Summary
- AFRINIC's published minutes show a board that had formal audit machinery and discussed internal control, organisational health and internal-audit capacity before the address scandal was publicly disclosed, but formal scope did not automatically produce timely assurance over Registration Services.
- The public knowledge timeline sharpened in 2019: a later AFRINIC report dates suspicious activity to about March; secondary reporting says the former chief executive informed the board in April; the board approved a fraud and corruption policy in May; July brought an externally assisted investigation; and August minutes explicitly record debate over suspicious IP allocation.
- The August 23 minutes are the decisive pre-disclosure artifact. They record an internal-auditor report due by the end of September, urgency, external technical assistance and Audit Committee follow-up, but they do not publicly record immediate access containment, evidence-preservation decisions, a block-level scope or a member-notification rule.
- Silence in minutes is not proof of inaction. AFRINIC used redactions, executive sessions, short versions and delayed approvals. Accountability therefore requires the underlying papers, decision log, privileged-access actions and closure evidence, not an accusation built from omitted prose.
- Directors should be judged through a knowledge-action clock: what credible information reached them, what risk classification followed, how quickly they ordered independent inquiry and containment, what the Audit Committee verified, and how they protected registry continuity while claims remained unresolved.
Minutes are evidence of governance, not governance itself
Board minutes are unusually seductive documents. They present dates, attendees, agenda items, resolutions and action owners. Their formal tone makes the past look settled. In a scandal, readers scan them for the moment a director should have known, the sentence that proves neglect, or the omission that suggests concealment. This can produce a neat indictment and a poor analysis.
Minutes are a selected record. They may summarise hours of discussion in a line. Legal advice, personnel matters and investigations may move into executive session or be redacted. Drafts may be approved months after the meeting. A "short version" may exclude supporting papers. The date on which a meeting occurred, the date on which its minutes were approved and the date on which the public could read them may differ. An absence from the public text cannot establish that no private discussion or action occurred.
The opposite mistake is to treat incompleteness as immunity. A board that chooses summary minutes must still preserve a decision record sufficient to show that it discharged oversight. Confidentiality can justify withholding names, evidence and tactical detail. It does not remove the need to record the risk considered, the decision taken, the responsible owner, the deadline and the later verification. If none of that can be produced even under appropriate review, the problem is not public transparency alone. The institution cannot prove what it did.
AFRINIC's minutes should therefore be read in layers. The first layer is what the board publicly represented at the time. The second is what later AFRINIC statements say the board knew and did. The third is what investigative reporting adds, with attribution and caution. Where the layers conflict, the task is to identify the missing primary record rather than force certainty.
This approach changes the central question. It is not whether a particular meeting contains the word fraud. It is whether the board's control system converted increasingly specific warnings into inquiry, containment, independent assurance, communication and durable repair. Responsibility lies in the intervals between those acts.
The record before 2019 was audit-heavy and operationally thin
AFRINIC did not enter 2019 without an Audit Committee. Its board archive from 2015 records intense concern about financial statements, audit quality and the possibility that deeper financial analysis could expose maladministration. The board expanded the Audit Committee, negotiated with external auditors and resolved that minutes should be published within seven days of approval. Those were genuine accountability measures. They also reveal where assurance attention was concentrated: financial reporting and corporate regularity.
A number registry's decisive operational asset is different. It is the integrity of the authority record connecting available inventory or historical custodianship to the organisation shown in WHOIS. Financial accounts can be accurate while that authority record is compromised. Address space is not conventional stock owned and sold by the registry, so an unsupported change may not produce an obvious accounting entry. An audit culture organised around the financial calendar can miss the institution's largest legitimacy risk.
By 2017, AFRINIC's annual report described a broader remit. The Audit Committee was said to review internal financial control, risk management, internal audit and control, information systems and technology governance. Published minutes from April 2017 include a director asking whether an information-technology audit had been conducted. Minutes from May say the committee had submitted a lengthy report in the prior meeting and had not received board comments; the chair asked directors to read it, while the Finance Committee had noted points and acted on some.
The public text does not establish what the long report covered or whether it addressed registry privileges.
That episode illustrates a recurring governance distinction. Receiving a report is not reviewing it. Reviewing it is not assigning remediation. Assigning remediation is not verifying closure. Minutes that say a committee "reported" or the board "took note" provide evidence of transmission, not outcome. For a high-risk operational finding, the record should show severity, owner, deadline and closure test even if details remain confidential.
The August 2018 face-to-face minutes make capacity concerns more explicit. The Audit Committee discussed terms for recruiting an internal auditor, with recruitment proposed for the final quarter of 2018. A director suggested an audit of the performance of the organisation as a whole. The board approved an amended committee charter. Elsewhere in the meeting, directors requested quarterly management reporting, debated organisational health and emphasised a consolidated business-continuity plan.
The same minutes contain an "Update on Investigation" and actions to develop a whistleblower mechanism and an organisational policy index. The subject was associated with an earlier staff and governance controversy in the public record, not identified in these minutes as suspicious number-resource allocation. It would be irresponsible to collapse every AFRINIC investigation into the later address case. Its relevance is institutional: by August 2018, directors had already recognised the need for stronger internal control and a protected reporting route.
The pre-2019 picture is thus neither complacency nor assurance. The board had committees, charters, reports and action items. It was still building internal-audit capacity and basic control infrastructure while managing repeated governance strains. That condition should have elevated, not reduced, scrutiny of the registry's core operations.
A charter can promise more than a committee can deliver
AFRINIC's January 2019 Audit Committee charter was broad. It covered the effectiveness of internal control and audit, risk management, information systems and technology governance. It authorised direct communication with the internal auditor. It required the committee to review the annual plan, receive periodic results, monitor management's response and ensure the auditor had resources and access. It also referred to safeguarding assets against unauthorised use or disposal and supervising investigations into employee fraud, misconduct or conflicts of interest.
On paper, that remit was capable of reaching the address-allocation problem. It did not confine the committee to financial statements. It gave the committee authority to ask whether registry changes were authorised, whether staff privileges were excessive, whether conflicts existed, and whether management closed findings. The board could not reasonably say that WHOIS integrity was someone else's category.
Yet a broad charter creates its own danger: apparent coverage without practical capacity. A committee meeting at least twice a year around the financial reporting cycle may devote most of its time to accounts and external audit. Non-executive directors may lack detailed understanding of registration systems. A newly recruited internal auditor may face an enormous universe, limited staff and immature documentation. "Information systems" can become a line in a charter rather than a tested domain.
The board's duty was therefore to translate the charter into risk priorities. Which systems could change resource custodianship? Who had privileged access? How many large allocations or legacy changes bypassed ordinary interfaces? Could a public WHOIS entry be traced back to an approved request? Were discrepancies among membership records, internal inventory and public statistics reconciled? Had outside complaints been logged and escalated? These questions did not require directors to become hostmasters. They required them to define the assurance they needed.
The committee also needed independence in fact, not merely form. It should have controlled the internal auditor's scope and access, received reports without management filtering, and met privately with the auditor. If a senior operational employee was implicated, that employee and their line managers could not select files or explain every anomaly without corroboration. The charter anticipated direct access. The minutes needed to show that the power was used.
Formal responsibility therefore cannot be measured by whether the charter contained the right nouns. It must be measured by whether the committee commissioned the right tests before the risk matured, acted on findings, and told the full board what remained exposed.
April 2019: Registration Services finally enters the plan
Minutes covering board meetings on April 3, 10 and 17 record the 2019 internal-audit plan. The programme included corporate compliance, finance and accounting, Registration Services and the business-continuity plan. The Audit Committee had approved the plan; the board raised no objection and noted that approval belonged to the committee.
This is an important milestone. Registration Services was not hidden outside the audit universe. It was named. The institution had an internal auditor and a committee-approved plan. The question becomes what was scheduled, what fieldwork began, what records were tested and when findings reached decision-makers.
The minutes do not answer. "Registration Services" can describe a process review, a policy-compliance sample, an access-control examination or a full reconstruction of allocations. Those are not equivalent. A process review may confirm that staff know the written steps while missing direct changes outside them. A small random sample may miss a concentrated set of large exceptions. An access review may list users without testing what they did. The board needed a risk-based scope that reflected IPv4 scarcity, legacy-record fragility and insider privilege.
Timing is equally consequential. AFRINIC's later 2021 report says that in about March 2019 a Mauritian court order following an FBI application alerted the organisation to suspicious activity concerning several address blocks, and that a preliminary internal examination indicated possible unauthorised staff action with third parties. If that later chronology is accurate, the April audit-plan discussion occurred after the institution had a specific signal. The plan should then have shifted from routine annual coverage to incident-linked assurance.
MyBroadband later reported that former chief executive Alan Barrett informed the board in April about manipulation of WHOIS data. AFRINIC's December board update used a different formulation, saying the issue was first brought to the board after the former chief executive's resignation, when he said unauthorised changes might have occurred and internal inquiries were under way. The later accuracy report says the board commissioned an APNIC-assisted investigation in July. These sources do not produce a perfectly aligned date.
The discrepancy matters. If the board received specific notice in April, directors had more time and a different duty than if they first learned after Barrett's July departure. The primary evidence should be a dated communication, board paper, meeting note or incident log. Public accountability should not depend on reconstructing notice from later summaries with different wording.
An April staff-engagement discussion created a separate ad hoc committee to assess the state of AFRINIC operations and report by the end of the month. The 2019 annual report says it completed its work and was dissolved in May. Resolution 201905.483 accepted the report, and the board separately approved a fraud and corruption policy. The public record does not show that the ad hoc committee's organisational-health remit included suspicious IP allocations. It should not be retroactively treated as the fraud investigation without evidence.
What it does show is a board facing multiple signs of institutional strain at once: staff engagement, leadership transition, audit planning, continuity and, according to later accounts, suspicious resource activity. Fragmented committees can each address one symptom while no one owns the combined risk. The chair and full board were responsible for joining them.
May to July: policy, leadership change and independent inquiry
On May 31 the board approved a fraud and corruption policy proposed by the Audit Committee. The timing is notable because it followed the later-reported March and April signals. A policy can define prohibited conduct, reporting and investigation. It cannot contain an active threat by itself. The immediate questions were whether relevant staff acknowledged conflicts, whether access was reviewed, whether past transactions were preserved, and whether the investigation was independent.
Leadership was also changing. Barrett's departure was announced in July, and an interim chief executive took responsibility while the board searched for a replacement. Leadership transitions increase both risk and opportunity. Handover can expose unresolved issues, but authority can become diffuse. The board should specify who owns incident decisions, who can suspend access, who preserves evidence and who communicates with external experts.
AFRINIC's 2021 report says the board commissioned an investigation in July with APNIC's assistance. The December 2019 board update similarly says APNIC was selected to lead an independent assessment. Choosing a sister registry was sensible in principle: another RIR could understand allocation records, WHOIS controls and operational continuity in a way a general corporate investigator might not.
Independence requires more than an external name. The terms should define who selected the scope, whether investigators received complete logs and tickets, whether implicated staff could influence access, how evidence integrity was protected, what interim findings triggered containment, and whether the Audit Committee received reports directly. The final report's delivery date and the decision rights attached to preliminary findings matter as much as its eventual conclusions.
The public minutes available for these months do not provide that mandate. That may reflect confidentiality. It leaves members unable to judge whether the investigation began as a narrow review of several blocks or an institution-wide examination of allocation and legacy changes. Scope determines how quickly a board can know whether the apparent case is isolated.
The later audit eventually examined all IPv4 space administered by AFRINIC and checked membership and resource records across 2005-19. That comprehensive scope was appropriate for restoration. It arrived after the initial crisis. The board's 2019 task was to identify enough of the pattern quickly to contain it while preserving services.
August 23: the minutes become specific
The August 23, 2019 minutes are the clearest pre-disclosure board record. Under the Audit Committee report, they say the board debated suspicious allocation of IP. They record that the internal auditor would submit a report by the end of September. The interim chief executive stressed urgency and the need for outside technical expertise; the minutes add that, for example, ARIN had accepted a request to assist. Action items told the Audit Committee to follow the internal auditor's plan and prepare a report on a legacy registration agreement.
Later AFRINIC statements identify APNIC, not ARIN, as leading the independent assessment. The two statements may describe separate offers of assistance, an early option that changed, or loose minute drafting. They should not be silently harmonised. The investigation-engagement correspondence would settle which registry did what and when.
Several positive features are visible. The matter reached the full board, was connected to the Audit Committee and internal auditor, was labelled urgent, and prompted a search for external expertise. Legacy arrangements were recognised as a distinct issue. These are not trivial actions.
The minutes also expose unanswered questions. They do not state how many blocks or addresses were in scope. They do not identify whether the suspicion concerned pool allocations, legacy changes or both. They do not record an immediate privileged-access review, dual approval, account suspension, evidence hold, notification to potentially affected holders, or a deadline shorter than the end of September for preliminary containment advice. The absence does not prove those actions were not taken. It means the public minutes cannot demonstrate them.
The proposed report date deserves scrutiny. For a routine audit, five weeks may be brisk. For a credible insider threat to the authoritative registry, waiting until the end of September for a report could be too slow unless interim controls were already active. A sensible mandate would require immediate preservation and a rapid preliminary assessment, followed by a fuller report. Boards should distinguish the deadline for final analysis from the deadline for stopping further unauthorised change.
The meeting also created a Technical Committee to address infrastructure and other technical issues facing AFRINIC. Again, structure is not action. The important question is whether that committee had a defined role in the suspicious-allocation matter or whether the Audit Committee retained ownership. Dual ownership without a single incident lead can slow decisions.
One detail outside the fraud item illuminates the board's control capability. The same minutes carefully specified bank-signature combinations and named Internet-banking access roles after a leadership transition. Directors understood that financial authority required explicit revocation, grant, role and thresholds. Comparable precision should have been applied to the registry's privileged accounts: revoke former access, name permitted roles, require dual control for high-risk changes and define thresholds for board or executive review.
The contrast is not proof that registry access was ignored. It is a governance benchmark drawn from the board's own practice. What was explicit for money should have been at least as explicit for the authority to change scarce resource records.
September to December: investigation and disclosure move on different clocks
MyBroadband published its first large investigation on September 1. Public reporting expanded the audience and gave the board a new risk: members and affected organisations could now compare the allegations with AFRINIC's silence. The board had to balance investigation integrity, employee fairness, legal constraints and the membership's need to protect resources.
On September 26 AFRINIC publicly honoured long-serving staff, including Ernest Byaruhanga. The recognition does not establish what the interim chief executive or communications team knew. It does show that a public personnel process could continue while the board minutes had already recorded suspicious allocation and urgent investigation. A coordinated incident structure should decide whether public endorsements of people within scope are paused, not as punishment, but to avoid contradictory institutional signals.
The public record then accelerates. Deeper reporting in early December named Byaruhanga and connected historical records, companies and transactions. AFRINIC says APNIC submitted findings in December. The matter was reported to the Mauritian police on December 10. AFRINIC later said a disciplinary hearing took place on December 13 and management summarily dismissed Byaruhanga. The board issued its broad update on December 16.
That update said the board initiated investigations as soon as it learned of the matter, APNIC confirmed some allegations, and the chief executive was tasked with limiting access, preventing manipulation and suspending or revoking implicated or suspected parties' access. It also said the former chief executive had first told the board after his resignation. The statement is important because it assigns the board's own claimed knowledge point and describes containment.
It is also a narrative by the institution under scrutiny. "As soon as" is a conclusion, not a measurable interval. Members need dates: initial notice, triage, investigator appointment, evidence preservation, first access restriction, preliminary finding, board escalation, police referral and public notice. With those dates, the claim can be evaluated. Without them, speed is self-certified.
The public disclosure came after police referral and APNIC's findings, which may reflect legal caution. Yet some communication can precede a final finding. The registry could tell holders that it was examining suspicious records, ask them to verify contacts, increase change controls and explain how to report anomalies without naming an employee or prejudging a case. AFRINIC's later comprehensive audit adopted broad communication and verification. The question is whether an earlier bounded notice could have reduced exposure.
Communication has costs. Alerting a suspected insider can affect evidence; public statements can trigger opportunistic claims over dormant blocks; premature accusations can harm employees and counterparties. The board needed a documented disclosure threshold, not automatic transparency. That threshold should weigh the ability of members to protect themselves, the number and status of affected resources, continuing access, investigation secrecy and legal advice.
The knowledge-action clock
Board responsibility should be assessed through a clock with five hands. The first marks notice: when did a credible signal reach management, the chair, the Audit Committee and the full board? The second marks classification: when did the matter become an insider-risk incident rather than an ordinary allocation discrepancy? The third marks containment: when were evidence and privileged systems protected? The fourth marks escalation: when did independent investigators, police and affected holders enter the response? The fifth marks remediation: when did the board verify that controls and records were corrected?
Different evidence thresholds apply to each hand. A single anomaly may justify preservation and quiet review but not public accusation. Multiple unsupported changes linked by actor or method may justify dual control and external investigation. A credible finding of intentional misuse may justify suspension and police referral. A final resource correction may require holder-specific due process. The board did not need complete proof before every protective action.
This framework also prevents hindsight. Directors in March may not have known what AFRINIC concluded in 2021. They should be judged on the information available at each date and whether their response was proportionate. A later large finding cannot retroactively make an early ambiguous signal obvious. It can reveal that the institution's triage process was too weak to discover what the signal meant.
The clock must include management. The board oversees; executives operate. The chief executive or interim chief executive may have authority to restrict access, preserve logs and assign staff without waiting for a formal resolution. Directors become responsible when they fail to define authority, do not demand reporting, tolerate delay or accept assurances without evidence. Management becomes responsible when it withholds material facts, delays containment or fails to execute board decisions.
The Audit Committee occupies the bridge. It should receive the internal auditor's findings directly, test management's response and tell the board what remains unresolved. It cannot replace incident management, and the charter says it should not assume management functions. It can ensure that the people managing the incident are not also certifying its success.
What a sufficient board record would contain
A defensible confidential record for March-December 2019 would begin with a dated notice ledger. Each warning would identify the source, affected prefixes, alleged mechanism, credibility assessment and recipients. It would show when separate reports were linked and when the issue was elevated from a block dispute to a possible staff-enabled pattern.
The next section would record protective decisions. It would list preserved systems and custodians, copied logs, credential rotations, privilege changes, dual-approval requirements, monitoring rules and continuity arrangements. It would explain why full suspension was or was not ordered at each stage. Sensitive names could remain sealed while the decision and date remained reviewable.
The investigation mandate would identify scope, independence, access, reporting line and interim-report obligations. It would distinguish the internal auditor's role from the sister registry's technical work and the police enquiry. It would preserve disagreements over scope rather than flatten them into a single institutional conclusion.
The board pack would contain an address-weighted exposure table: pool blocks, legacy records, current status, current use, holder contact, legal dispute, suspected actor and risk of immediate change. It would not assume that routing proved entitlement. It would help directors decide where a lock protected the registry and where an abrupt action threatened innocent networks.
The communication paper would set thresholds for staff notice, member notice, public statement, law-enforcement referral and notification of named historical holders. It would record legal constraints without using legal advice as a blanket explanation for silence. Confidentiality and transparency are decisions to balance, not slogans.
Finally, the closure record would track every recommendation. A policy approved is not a control operating. A credential revoked is not a record restored. An audit completed is not a finding remediated. Directors should receive evidence that access reviews occurred, discrepancies were reconciled, affected files were adjudicated through appropriate processes and repeat tests found no similar unsupported changes.
If AFRINIC holds such records, the public minutes understate a stronger response. If it does not, the board's problem extends beyond disclosure: institutional memory is too weak to support accountability.
Membership was a principal, not an audience
AFRINIC's members were not merely readers waiting for a press statement. They financed the institution, elected directors through the applicable structures and relied on the registry's representation of number-resource custodianship. Some also possessed information the board did not: historical allocation papers, old contacts, mergers, current routing arrangements and attempts by third parties to assert control. A disclosure strategy that treated members only as a reputational audience would waste a distributed source of verification.
Member participation required design. A general alarm could invite speculative claims over dormant space. Naming suspected blocks too early could disrupt networks or compromise evidence. Silence, however, left genuine holders unable to check whether their contacts and maintainers had changed. The board could have used graduated notice: first contact holders through previously verified channels; then ask all members to review a secure statement of resources and authorised contacts; then publish aggregate categories and a protected anomaly-reporting route.
The response to a report should have been traceable. A member saying "this block is ours" is not proof, but neither is it noise. Staff should record the assertion, preserve supporting material, compare it with historical records and state whether the case is pending, rejected or escalated. Reports involving a staff member, repeated contact domain or common counterparty should be joined by assurance personnel outside the ordinary service queue.
Board minutes should record the policy for this engagement even if individual cases remain confidential. How many holders were contacted? How many replied? How many challenged a change? How old were unresolved cases? What address volume did they represent? These measures would let members judge progress without exposing evidence or prejudging title.
Membership accountability also means explaining the limits of board knowledge. A candid interim statement can say that the scope is uncertain, that an independent examination is under way, that specified controls have been tightened and that existing holders should verify records. Such a statement is stronger than a declaration that everything is contained, because it invites correction while preserving uncertainty.
The board's 2015 resolution to publish minutes reflected a similar principle: members need visibility into how authority is exercised. The 2019 crisis required that principle to reach operations. Elections and annual meetings are weak accountability devices if members learn of a threat to the registry record only after journalists name the alleged actor.
Continuity was part of containment, not a reason to delay it
Directors facing suspicious allocations had to protect two things at once: the integrity of the record and the continuity of registry services. Poorly designed containment can harm legitimate holders. Disabling a senior employee without transferred knowledge may delay urgent requests. Locking a disputed block can prevent a genuine organisation from correcting abuse contacts. Reversing WHOIS immediately can create a new false statement. Removing route-related entities or certificates can have effects beyond the office.
These risks argue for prepared containment, not continued exposure. The board had already emphasised a consolidated business-continuity plan in August 2018, and the April 2019 internal-audit plan included continuity. The suspicious-allocation response should have tested whether critical Registration Services duties had trained substitutes, whether privileged credentials could be rotated without outage, and whether high-risk changes could move to dual control while ordinary service continued.
A continuity plan for insider risk differs from a plan for fire or equipment failure. The threatened person may hold unique knowledge, understand monitoring and retain social authority over colleagues. Handover material cannot be accepted without independent verification. Recovery credentials must be outside the same reporting line. Logs must be copied to a location the subject cannot alter. Staff asked to take over work need a protected route to report inconsistencies.
Block-level remedies also need a continuity classification. A suspicious unallocated-pool change with no active legitimate dependency may be quarantined quickly. A legacy block used by a hospital, network operator or public institution may require a lock on administrative changes while routing and services remain stable. A block with competing commercial claimants may require notice and a neutral hold. The board should approve principles; qualified staff and counsel should apply them to evidence.
The minutes' silence on these details cannot establish that they were ignored. It identifies what the supporting papers should contain. If directors delayed access restrictions because one employee was operationally indispensable, that dependence was itself a material control finding. If they imposed restrictions successfully without service degradation, the evidence would show that containment and continuity were compatible.
Court risk reinforces the same conclusion. Once records have been relied upon by buyers, networks or historical holders, correction can generate injunctions and damages claims. A contemporaneous decision record showing preservation, notice, proportionality and review gives the institution a stronger position than an abrupt retrospective assertion. Governance discipline before litigation is part of continuity because it reduces the chance that a court must manage the registry's operations through emergency orders.
The board's responsibility was therefore not to choose between stopping suspected abuse and keeping AFRINIC running. It was to ensure that the institution could do both. A registry that can continue only while a suspect retains broad access has already suffered a continuity failure, even before any system goes offline.
A fair verdict is conditional but not empty
The public material does not support saying that AFRINIC's directors knew throughout 2015-18 that an employee was misappropriating addresses. It does show that they knew the organisation needed stronger audit capacity, internal control, whistleblowing and continuity arrangements. Those general concerns should have shaped risk-based oversight of Registration Services.
The record becomes more specific in 2019. The exact initial board-notice date remains inconsistent across later accounts. By August 23, however, there is no ambiguity in the public minutes: directors debated suspicious IP allocation, recognised urgency and sought reports and external expertise. From that point, their responsibility can be tested against concrete protective actions.
The minutes demonstrate inquiry. They do not publicly demonstrate the timing of containment. The December update describes containment instructions but does not date their first execution. The period between specific board knowledge and verified access restriction is therefore the central unresolved governance question.
The board also deserves credit for obtaining external registry expertise, approving a fraud policy, using the Audit Committee and ultimately referring the matter to police. Credit does not end the review. An investigation that confirms allegations after public reporting may still have begun too slowly, scoped too narrowly or lacked interim safeguards. Conversely, an investigation can be responsible even if disclosure waits, provided the institution contained risk and had a justified communication threshold.
The standard should be neither exoneration by committee nor condemnation by omission. It should be documentary: show the notice, decision, owner, deadline and verification for every material step. Where confidentiality remains necessary, an independent reviewer or membership-authorised body can inspect the full record and publish bounded findings.
The lesson written between the lines
AFRINIC's minutes before disclosure show an organisation building governance machinery while serious risks moved through its core function. Charters widened. An internal auditor was recruited. Registration Services entered the plan. A fraud policy was approved. An independent technical investigation began. The board eventually debated suspicious allocations explicitly.
The scandal exposes the distance between those institutional nouns and the verbs that matter. Did the auditor test? Did the committee escalate? Did management revoke? Did the board verify? Did members receive enough notice to protect their claims? Did remediation close the exact path that had failed?
Minutes can identify when those questions became unavoidable. They cannot answer all of them. That is why the proper demand is not a more flattering narrative or a more accusatory one. It is a complete knowledge-action timeline, supported by primary records and measured against the continuity obligations of a Regional Internet Registry.
A board need not predict every dishonest act. It must construct a system in which a warning about the registry's authoritative record cannot remain merely an agenda item. The moment suspicion became specific, the clock began. Accountability is the record of what happened before it ran out.
Sources and analytical boundaries
The analysis uses AFRINIC's published August 2018 board minutes, the January 2019 Audit Committee charter, the April 2019 board minutes, the August 23, 2019 board minutes and the board's December 16, 2019 update. Earlier board archives and later AFRINIC audit findings provide context but do not override the contemporaneous record.
The article does not assume public minutes reproduce every confidential discussion or action. It does not conflate AFRINIC's earlier staff investigation with the later address matter. It does not determine individual liability, the rightful custodian of any prefix or the lawfulness of a disputed transaction. Where AFRINIC's later accounts and media chronology differ on when the board first learned of suspicious changes, the difference is stated rather than resolved without primary evidence.

