Summary

  • A securities trade is not the same event as settlement. Between agreement and final book entry lie allocation, matching, validation, resource availability, settlement instructions and a defined point of irrevocability.
  • The European Settlement Finality Directive protects transfer orders and netting against later insolvency effects once they enter a designated system under its rules, and prevents entity revocation after the system's stated point.
  • Delivery versus payment does not require every technical action to be simultaneous. It requires the final settlement of one linked obligation to occur if and only if the other becomes final, so neither side bears full principal risk.
  • Failed settlement and final settlement require opposite treatment. Before commitment, an incomplete transaction can remain pending, be bilaterally cancelled or return to a clean prior state. After commitment, correction should occur through a new, attributable event rather than deletion or unilateral reversal.
  • An IPv4 finality rule should bind authenticated seller authority, buyer acceptance, registry recognition, any cross-registry reconciliation and payment release into one declared settlement condition, while leaving routing deployment and private legal claims in their proper institutions.
  • NRS can use finality as an advocacy discipline by publishing research on entity duties, failure states, default rules, correction powers and audit evidence. RIRs, authorised transfer services, arbitral bodies and courts retain responsibility for executing or enforcing finality.

A trade is a promise; settlement changes the authoritative state

Financial markets distinguish execution from settlement because agreement does not itself move the asset and cash to their final accounts. After a trade, parties allocate the transaction, confirm terms, match instructions, arrange securities and liquidity, submit to relevant infrastructures and wait for the settlement date. A trade can be valid while settlement fails. A settlement can be delayed without cancelling the underlying contractual obligation.

The distinction became more visible when the United States moved most broker-dealer transactions from T+2 to T+1 on 28 May 2024. The Securities and Exchange Commission did not say that trades suddenly occurred a day later. It shortened the standard interval between trade date and settlement and added requirements intended to improve same-day allocations, confirmations, affirmations and straight-through processing. The change recognized that time between agreement and completion contains credit, market, liquidity and operational risk.

IPv4 transactions need the same vocabulary. A signed sale agreement creates private obligations. Escrowed funds show that consideration may be available. A seller's request shows an instruction. Registry approval shows an institutional decision. Publication of a new record shows a state change. A route from the buyer shows operational use. These events can occur in different orders, and none should be allowed to impersonate all the others.

The point of settlement design is to define which combination completes the transfer for registry purposes. Until that point, parties know the transaction is pending and which obligations remain. At that point, the recognised registration changes once. After that point, the former state cannot return because one entity changed its mind or an institution reopened the file informally.

This is a narrower and more valuable use of the securities analogy than saying addresses are assets. It turns an ambiguous administrative sequence into a state transition on which contracts and operators can rely.

The 1998 directive was written against the danger of unwinding

The European Union's Settlement Finality Directive addressed a specific systemic problem. If insolvency law could retroactively unwind transfer orders or netting already processed in a payment or securities settlement system, one entity's failure could reopen obligations across the system. Other entities would discover that balances they treated as final were contingent after all.

Article 3 makes qualifying transfer orders and netting legally enforceable and binding on third parties even when insolvency proceedings open against a entity, provided the orders entered the system before the legally defined moment. It prevents ordinary rules for setting aside earlier transactions from unwinding protected netting. Article 5 says a transfer order may not be revoked by a entity or third party from the moment defined by the system's rules.

The directive does not impose one technical timestamp on every system. The moment of entry is defined by each designated system's rules, subject to governing law. That is a crucial design choice. Finality needs a common legal effect, but the infrastructure must specify exactly when its own state reaches the protected point.

The recitals preserve an equally important boundary. Fraud, technical error or another defect in the underlying transaction may still support a legal claim for recovery or restitution, provided the remedy does not unwind netting or revoke the transfer order inside the system. Finality protects the settled state. It does not declare every cause, representation or contract behind that state lawful.

For IPv4 transfers, the lesson is not to immunize fraud. It is to separate the integrity of the common record from the remedies available between parties. If a final record can be silently deleted whenever a later claim appears, nobody knows whether the state is final. If a final record can never be corrected under any process, fraud becomes entrenched. The answer is a new corrective event under a published authority, not retroactive disappearance.

Finality is the point at which risk changes hands

The CPMI-IOSCO Principles for Financial Market Infrastructures define settlement finality as a legally defined moment. Principle 8 requires clear and certain final settlement no later than the end of the value date and, where needed, intraday or in real time. The rules should define both when settlement is final and when a entity can no longer revoke an accepted but unsettled instruction.

This clarity serves more than bookkeeping. Before finality, a entity may face counterparty risk, replacement-cost risk and uncertainty about liquidity or delivery. After finality, account balances and exposures can be calculated on the settled state. In resolution or insolvency, administrators can identify which transactions completed and which remain claims.

An IPv4 transfer also redistributes risk at a definable moment. Before finality, the seller should remain the recognised holder and the buyer should know that deployment based on an expected transfer is premature. Escrow should not release merely because one reviewer said yes. Registry-controlled security and reverse-DNS services should not be handed over irreversibly while the transfer can still fail.

After finality, the buyer should be able to rely on recognition without fearing that the seller can revoke its instruction. The seller should be able to rely on being removed from future holder responsibility. An escrow provider should be able to release under an objective condition. A lender should know which party's interest is being financed. A second registration service should not continue presenting the seller as current.

Finality is therefore not a claim that all risk disappears. Market value can move. Courts can issue orders. Routes can fail. The point is that registration risk changes from "will this instruction complete?" to "what new event, if any, lawfully changes the completed state?" That change is what makes reliance possible.

A CSD is a book-entry institution with a bounded role

The securities comparison becomes useful only when the institution is described accurately. A central securities depository supports the integrity, safekeeping and transfer of securities, commonly in immobilised or dematerialised form. It maintains accounts and operates or supports a securities settlement system. It does not make every investment decision, set every market price or decide every dispute between beneficial owners.

Principle 11 of the CPMI-IOSCO standards requires a CSD to maintain securities in immobilised or dematerialised form for book-entry transfer and to minimise risks associated with safekeeping and transfer. In the European Union, Article 39 of the Central Securities Depositories Regulation requires each CSD-operated settlement system to define moments of entry and irrevocability, disclose the finality rules, pursue final transfers in real time or intraday and no later than the end of the actual settlement day, and settle cash transactions between direct entities on a delivery-versus-payment basis.

This is a strong infrastructure role, but its strength comes from bounded rules. Entities know what an account entry means. They know which system rules govern. Supervisors can examine legal certainty, settlement efficiency, operational resilience and entity default. The CSD cannot make finality credible through reputation alone.

An IPv4 registry is not a CSD. It does not settle regulated securities, hold central-bank money or inherit the same statutory protections. Yet it performs a comparable narrow function when a scarce resource changes recognised holder by book entry. The useful question is whether its rules state entry, irrevocability, failure and correction with anything like the same precision.

If the answer is no, calling the registry a trusted steward does not fill the gap. Trust is the result of a finality rule, not a replacement for one.

Delivery versus payment is conditionality, not a cinematic instant

DvP is often described as simultaneous exchange: the securities move as the money moves. The functional principle is slightly broader and more useful. Principle 12 says the final settlement of one linked obligation should occur if and only if the final settlement of the other occurs. The system must eliminate the risk that a seller irrevocably delivers the full asset but never receives the price, or that the buyer pays but never receives the asset.

The technical steps need not happen in the same microsecond. The CPMI-IOSCO explanation permits designs in which securities are blocked, payment settles in another system and delivery follows only after confirmation. What matters is that the legal, contractual and technical design keeps the final legs conditional and minimizes the interval in which blocked resources are exposed.

The European Central Bank's TARGET2-Securities platform provides a concrete implementation. Entities use securities accounts with connected CSDs and dedicated cash accounts with central banks. T2S matches settlement instructions and settles in central-bank money on a DvP basis. It also uses partial settlement, auto-collateralisation and optimisation to reduce failures.

An IPv4 transaction can apply the principle through conditional registry delivery and escrow release. The registry need not process the commercial payment itself. It can publish a signed commitment that the authenticated transfer will become final when a named escrow condition confirms funds, while the escrow agreement releases when the registry emits the final event. A neutral coordinator can ensure neither condition becomes irrevocable alone.

The system should not claim perfect atomicity if institutions communicate through emails and manual portals with no protected commit protocol. It should state the actual sequence, reserve a safe pending state and define recovery if one service is unavailable. Honest conditionality is safer than a marketing claim of simultaneity.

Failed settlement belongs before finality

The phrase "rollback" is dangerous unless the state being rolled back is identified. Before finality, a failed settlement attempt can return to the last final state. A matched instruction may remain pending because the buyer lacks funds, the seller lacks deliverable securities, a entity is unavailable or a required validation fails. The system can retry, partially settle under defined rules or cancel bilaterally. Because no new final state was committed, restoring the prior state is not a reversal of final settlement.

After finality, rollback has a different meaning. It would erase a state on which other entities have relied. The 1992 BIS report on delivery versus payment examined net settlement models in which a failed entity's transfers could be unwound and obligations recalculated. It warned that such unwinds could impose substantial liquidity pressure on other entities. Later finality standards seek to avoid treating completed settlement as provisional.

IPv4 transfer design should make this temporal boundary explicit. If authority evidence fails before commitment, the request returns to rejected or incomplete without changing the current holder. If buyer acceptance or funds confirmation expires, the pending reservation is released. If one RIR cannot complete its side of an inter-regional transfer, neither registry should publish a final contradictory holder state.

Once the final transfer event is emitted and reconciled, an allegation does not invoke "rollback" as an undefined emergency power. The system opens a correction case, preserves the completed event, records any temporary restraint and requires a competent decision. If correction is justified, a new event transfers or restores recognition with its own effective time and reason.

This distinction lets the system be reversible while it is uncertain and durable when it becomes final. Without it, every successful transfer remains an indefinitely revocable draft.

Matching is the underappreciated control

Securities systems do not rely on one party's narrative of the trade. Settlement instructions are matched on fields such as instrument, quantity, parties, accounts, price and date. A mismatch does not invite the infrastructure to guess which side is right. It remains an exception for the parties to resolve.

IPv4 transfers need a similarly strict match. The seller instruction and buyer acceptance should identify the exact prefix, transfer type, source and recipient legal entities, current and receiving registration services, consideration condition, intended effective time and treatment of any parent or child ranges. Corporate identifiers should be stable enough to distinguish a legal-name variation from a different entity.

Cross-registry transfers add another match. The source service confirms the authenticated release and current resource state. The receiving service confirms the recipient, applicable acceptance conditions and readiness to assume the record. Both should derive a common transaction identifier from the same canonical terms. If either service presents a different prefix or party, the transaction does not progress.

Matching reduces discretion because it turns ambiguity into a visible state. "Needs more information" should identify the unmatched field. A buyer should not discover after payment that the source registry processed a smaller range. A seller should not discover that the receiving service attached a different legal entity. An escrow agent should not interpret prose across two approval letters.

The record should preserve every submitted version and the final matched terms. Amendment before irrevocability consumes the earlier instruction and creates a new version accepted by both sides. There is no reason for an infrastructure handling exact numerical ranges to tolerate less precision than a securities system handling quantities and accounts.

Irrevocability must begin before parties can weaponize delay

Final settlement and instruction irrevocability are related but not identical. A system may accept an instruction before it finally settles. If a entity can revoke at any time during that interval, others cannot plan liquidity or delivery. Principle 8 therefore requires a defined point after which unilateral revocation is prohibited even for an accepted but unsettled instruction.

For IPv4 transfers, the seller should be able to withdraw during an early review period if the buyer has not accepted, no final consideration condition has been locked and no other party has relied. Once the transfer is matched, approved and committed to a scheduled settlement window, unilateral withdrawal should end. Bilateral cancellation can remain available before finality if it is authenticated by both parties and does not defeat a legal restraint or third-party right.

The registry also needs a limit. It should not revoke its own accepted commitment because a staff member changes interpretation after every published condition has been met. A narrowly defined integrity emergency can pause finality before completion, but it must identify evidence, scope, decision maker, expiry and rapid review. "Registry discretion" is not an emergency category.

After finality, neither seller, buyer nor registry can cancel the event. They can initiate a new transfer, correction, court-directed disposition or consensual reversal. The distinction may look formal, but it protects history. A new event shows that the first transfer occurred and was later changed; cancellation falsely says it never happened.

This is how finality and accountability coexist. The settled state remains stable, while later law and evidence can still produce a visible successor state.

Failure should create responsibility, not ambiguity

Modern securities regulation treats settlement failure as something to monitor and attribute. Article 7 of CSDR requires CSDs to monitor fails and report them. Its current penalty mechanism imposes daily cash penalties on entities that cause attributable failures after the intended settlement date until settlement or bilateral cancellation, with exceptions for causes not attributable to entities and specified circumstances. Persistent, systematic failure can lead to suspension procedures after an opportunity to make observations.

The point is not that every failure deserves punishment. The point is that the system distinguishes a market entity that did not deliver from infrastructure outage, insolvency and other causes. Responsibility is classified rather than dissolved into a generic delay.

IPv4 transfers frequently lack that clarity. A request can stall because the seller supplied incomplete authority, the buyer failed a stated condition, an RIR did not answer, two policies are incompatible, a portal failed, legal review expanded without a deadline, or an adjacent service could not prepare handover. These causes impose different obligations and should produce different metrics.

A finality regime should assign a clock and responsible actor to each state. The party causing an avoidable failure can bear documented incremental costs under the transfer agreement. A registration service that misses a commitment can refund fees, compensate covered loss or fund substitute completion. An external legal restraint pauses the affected act without being blamed on either commercial party. A system outage triggers continuity procedures rather than a moral judgment.

Attribution disciplines institutions as much as users. If delay is always described as applicant incompleteness, registry performance cannot be measured. If every denial is described as market risk, policy incompatibility remains hidden. Settlement statistics should expose where the process actually breaks.

Entity default rules make finality credible under stress

Finality is easiest when both parties perform and every system is available. Its value is revealed by default. Principle 13 requires effective, clearly defined entity-default rules that let a financial market infrastructure act quickly, contain loss and liquidity pressure, and continue meeting obligations. Key procedures should be public and tested with entities. CSDR Article 41 imposes similar duties on CSDs.

An IPv4 settlement rule needs its own smaller default map. What if the seller enters insolvency after instruction but before finality? What if the buyer becomes insolvent after funds are reserved? What if an escrow bank freezes payment? What if a registry loses access to its systems? What if the authorised employee leaves? What if a court order arrives between irrevocability and completion?

The answer cannot be improvised through whichever institution is most powerful that day. The rules should identify which pending states terminate, which survive, which require an insolvency officeholder, and how funds and records remain protected. A commitment made before insolvency may need legal advice specific to the governing jurisdiction; no technical standard can override that law. But the system can preserve evidence and prevent contradictory unilateral action while the question is decided.

The registration service itself must be treated as capable of operational default. A continuity mechanism should export pending and final events, authenticated evidence references, dispute states and signing authority to a qualified successor. Finality cannot depend on the continued health of one corporation that happens to maintain the current account.

Testing matters. A rule that has never been exercised across an unavailable registry, failed payment service and contested signatory is a statement of hope. Periodic simulations should show whether the last final state survives and whether a clean pending transaction can be completed or cancelled without duplication.

The IPv4 settlement unit must be defined before it can be final

Securities systems know the instrument, quantity, accounts and cash amount to which settlement applies. IPv4 transfers sometimes use an imprecise unit: "the block," "the resources" or "the account." That is limited public evidence when a larger prefix can be split and adjacent services follow different boundaries.

The settlement unit should include the exact prefix set and any required treatment of parent or child records. It should name the current registered organisation, recipient organisation, source and receiving services, transfer category, effective time and common event identifier. It should state whether the unit is indivisible or permits declared partial settlement.

Partial settlement can be useful. If a buyer acquires several independent prefixes and one carries a legal restraint, the clean prefixes need not fail. But partial settlement should never be invented after the fact. The contract and instructions should say which components can settle separately, how price is allocated, how escrow releases and whether splitting would create an operationally harmful route or RPKI structure.

The unit also needs an adjacent-service schedule. Which RPKI objects are expected to change? Which reverse-DNS delegations must move? Are IRR updates performed by the parties? These are not all part of registration finality, but a failure to name them can leave the buyer with a final record and no operational readiness.

The final event should distinguish what committed from what remains. "Registration settled" can be final even while a buyer has not announced a route. "Operational handover pending" can remain an honest separate state. Precision avoids both false completion and unlimited conditions.

Cross-RIR settlement needs one commit condition

An intra-registry transfer can update one authoritative service. An inter-RIR transfer requires source and recipient institutions to coordinate. If each treats its own update as final at a different time, a failure between them can produce a gap or two rival truths.

The source RIR may confirm release only after authenticating the holder and checking policy restrictions. The recipient RIR may confirm acceptance only after reviewing the buyer and its own conditions. The records then need a shared commit point: source status becomes transferred out if and only if recipient status becomes current. Both preserve the same effective time and transaction identifier.

Technical implementation can use prepared states. Each service signs a readiness message that is not yet public finality. A coordinator verifies both, locks the matched transaction and issues a commit message. Each registry applies the state change and returns a receipt. If one cannot prepare, neither commits. If one applies but loses connection before receipt, idempotent replay and reconciliation determine whether the event already committed rather than creating a second transfer.

The design does not require one global registry. It requires a common protocol for the narrow settlement event. Each institution can retain its legal form and service responsibilities while agreeing that one address range cannot have two current transfer states.

If the current RIRs cannot provide that coordination, the competent institutions could authorise a qualified reconciliation service through recognised agreements. NRS can advocate the design, convene affected members and publish evidence about its performance, but it should not operate or authorise the reconciliation layer. The coordinator's authority must come from entity agreement and the relevant registry framework.

Atomicity here means one logical commit across records, not one institution's monopoly.

Payment should be linked without making the registry a bank

Securities DvP often uses central-bank or commercial-bank money inside regulated settlement arrangements. Number registries are not payment institutions and should not become custodians of transaction funds merely to imitate a CSD.

The functional link can be achieved with escrow or another regulated payment provider. Before settlement, the provider confirms that funds are irrevocably available subject to the agreed registry event. The registry services confirm that the matched transfer is ready. A common settlement instruction then triggers the final registration event and the payment release under mutually dependent rules.

There remains a last-mile problem: no ordinary internet message makes acts in legally separate systems mathematically simultaneous. Contracts must allocate the residual risk. The escrow provider can commit to release on a verifiable signed registry receipt. The registry can commit that the receipt is emitted only after the new record is durable. If the receipt is emitted but the payment provider fails, the buyer may remain registered while the seller has a claim against escrow. If payment releases on a forged receipt, the payment provider bears responsibility under its verification duty.

These outcomes are not perfect DvP. They are better than vague sequencing because each failure has a responsible institution and remedy. Higher-value transfers may justify prefunded guarantees, insurance or a settlement agent that accepts principal risk. Routine transfers may use simpler escrow with transparent limits.

The essential prohibition is unilateral exposure by design. A seller should not lose final registration while payment remains freely revocable. A buyer should not release unconditional payment while registry completion remains subject to open-ended discretion.

Finality must not be confused with route activation

The temptation to make settlement wait for routing comes from a legitimate concern: the buyer wants usable addresses, not a decorative entry. Yet routing is a poor finality condition because independent networks control it.

RFC 7020 states that whether addresses are announced and how they are advertised are operational matters outside the Internet Numbers Registry System. BGP routes can change after settlement for ordinary engineering reasons. A buyer may acquire space for future deployment, keep it unannounced, use a mitigation provider, announce from several sites or change origins.

Finality can require operational readiness evidence without requiring global route observation. The buyer can identify an intended origin and confirm control of necessary accounts. The seller can remove stale ROAs at a coordinated time. Registry-controlled RPKI access and reverse-DNS delegation can be included in a handover plan. Upstream letters and IRR changes can be conditions if the parties choose.

But a route collector seeing the buyer is not proof that payment settled or corporate authority was valid. Conversely, the absence of a route does not make a final transfer defective. A registry should not reverse a completed change because the buyer has not yet announced.

The settlement event changes who is recognised in the registration system. Operational deployment follows through operator decisions and adjacent services. Keeping the boundary clear gives parties a stable point from which to perform the rest.

Fraud recovery should create a correcting transfer, not historical amnesia

The hardest objection to finality is a stolen credential. If a forged seller instruction produces a final transfer, why should the registry refuse to roll it back? Because "roll back" can mean two different things.

The system should absolutely restore the rightful state when a competent process establishes fraud. It should freeze further disposition quickly, preserve existing safe services where possible and prevent the fraudulent recipient from compounding the harm. But restoration should appear as a new correction event linked to the fraudulent event. The record should state which authority ordered correction, when it took effect and which interests or compensation claims remain.

Deleting the fraudulent transfer produces false history. It makes auditors unable to explain the period in which the wrong party was registered. It obscures who controlled RPKI or reverse DNS. It can cause an escrow provider or later buyer to rely on a fabricated continuity. It also lets the registry avoid showing that its controls failed.

The securities directive's boundary is instructive. Underlying claims for fraud or technical error can survive without revoking the protected transfer order inside the system. Remedies can operate through restitution, damages or a new disposition. The exact legal tools for IPv4 will vary by jurisdiction, but the recordkeeping principle is universal: correction succeeds the error; it does not pretend the error never entered the shared state.

This is also where compensation belongs. An innocent buyer that loses recognition after a forged chain may have a claim against the seller, insurer, escrow provider or registry depending on responsibility. Finality preserves the common history while law allocates the loss.

NRS should advocate the discipline, not wear the institutional costume

The Number Resource Society publicly argues for accurate registration, operator control and less concentrated registry authority. Settlement finality can turn those principles into a concrete standard for RIRs and authorised transfer services. It would betray them if NRS presented itself as a new central securities depository, settlement operator or source of exclusive global authority.

The constructive model is a rulebook for interoperable registration settlement. It defines entities, evidence, instruction formats, matching, prepared state, irrevocability, commit, failure, cancellation, correction and default. It publishes which parts are automated and where human judgment remains. It identifies governing law for each service and requires cross-service legal analysis before claiming insolvency protection.

NRS can commission conformance research, advocate a replaceable coordinator, compare public event-proof designs and represent members in debates about dispute and continuity services. Certification, coordination, authoritative event commitment and remedies must remain with RIRs, authorised technical operators, arbitral institutions or courts. NRS should not hold transaction funds or transform a membership position into universal title.

Entity responsibility must include every authorised coordinator. If it signs a false commit, loses a pending state or permits duplicate completion, a correction and liability rule should apply. NRS's responsibility is different: accurately source its research, disclose member interests and correct advocacy claims when evidence changes.

The strongest institutional lesson from securities markets is not centralisation. It is explicit allocation of authority and risk at every state. A thin common layer can provide that discipline while registration services remain plural and portable.

A practical state model has nine steps

First, proposed: one party opens a transaction naming exact resources and counterparties. No public registration change occurs.

Second, authenticated: the source service verifies the current holder's instruction and corporate authority under a published standard.

Third, matched: seller, buyer and affected services accept identical canonical terms. Amendments consume the earlier version.

Fourth, conditioned: payment assurance, legal restraints, recipient eligibility and declared technical prerequisites are either satisfied or identified as pending.

Fifth, prepared: every service required for authoritative registration signs readiness. The transaction obtains a settlement identifier and scheduled window.

Sixth, irrevocable: unilateral cancellation ends. A defined integrity emergency can pause, but only through a time-limited, reviewable act.

Seventh, committed: all authoritative records apply one effective holder change while the payment provider makes the matched release irrevocable under the common settlement condition. The paired event is durable, replay-safe and reconciled.

Eighth, discharged: the registration and payment services issue final receipts and complete any mechanical posting that remained after the irrevocable paired commitment. If a separate payment institution defaults on its committed release, its guarantee and liability rule apply rather than silently restoring the seller.

Ninth, completed with adjacent actions: RPKI, reverse DNS, IRR and operational contacts move according to the declared schedule. Their status is visible but does not reopen registration finality unless the settlement terms expressly made a registry-controlled action part of commit.

A rejected or expired transaction can leave from the first four states without changing the last final record. A prepared transaction that cannot commit enters a defined recovery state. A committed transaction can change only through another final event. This simple state grammar would remove much of the uncertainty that currently appears as discretion.

The analogy has strict limits

Securities settlement rests on legal and institutional foundations that number registration does not share. CSDs are authorised and supervised. Designated systems can receive statutory insolvency protection. Entities are usually regulated financial institutions. Settlement assets are commonly fungible, accounts are legally characterised, payment occurs through established money systems and prudential rules support default management.

IPv4 prefixes are not securities merely because they are scarce and transferred. Their legal character varies. RIRs are private institutions with different agreements and jurisdictions. Buyers and sellers range from global carriers to small businesses. There is no central bank leg for address settlement. Routing remains a decentralized operational activity. A court order affecting one party may not bind every service involved.

These differences rule out mechanical transplantation. NRS cannot cite the Settlement Finality Directive and thereby obtain its insolvency protections. An RIR cannot declare an arbitrary moment legally binding on third parties in every country. A common protocol cannot resolve conflicting property, sanctions or insolvency law. Capital requirements designed for financial infrastructures may be disproportionate to a thin registration service.

The analogy supplies design questions and a standard of precision. Where does an instruction enter? When can it be revoked? What conditions are linked? What happens if one entity fails? Which state is authoritative after commitment? Who may correct it? What claim survives without unwinding it? Who bears loss?

Answering those questions in number-resource terms would be a major advance. Pretending that securities law already answered them for IPv4 would be another category error.

Finality should be measured by reproducible reliance

A settlement regime should publish the share of complete instructions that reach each state, the time spent there and the attributable reason for failure. Median completion time is not enough. Long-tail cases, repeated evidence cycles, expired conditions and infrastructure outages reveal whether the finality promise works under stress.

The system should reconcile committed events across services and report gaps, duplicates, replay attempts and late acknowledgements. It should count how often a final event is later corrected, why, under whose authority and after how long. A higher correction rate may reveal weak authentication; a zero rate may reveal hidden deletion or inaccessible remedies.

Payment linkage should be tested through exceptions: registry committed but payment did not release; payment released without a valid commit; escrow timed out after irrevocability; a forged receipt was rejected. Each scenario should have a predefined loss bearer.

Operational continuity should be measured separately. Did registry-controlled RPKI and reverse-DNS services move on schedule? Did route observations show disruption? The data should never imply that the registry guarantees worldwide reachability, but it should reveal whether its own transition acts contributed to an outage.

Default exercises should test entity insolvency, service failure, credential compromise and conflicting legal orders. Results can be aggregated without exposing transaction details. Rule changes should show the evidence that prompted them and preserve transition periods for pending cases.

The ultimate measure is whether an unrelated third party can inspect the event and answer one question: which organisation was recognised at a specified time, and what valid event changed that state? If the answer depends on private emails or institutional memory, finality has not been achieved.

Conclusion: irreversible after commit, reversible through a new event

Securities settlement gives number-resource governance a precise way to think about irreversibility. Agreement is not settlement. Approval is not settlement. Payment alone is not settlement. A state becomes final when defined conditions have been met, the authoritative book entry has committed, linked obligations cannot leave one side exposed, and the system's rules prohibit unilateral revocation.

Before that point, failure should be clean. An unmatched, underfunded, unauthorised or legally restrained instruction remains pending, expires, is bilaterally cancelled or returns to the last final state. It should not leave payment released against no registration, a buyer recorded in one registry and a seller recorded in another, or security control stranded between parties.

After that point, the opposite principle applies. The transfer is durable. Seller insolvency does not automatically resurrect the old record. Staff reconsideration does not erase it. A later fraud finding, court order or consensual reversal can change the state through a new attributable event. History remains intact, and compensation or restitution allocates the resulting loss.

The design is demanding because IPv4 transfer joins institutions that do not share one law or technical platform. The answer is not to pretend that a single RIR already supplies global finality. It is to define the exact settlement unit, match both parties, coordinate source and recipient services, link registry commitment with payment assurance, publish failure states and make every exceptional power reviewable.

NRS can help by campaigning for interoperable and portable rules and publishing comparable evidence from the institutions that operate them. Its success should not be measured by transactions controlled—NRS should control none—but by whether its advocacy helps prevent indefinite provisional transfers, unsafe revocation and ambiguous rollback.

Settlement finality is an institutional design tool because it tells each actor when discretion ends. The buyer obtains a durable record. The seller obtains discharge. The registry obtains a bounded role. The payment provider obtains an objective release condition. Courts retain authority over legal claims without forcing the shared ledger to forget its history.

The rule can be stated in one sentence: an IPv4 registration change should become irreversible when authenticated, matched and conditioned instructions commit to one reconciled record; after that, it may be changed only by another valid event.

That is not securities law for the Internet. It is the discipline of finality adapted to a global number system that has operated for too long without naming the moment on which everyone is expected to rely.

Sources