was never recorded.

Article 1.3 gives the system continuity: duties do not disappear while a common implementation layer is unfinished. Article 1.4 gives it a discipline: decisions still belong to procedures, actors and review paths. The durable object is the line between them.

Sources