Summary
- Sanctions against a defined entité should not automatically cascade from a failed payment or restricted corporate benefit to deregistration, certificate revocation or route suppression. Each consequence requires its own legal basis, fact-finding and proportionality review.
- The five relevant layers are payment, corporate membership, authoritative registration, RPKI and routing. They have different users, dependencies, reversibility and third-party effects, so a single account status must not govern all five.
- The RIPE NCC transparency reports since 2022 show the practical difference: applicable sanctions can freeze registration changes without deleting resources or ending every existing relationship, while bank restrictions can impede invoicing even when the registry is not legally required to apply the foreign measure.
- Mismatches and unresolved ownership evidence are a major continuity risk. Temporary restrictions should be narrow, time-limited and reviewable, keeping clean resources and independent services while identity questions are resolved.
- RPKI requires particular restraint because certificate and repository actions can change how many independent networks classify routes. A financial restriction is not evidence that a route authorisation is false or that third-party traffic should become unreachable.
- Routing remains an operator decision determined by law, contract and risk. A number resource institution should not turn its sanctions screening into a global routing instruction, and transit providers should not treat the registry status as a substitute for their own legal analysis.
- A credible NRS model would maintain an auditable resource record, provide separate service entitlements and contracts, publish layer-specific decisions, support lawful exceptions, and measure both over- and under-enforcement through independent review.
Sanctions Become Fragmentation When Institutions Merge Different Powers
The usual sanctions discussion begins with a binary question: should an organisation continue to serve a listed customer or not? This framework is too coarse for Internet number resources. A registry relationship is not a single service. It can encompass invoicing, voting rights, support, allocation, transfer, public registration data, reverse domain delegation, routing registry entries, hosted certificate creation, repository publication and security notifications. A network may use some of these functions directly, while thousands of other organisations depend on the resulting public state.
Merging these functions creates a hidden escalation ladder. A payment processor rejects funds, so an invoice is marked unpaid. Non-payment leads to closure of a membership account. The closure removes portal access. The same account controls registration data and hosted RPKI. Certificates or signed entités expire. Networks using route origin validation then classify announcements differently. What began as a financial friction has acquired a routing consequence that the bank neither assessed nor intended.
The reverse error is also possible. An institution may describe everything as critical continuity and continue to provide new allocations, discretionary transfers or premium services to a listed entité despite a clear prohibition. Technical significance is not a blanket exception. The relevant distinction is between preserving established global uniqueness and granting a new economic benefit. Registration continuity may be necessary to prevent conflicting claims, while a new transfer may change control over a scarce resource.
Providing current security entités may protect third parties, while issuing a new authorisation at a customer's request may require separate analysis.
Service layer separation prevents both errors. It asks five questions in order. Can funds be lawfully moved? Can the legal person retain corporate rights in the institution? What must the authoritative resource record continue to say? What certificate and repository actions are necessary to keep routing statements correct? What, if anything, should network operators do with the actual routes? The answer may differ at each layer without contradiction.
This architecture also improves accountability. A registry can explain that it refused a transfer but kept the historical registration. A bank can explain that it refused a transaction without claiming to decide address rights. A certification authority can maintain a previously valid entité for a limited period while declining an unsupported change. A transit provider can make its own routing decision. Each actor remains responsible for the power it actually exercises.
Fragmentation is therefore not only the creation of separate national networks. It can occur through unchecked institutional coupling. When a sanctions alert silently disables multiple shared functions, the global network breaks through administrative cascade. The remedy is not to ignore the law. It is to prevent one decision at one level from becoming an unfounded command at all others.
The Post-2022 Record Shows That Payment, Registration and Use Already Diverge
The public record of the RIPE NCC provides the clearest sustained evidence. As an organisation based in the Netherlands, it states that it must comply with applicable EU sanctions. Its stated response is to freeze registration, not use: a sanctioned holder cannot acquire further resources or transfer existing ones, but resources are not deregistered and an existing standard service agreement is not terminated on that ground alone. This is already a form of layer separation.
The distinction did not eliminate difficulties. The RIPE NCC also reviews alerts related to the U.S. Office of Foreign Assets Control because Dutch banks take account of those lists, even though the registry itself is not required to apply U.S. sanctions to service. Banking practice therefore affects invoicing more broadly than the registry's direct legal duty would suggest. Iranian and Syrian members faced payment obstacles because banks were unwilling to process transactions, and the institution offered extensions rather than treating the blocked payment as evidence that the underlying resources should be removed.
The volume of reviews matters. The RIPE NCC transparency report for Q2 2026 recorded 2,110 screening alerts as of 7 April 2026. Of these, 1,971 were classified as false positives, exemptions, non-applicable cases or OFAC-related matters; 99 were still under investigation, 16 were deferred and 24 were confirmed as sanctioned and applicable. These categories are not interchangeable. Most alerts did not end with findings that required a registration freeze.
This denominator is a warning against immediate technical measures. Names transliterated across alphabets, common company words, subsidiaries, ownership changes and incomplete public records can produce matches that require human investigation. If every alert suspended certificate publication or caused a route filter, false positives would become connectivity events. The harm would affect not only the matched company but also customers, hospitals, public institutions, hosting tenants and counterparties that use its network.
The same report states that potential matches must be treated restrictively during review because sanctions law may not provide a grace period. This creates a genuine tension. An institution cannot simply wait without controls. Yet it can choose which controls are necessary. Denying a new allocation or transfer while maintaining the current registration and security state is more proportionate than making an existing prefix appear unassigned.
The record also demonstrates reversibility. Entries can be thawed when restrictions are lifted or an exception is determined. A design that preserves the authoritative history makes recovery traceable. A design that deletes records, lets certificates fail unpredictably and scatters customers across conflicting copies turns a temporary legal status into permanent technical disorder.
Layer One: Payment Is a Transaction, Not a Judgment on Connectivity
The payment layer concerns the movement of money through a particular channel, currency, institution and jurisdiction. A bank may reject a transaction because a party is listed, because ownership appears risky, because an intermediary bank applies a wider policy, or because its internal controls cannot economically resolve the case. Only some of these outcomes establish that the registry itself is prevented from providing every associated service.
NRS should treat a failed or refused payment as evidence of that transaction. The billing record should include the amount, due date, methods attempted, the bank's response category and available lawful alternatives. It should not automatically override the resource record. Unless a general licence, statutory exception or competent authority authorisation covers essential communication, the institution should be able to accept payments via a compliant path or defer collection without obscuring the agreement.
A deferral must not become a private subsidy without authorisation. The amount remains due where law and contract permit later collection. Interest, penalties and termination rules should be adjusted so that a customer is not penalised for a channel the institution itself cannot make available. At the same time, a customer who can lawfully pay but refuses should not receive unlimited free service by invoking geopolitical difficulty. Evidence should distinguish inability from unwillingness.
Bank diversity can reduce accidental exclusion, but selecting between banks is not a licence to circumvent controls. The institution should pre-qualify channels in different jurisdictions, document the legal basis for each, screen intermediaries and stop when a prohibition applies. It should avoid routing a payment through opaque entités solely to obtain acceptance. The aim is lawful resilience, not obscurity.
The most important technical safeguard is decoupling. Billing status can limit paid support, attendance at paid events or new discretionary requests. It should not alone delete an address registration, revoke a current certificate or instruct networks to filter routes. Those actions require findings at their own layers.
Aggregated reporting should distinguish legal refusals, bank risk-based refusals, customer defaults and deferred obligations. Without these categories, a registry may claim sanctions compliance when the true cause is commercial risk appetite. Members and regulators need to know whether the law, a bank or the institutional design caused the restriction.
Layer Two: Corporate Membership Can Be Restricted Without Deleting the Record
Corporate membership confers institutional rights: voting, nomination, attendance at meetings, access to member-exclusive information, eligibility for committees and possibly favourable service terms. These benefits are not identical to the authoritative record of an existing allocation. A sanctions rule may prohibit providing funds or economic resources to a listed firm, or it may restrict the firm's participation in a legal association. The appropriate response may therefore affect membership, even while record continuity remains necessary.
NRS should specify which rights are corporate and which are fiduciary. Voting and candidacy may be suspended if applicable law requires it. New grants, discounts and discretionary advice may be restricted. Basic notifications, access to review of adverse measures and the ability to correct a dangerous factual error should remain available through a controlled channel. Refusing every means of communication would impede accurate compliance.
Suspension should not allow a listed member to influence decisions through a related entité or front. Ownership and control tests must go beyond the account name. At the same time, an affiliation is not enough. A customer, minority investor, former director or similarly named company should not lose rights without evidence meeting the applicable standard. The institution should record which legal test it used and as of what date the ownership picture was assessed.
Rules also need a position on fees. If a member cannot pay due to bank restrictions but is not itself prohibited, maintaining membership with deferred billing may be justified. If the legal person is subject to an assets freeze, continuing valuable corporate privileges may differ from maintaining a public resource record in the interest of third-party security. The decision must name this difference, not hide it in an account flag.
Corporate suspension should have an expiry or review date. Sanctions lists change, ownership changes and courts annul listings. An institution that can impose a restriction within hours but takes months to lift it creates an asymmetric penalty that the law does not provide. Regular re-reviews and a direct evidence channel are necessary.
Most importantly, the loss of a vote must not make a network number ambiguous. The resource history should show the holder's status, restrictions and permitted actions without releasing the space for reissue. Corporate rights may pause while fiduciary administration continues.
Layer Three: Authoritative Registration Protects Uniqueness Even Under Restriction
The registration layer answers the question of who currently holds recognised authority over an Internet number resource, what restrictions apply, which contacts may be published and what changes have been accepted. Its public value is avoiding conflicting claims. This value persists even when the holder is sanctioned. Geopolitical conflict makes a stable record even more important.
Freezing registration should mean a limited prohibition of changes that would make a new economic resource available or transfer control. It should not mean pretending the existing allocation never happened. Deregistration could release the same space for reissue, competing route claims or opportunistic seizure. Even if no responsible registry reassigns it immediately, an apparently empty record weakens the evidence used by networks, investigators and counterparties.
Not all changes are equivalent. A transfer to a new beneficial owner differs significantly from correcting an abuse contact or replacing a compromised authentication credential. The former may alter control over a scarce resource. The latter may protect victims and improve accountability. NRS needs a matrix of permitted changes for restricted records. Security corrections, legally required disclosures and measures to prevent hijacking should have a path, even when commercial transfers are prohibited.
Corporate restructurings require careful treatment. A renaming after a merger may be a harmless correction, a prohibited transfer or an attempt to conceal listed ownership. The institution should examine legal person continuity, beneficial owner, consideration, control and applicable exemptions. A public status should reveal that a restriction exists without publishing sensitive evidence or making an unsupported allegation.
The registration history must be append-only in output. Previous states, decisions and supporting categories should remain available to authorised auditors. If a freeze is later lifted, the record should show continuity, not a newly invented start date. This protects both enforcement and the holder: authorities can see what was prevented, while the holder can prove that its recognised resource did not disappear during the restriction.
Transfers between registries are particularly sensitive. A sending institution cannot resolve sanctions risk by exporting a case to a registry with weaker controls. The receiving institution cannot assume that a regional shift cures a restriction. Both need compatible evidence, a common switchover event and a clear decision about which restrictions travel. Nevertheless, a restriction should not simply be extended because two institutions use different terminology. The legal basis, not the label, must travel.
NRS can add value here by providing a neutral, transferable record rather than declaring itself outside jurisdiction. A common record can preserve holder continuity, restriction origin, review dates and permitted actions across service provider changes. Neutrality means accurate limited state, not indifference to law.
Layer Four: RPKI Actions Can Affect Far Beyond the Named Entité
RPKI is the point where administrative coupling can become an immediate network security problem. Resource certificates and route origin authorisations enable dependent parties to determine whether an autonomous system is authorised to announce a prefix. Many networks use validated states in routing policy. Revoking a certificate, withdrawing an authorisation or letting publication fail can therefore change route classification in organisations that were never part of the sanctions decision.
A company's legal identity and a route's cryptographic authorisation are related but separate. RFC 9255 clarifies that the identity expressed in RPKI is not a general confirmation of a real person or company. RPKI expresses authority over specific Internet number resources. A sanctions match with a legal name is not itself evidence that an existing route authorisation is technically false.
This does not make RPKI untouchable. A prohibited reassignment should not be certified as if it were valid. A completed lawful transfer requires the end of the old authority and the start of the new. Evidence of key compromise may justify urgent replacement or revocation. A specific legal order may require a certificate action. The discipline is to link the action to an RPKI-relevant fact or an express legal requirement.
Hosted service creates an additional risk. If the same account controls billing, registration and signing, an account suspension may stop renewal or publication without a deliberate certificate decision. NRS should separate entitlements, status and continuity counters. A holder under financial restriction may lose access to optional hosted controls while the last known accurate signed state remains available for a limited period under pre-agreed rules. Any renewal must be legally vetted and visible in audit evidence.
The institution should favour conservative continuity over invention. It should not create broader route authorisations on behalf of a restricted holder. Nor should it silently retain an entité known to be false. The safe standard is to maintain the last verified state while facts are unresolved, use short and disclosed review intervals, and provide an emergency path to correct security-critical errors.
Repository availability should be treated separately from signing. Removing access to a customer portal must not make already published entités inaccessible. A repository serves dependent parties worldwide, and its continuity protects their ability to maintain a consistent view. Publication may continue while requests for new signed content are restricted.
Every sanctions-related certificate action should have a dependent-party impact assessment. The authority should estimate which prefixes and origins are affected, whether routes will become invalid or not found, how long caches will hold state, which dependent networks might be at risk and how reversal will converge. This is not to claim that impact overrides law. It ensures the lawful action is implemented with knowledge of its external consequences.
Layer Five: Routing Is an Operator Decision, Not a Registry Sanction
Routing is carried out by autonomous networks according to technical policy, contracts, security conditions and applicable law. A registry records resources and may operate certificate services, but does not ordinarily command every network to carry or reject a route. Maintaining this boundary is essential when sanctions pressure rises.
A transit provider may be prohibited from serving a listed entité. Another operator may conclude that carrying a route is permissible because its relationship is with non-listed customers, a communications exception applies, or the route aggregates traffic of a broader population. These are fact-based decisions. A registry status can inform them but not replace their legal analysis.
Similarly, route origin validation is not a sanctions list. A cryptographically valid route may still violate law or contract. A route that is not found because an entité expired is not thereby proved unlawful. Mixing the two would corrupt a security signal with an unrelated policy meaning. Operators would no longer know whether invalidity reflects a hijack, a configuration error, a disputed resource authority or a geopolitical measure.
Governments intending a route block should name the responsible operators, the legal scope, the target or service, the duration and the review mechanism. They should not rely on an opaque request to a resource institution as a global shortcut. The institution should require orders to be specific and should publish aggregated information about their reach to the extent legally permissible.
Operators must also protect independent customers. Shared hosting, wholesale access, cloud services and national backbones can place many legal persons behind the same origin. Blocking an autonomous system can be far broader than blocking a sanctioned service. Before acting, a provider should examine more specific technical measures, the possibility of customer migration, emergency communications and the risk of collateral disconnection.
NRS should provide accurate resource and restriction information over authenticated channels but should not issue a universal routing verdict. Its role is to keep the evidence coherent enough for networks to make accountable decisions. The ultimate forwarding decision remains with the operator, unless a competent authority lawfully orders otherwise.
A Five-Layer Decision Table Should Replace the Single Account Switch
Institutions often rely on a single customer status because it simplifies administration. Sanctions make this convenience dangerous. NRS should maintain a decision table in which each layer has its own legal question, authorised actions, continuity basis, approver, evidence and review date.
For payment, the question is whether a specific transaction can be received or refunded. Actions include acceptance, alternative lawful routing, deferral, blocking or return. For membership, the question is whether corporate rights or benefits can continue. Actions include full participation, restricted participation, suspension or termination. For registration, the question is which changes are prohibited while uniqueness and history remain intact. For RPKI, the question is which signed state accurately reflects resource and route authority and which publication obligations protect dependent parties.
For routing, the question belongs to operators and competent authorities applying their own obligations.
The table should also indicate what does not follow. Payment refusal does not establish loss of resource authority. Membership suspension does not make a prefix unassigned. Registration freeze does not prove existing routes are malicious. A valid route authorisation does not establish that every commercial service to the holder is lawful. Route filtering does not authorise resource reissue.
Cross-layer escalation should require an explicit bridge. For example, a court order may both freeze transfer of an asset and require a change in resource authority. A verified acquisition may change registration and then require new certification. A compromised administrator may justify revoking entitlements and an RPKI recovery without affecting corporate voting. The decision record should identify the fact that connects the layers.
This design is more work than an account switch, but the burden is proportional to institutional power. Automation can still handle routine checks, timers and notifications. Human judgement should focus on ambiguous ownership, exceptions, external effects and irreversible actions. The system should make the narrow lawful decision easier than the broad accidental one.
Identity Resolution Is the Central Operational Risk
Sanctions lists identify legal subjects through names, aliases, dates, registration numbers, addresses, ownership and control. Registry records may contain trading names, old addresses, sponsors and technical contacts. The matching problem is therefore structural. A similarity score cannot decide whether a network customer is the listed entité.
NRS should use graded identity evidence. Strong identifiers include official company numbers, jurisdiction, incorporation documents and verified beneficial ownership. Names and addresses help but can be outdated or shared. Technical contacts and email domains are weak evidence of ownership. Route announcements and RPKI objects identify network authority, not necessarily the natural persons who control a company.
Potential matches should be triaged by consequence. A request for a new transfer may pause while evidence is gathered. A measure that would interrupt security publication requires faster review and a higher evidence threshold. The institution should contact the holder through more than one established channel and explain what documents can resolve the match without revealing sensitive detection details.
Non-cooperation presents a difficult case. A customer that ignores reasonable requests cannot demand unrestricted new benefits. Yet silence may reflect war, detention, damaged infrastructure, language barriers or inaccessible corporate records. A 'pending' status should therefore restrict discretionary changes while preserving the safe current state. It should not automatically transition to technical deletion after an arbitrary interval.
Reviewers need cultural and jurisdictional competence. Transliteration conventions, patronymics, state-owned enterprise forms and commercial registers differ. A mismatch rate as high as the numbers indicated by the RIPE NCC cannot be dismissed as noise. It is evidence that screening is a provisional signal, not a final decision.
The institution should measure precision and correction time. How many alerts become confirmed cases? How long do false positives remain restricted? Which source caused repeated errors? Are certain countries or scripts exposed to longer resolution? Accountability must include the people wrongly restricted, not only the successfully frozen cases.
Exceptions and Banking Reality Require Separate Legal Maps
Sanctions regimes often contain exceptions, general licences or authorisation paths for telecommunications and Internet communication. The U.S. Treasury, for example, has stated that Russia-related General License 25D authorises certain transactions ordinarily incident to telecommunications and certain services, software, hardware and technology incident to Internet communications, subject to exclusions. European Union measures also contain communications-related exceptions in defined environments. These provisions do not automatically cover every registry service, but they show that legislators recognise the risk of collateral communication.
NRS should maintain a jurisdiction-specific legal map for each layer. The map should identify the governing instrument, the listed party, the ownership threshold, the covered service, the exception, the competent authority, the reporting obligation and the expiry date. It should not collapse different regimes into a single global blacklist. A service may be permitted under one law, prohibited under another and commercially refused by a bank applying its own policy.
When a legal exception appears available but the bank still refuses payment, the institution should record this difference. It may request a written explanation, use a different compliant bank, seek regulatory comfort or defer the amount. It should not tell the public that law required a disruption when commercial caution caused it.
Conversely, a bank channel that accepts funds does not prove the service is lawful. The registry remains responsible for its own obligations. Separation prevents legal judgement from being outsourced upward to the strictest intermediary or downward to the most permissive one.
The legal map must be maintained by responsible legal advisers and made accessible for independent review in a form that protects privileged advice. Members should at least see the operational rule, the service category, the decision date and the path to challenge. Secret interpretations concentrate uncontrolled power.
Exceptions also need expiry control. A general licence may be amended or revoked. A temporary authorisation may only cover wind-down. The institution should warn before an authorisation ends and prepare continuity options rather than dropping a certificate or registration service at midnight.
Continuity Should Protect Third Parties Without Enriching the Target
The strongest objection to continuity is that any maintained service benefits the sanctioned entité. Sometimes it does. The response is not to deny the problem but to distinguish the benefit retained by the target from the harm avoided for others.
Keeping an address record visible prevents conflicting claims by all. Maintaining repository availability allows independent dependent parties to validate a consistent state. Maintaining an abuse contact can help victims. Granting time for a hospital customer to migrate from a sanctioned carrier protects public health. These measures may incidentally aid the listed entité, but their primary and measurable purpose can be broader stability.
The continuity measure should therefore be minimal, limited and non-expansive. No new resources, broader authorisations or preferential support should be added unless expressly permitted. The existing state should be maintained only as long as necessary to clarify status, migrate dependants or comply with an exception. Fees and deferred obligations should be recorded. Decision-makers should disclose conflicts of interest.
Where possible, services should be directed to third parties, not to the target. A repository can continue to serve public entités without giving the holder new portal rights. A registry can accept a security correction through an independent administrator. A continuity provider can migrate critical downstream customers while commercial service to the listed parent remains restricted.
This approach is not perfect. Shared infrastructure makes incidental benefits inevitable. Sanctions law itself often addresses this through licences and proportionality. NRS should seek guidance from competent authority in ambiguous high-impact cases rather than improvising broad exceptions.
Continuity must also end when it no longer protects the stated interest. If all independent customers have moved and a specific prohibition covers the remaining service, the institution should act. A continuity justification without milestones becomes evasion. The record should state the protected population, permitted actions, review interval and termination condition.
Emergency Measures Need Narrow Authority and Rapid Independent Review
War and rapidly changing sanctions create pressure for immediate decisions. A new listing may appear outside business hours. Banks may freeze accounts without warning. A certificate may approach expiry while ownership evidence is disputed. NRS needs emergency authority, but its form determines whether urgency becomes permanent discretion.
An emergency officer should be able to pause new allocations and transfers, protect entitlements, preserve records and maintain the last known safe publication state for a short period. The officer should not be able to deregister resources, create new route authority or impose an indefinite corporate exclusion alone. High-impact measures should require a second approver and review by an independent panel within a fixed number of hours or days.
Every emergency measure needs a written justification: the suspected legal restriction, the affected entité, the layers touched, the available evidence, the collateral risk, the expiry date and the responsible person. If facts are incomplete, this uncertainty should be explicit. Review should decide whether to confirm, narrow, replace or lift the measure.
Notification should normally reach the holder and affected service providers through established channels. A brief delay may be justified if notification would facilitate a prohibited transfer or abuse of entitlements, but secrecy should self-expire. Independent customers exposed to connectivity risk need practical information without disclosing protected sanctions evidence.
Reversal must be rehearsed. Restoring portal access is not enough if repository state, contacts and provider entitlements remain inconsistent. NRS should test the return from each layer-specific restriction and measure how long the public state takes to converge. A temporary freeze that cannot be cleanly lifted is not temporary in practice.
Rule of Law Improves Enforcement Rather Than Weakening It
Sanctions administration is sometimes presented as incompatible with ordinary review because assets can move quickly. This concern supports immediate preservation measures, not unappealable final decisions. Accurate identity, ownership and service classification are essential for enforcement. A structured challenge can uncover mismatches, sham transfers and hidden controllers more reliably than silence.
The holder should receive the non-sensitive basis for the measure, the layers affected, the permitted activities, the evidence needed for correction, the review deadline and the escalation path. The institution should not disclose information the law protects, but it should avoid empty language that makes a response impossible. If a government agency holds the decisive evidence, the notification should name the agency and the available legal remedy.
Independent review should include sanctions expertise, number resource operations and routing security. A purely legal body may understate certificate consequences. A purely technical body may treat criticality as a legal exception. Mixed competence is necessary.
The reviewer should have authority to order narrower treatment. It may uphold a payment freeze but restore a security contact, uphold a transfer freeze but require repository continuity, or exempt a subsidiary while restrictions on the listed parent remain. A binary confirm-or-lift review would reproduce the original design flaw.
Publication should protect privacy while revealing institutional behaviour. Aggregated reports can show alerts, confirmed cases, false positives, time to decision, layer-specific restrictions, lifts, bank-caused outages, exception usage and collateral incidents. Significant cases may receive anonymised or delayed explanations.
Review findings should improve screening criteria. Repeated false positives from one source, long delays in one jurisdiction and frequent excessive account freezes are governance failures. Enforcement credibility depends on correcting them.
Hard Cases Test Whether Separation Is Principle-Based
Consider a sanctioned parent whose subsidiary operates emergency communications but is itself not listed and not controlled at the applicable threshold. Payment from the parent may be blocked and corporate rights suspended. The subsidiary's registration and accurate route security state should not be removed merely because systems share a common billing account. NRS should separate entitlements and require evidence of subsidiary control.
Consider a non-sanctioned network whose bank refuses payment because its name resembles a listed company. New discretionary requests may pause briefly, but the institution should prioritise identity resolution, maintain registration and avoid certificate interruption. If the match proves false, restrictions should end immediately and the delay appear in accuracy metrics.
Consider a listed telecom operator that carries traffic for millions of people, including public services. A prohibition may prevent new resources and transfers. Existing registration may remain frozen, and repository publication may continue where lawful to avoid route misclassification. Transit providers and authorities must assess carriage, customer migration and communications exceptions separately. The registry should not make this decision for the world.
Consider a listed entité trying to transfer scarce IPv4 space for payment to a related company. Registration continuity does not justify approval. The transfer is a new control event and likely an economic benefit. NRS should freeze it, preserve the evidence and prevent conflicting claims in another region.
Consider a key compromise at a frozen holder. Inaction could permit route hijacking. NRS should allow a tightly authenticated replacement that restores the same limited authorisation without expanding resources or origins, subject to legal review. Security correction is not the same as a new commercial grant.
These cases show why principles must be defined before a crisis. Separation is not leniency. It can simultaneously produce a stricter transfer decision and a more protective continuity decision.
The Institutional Design of NRS Should Make Coupling Difficult
NRS should start with separate service identities. A legal person may have interconnected but distinct billing, membership, registration and certificate entitlements. Restricting one entitlement should not disable another unless a recorded rule ties them. Routing information remains public evidence, not a customer-driven service switch.
Contracts should reflect the architecture. The basic stewardship agreement covers authoritative registration and continuity obligations. Corporate membership terms govern voting and institutional benefits. Payment terms define lawful channels and deferral. Certificate terms govern keys, signing and publication. Optional support remains separable. This prevents one standard clause in an agreement from terminating everything.
Data architecture should preserve an authoritative resource history with layer-specific status. Auditors must be able to see that payment was deferred, membership suspended, registration changes frozen, current certificate publication maintained and no routing instruction issued. Public views should only reveal what users need to understand authority and restrictions.
Service providers should be replaceable. If a bank, certificate host or support company cannot lawfully serve a customer, another qualified provider can take over the permitted layer without moving the resource itself. Portability reduces the chance that one intermediary's risk policy becomes a global technical outcome.
Governance should prohibit mandate laundering. NRS cannot claim a bank forced deregistration when the bank only refused funds. A certificate operator cannot call a portal closure a legal revocation. A transit provider cannot cite an NRS freeze as an automatic routing prohibition. Each actor must name its own authority.
The society should also resist the opposite temptation: presenting neutral records as a way to maintain every service for every listed entité. Its neutrality is limited accuracy. New allocations, transfers, corporate privileges and paid support remain subject to law. Separation clarifies where the restriction belongs.
Metrics Should Disclose Both Excess and Deficiency
A credible sanctions report should not count only frozen entités. It should show the full funnel: alerts received, unique subjects, mismatches, ownership investigations, applicable listings, exceptions, bank-related restrictions, average resolution time and lifted cases. It should separate members, sponsored users, legacy holders and inter-registry transfers where these relationships affect authority.
Layer metrics are equally important. How many payments were refused, deferred or lawfully redirected? How many corporate rights were suspended? How many registration changes were frozen? How many security corrections were allowed? How many certificates or signed entités changed due to sanctions? How many routing incidents were reported by third parties?
Collateral effects should be measured. The institution can record dependent public services, downstream customers given migration time, validation changes observed by monitors and false-positive restriction days. It need not disclose customer secrets to reveal aggregate harm.
Speed has two directions. Quick freezing may be necessary, but quick clearing is equally important. NRS should publish median and worst-case times for initial restriction, identity resolution, independent review, restoration and public-state convergence. A mature institution treats correction as secondary.
Quality metrics should examine specificity. What percentage of measures named an authoritative rule, a legal subject, a layer and an expiry date? How many broad account closures were narrowed on review? How often was a bank refusal misclassified as a legal prohibition? These numbers show whether separation is actually applied.
External auditors should sample both confirmed and cleared cases. Reviewing only successful freezes rewards confirmation bias. Cleared cases show where data and judgement fail. Auditors should also test a simulated listing, payment block, certificate emergency and deletion from start to finish.
The Strongest Objections Do Not Justify a Single Switch
One objection is complexity. Five layers, legal maps and independent review cost money. But the comparison is not with a simple harmless alternative. A single switch hides complexity until it becomes an outage, an unlawful freeze or an unlawful service. Separation makes the actual decision visible earlier.
A second objection is evasion. A sanctioned entité may exploit gaps between layers by using continued registration or certificate publication to retain value. This risk supports strict limits on new benefits, beneficial ownership checks and explicit continuity purposes. It does not prove that deregistration or route suppression is always lawful or effective.
A third objection is inconsistency between jurisdictions. The same entité may be subject to different rules in Europe, the U.S. and elsewhere. NRS cannot erase this conflict. It can record which rule applies to each provider, preserve a resource history and prevent one jurisdiction's bank policy from posing as universal law.
A fourth objection is reputational risk. Institutions may fear criticism if they serve a listed network. Public layer-specific justification is the answer. It is more defensible to show that transfers were stopped while security-critical registration continued than to hide behind generic openness or generic compliance.
A fifth objection is operational security. Allowing changes to a frozen record could create a theft path. Permitted security changes should use enhanced authentication, segregation of duties and independent confirmation. A complete freeze can also create security risks if contacts or keys are compromised.
A final objection is that routing continuity indirectly supports a hostile state. Sometimes restrictions are intended to reduce that support. The decision then belongs to competent authorities and operators applying a specific measure. Corrupting registration or RPKI signals is a poor substitute because it distributes effects unpredictably and can hit independent users first.
What Should Be in Place by 2027
By 2027, every major number resource institution should be able to publish a service-layer sanctions policy. The policy should specify what actions occur at the payment, membership, registration and RPKI layers and affirm that routing decisions are not silently coded into registry status. It should identify exceptions, emergency powers, review times and restoration obligations.
Accounts should be technically decoupled. A bank failure should not accidentally expire a certificate. A membership suspension should not remove abuse contacts. A registration freeze should not prevent urgent entitlement restoration. Providers should demonstrate these outcomes in controlled exercises.
Institutions should coordinate interoperable restriction evidence for transfers without building a universal political blacklist. A receiving provider needs the legal basis, the affected resource, the measure, the date and the review status. It does not need every confidential document. Shared semantics can block prohibited transfers and limit overreach.
RPKI continuity rules should be explicit. They should define the last known safe state, actions that count as new benefits, treatment of key compromise, publication obligations, dependent-party impact assessment and time limits. Independent monitors should verify what validators actually observe.
Banks and regulators should participate in exercises. A registry cannot solve payment resilience alone. Competent authorities should clarify whether essential number registration and route security publication fall under communications exceptions. Banks should distinguish legal prohibition from internal risk refusal. The evidence should be recorded without disclosing protected customer information.
NRS should use its neutral record to support provider switching. If a payment or certificate provider fails, another can perform the lawful function without changing the resource identity. This is the positive case for NRS: not freedom from sanctions, but resilience against accidental cross-layer contagion.
The 2027 test should be concrete. Take a simulated entité with a listed parent, non-listed customers, a rejected bank payment, an active transfer request and a certificate approaching renewal. The institution should restrict exactly what the law requires, preserve independent continuity, publish accurate state, complete review and reverse lifted restrictions without a routing incident. If it cannot, its claimed separation remains theoretical.
Sanctions Compliance Needs a Narrower Form of Power
The Internet's shared identifiers do not make their holders immune to national law. Nor does sanctions law make every institution a global network controller. The governance task is to keep both statements true at the same time.
The post-2022 evidence shows that the hard cases are not solved by choosing either connectivity or compliance as absolute. Banks can refuse payments beyond a registry's direct obligations. Most screening alerts can turn out to be false or non-applicable. Registration can be frozen without declaring resources unused. Communications exceptions can preserve defined services. RPKI actions can reach dependent parties with no relationship to the listed entité.
Separating the five layers turns these facts into an institutional discipline. Payment follows transactional law. Corporate membership follows rules on benefits and participation. Registration preserves uniqueness while restricting prohibited changes. RPKI maintains accurate, limited route authority and repository continuity. Routing remains a decision for autonomous networks and competent authorities.
NRS should not promise a policy-free registry. That would be implausible. It should promise that political and legal decisions do not travel further than their authority and evidence justify. A neutral, transferable record, replaceable service providers and independent review can make this promise testable.
The measure of success is not whether every sanctioned network remains reachable or whether every alert produces a freeze. It is whether the institution can explain each measure, protect independent customers, stop prohibited benefits, correct errors and maintain a coherent history. Fragmentation begins when a narrow restriction becomes a silent order to the entire network. Service layer separation is how governance keeps the order narrow.
Sources
- RIPE NCC Quarterly Sanctions Transparency Report, Q2 2026– current numbers on alerts, investigations, false or non-applicable cases, deferred cases, confirmed applicable sanctions and the distinction between registration freeze and resource deregistration.
- The RIPE NCC and Ukraine/Russia– the institution's position on critical services, payment difficulties, applicable restrictions, transfers and continued registration after the 2022 invasion.
- RIPE NCC Quarterly Sanctions Transparency Report, Q4 2022– early post-invasion evidence on investigation volume, frozen registration, Iranian and Syrian invoicing obstacles and continued agreements.
- RIPE NCC Annual Report 2024– evidence on sanctions screening, bank reluctance, payment extensions and the search for a broader exception for Internet number resources.
- RIPE NCC Executive Board Decision on Provision of Critical Services– the board's commitment to uninterrupted critical services in its service region and the wider Internet community.
- OFAC FAQ 1122 on Russia-related General Licenses 25D and 65– the U.S. Treasury's statement on authorisations for certain telecommunications and Internet communications transactions.
- Council Regulation (EU) No 833/2014, consolidated version– current European Union restrictions and defined treatment of electronic communications, payment services and related exceptions.
- RFC 7020, The Internet Numbers Registry System– the registry hierarchy, stewardship role and goal of global uniqueness for Internet number resources.
- RFC 6480, An Infrastructure to Support Secure Internet Routing– the architecture linking resource certificates, route authorisation and validation by dependent parties.
- RFC 8211, Adverse Actions by a Certification Authority or Repository Manager in the RPKI– analysis of how certification authority or repository actions or failures can affect routing security.
- RFC 9255, The 'I' in RPKI Does Not Stand for Identity– the boundary between authority over Internet number resources and claims about real-world identity.

