Skip to main content
LARUS
Explore IPv4 Continuity
Explore

Technical guide

How mandate laundering turns registry coordination into governance power

How mandate laundering transforms registry coordination into a mechanism of governance power, reshaping authority, legitimacy, and control across internet infrastructure and creating systemic risk for network operators.

Explore IPv4 Continuity

mandate-laundering


Internet number registries exist for an important reason: independently operated networks need a reliable way to coordinate globally unique IP addresses and Autonomous System Numbers.

Without that common coordination layer, conflicting claims, inaccurate records and inconsistent resource information could make global interoperability more difficult.

But an important governance question follows:

When does authority needed for technical coordination begin to extend into broader commercial, territorial or operational governance?

Lu Heng uses the term mandate laundering as an analytical framework for examining this transition.

The concept does not claim that Regional Internet Registries are illegitimate or that registry coordination is unnecessary.

Instead, it asks whether the authority exercised by a coordination institution remains proportionate to the technical function that originally justifies compulsory common rules.

Mandate laundering is a concept proposed by Lu Heng. It is not a standard Internet-governance term or universally accepted description of the RIR system.

Mandate Laundering: Quick Answer

In Lu Heng's framework, mandate laundering describes a process through which a narrow coordination role may gradually be presented as supporting broader institutional authority.

A simplified version looks like this:

technical coordination → institutional process → perceived legitimacy → broader compulsory authority

The concern is not the existence of policy.

Registries require policies to operate predictably.

Nor is an open community process itself evidence of mandate laundering.

The question is whether authority created for functions such as uniqueness, registry accuracy and coordination is later treated as sufficient justification for controlling unrelated commercial or operational behaviour.

Coordination authority should remain connected to the coordination problem it is intended to solve.

Why Internet Number Registries Need Real Authority

Any serious discussion of governance boundaries should begin by recognising that registries perform necessary functions.

Internet number-resource coordination can include:

  • maintaining globally unique resource records;
  • recording allocations and assignments;
  • processing eligible transfers;
  • maintaining organisation and contact information;
  • supporting RPKI;
  • supporting reverse DNS;
  • maintaining registration services;
  • supporting resource-related coordination; and
  • helping preserve interoperability between independent networks.

IANA provides global coordination for Internet number resources, while five Regional Internet Registries administer number resources through their respective service regions.

See: IANA – Number Resources and NRO – Regional Internet Registries .

These functions are not merely administrative paperwork.

Accurate registry information can support routing security, resource transfers, troubleshooting, contactability and operational continuity.

The issue is not whether registry authority should exist. The issue is how broad that authority needs to be.

Registry Coordination Is Not the Same as Complete Governance

Internet number resources exist across several separate but connected layers.

legal and commercial rights → registry state → routing authorisation → operational use

Layer Primary Function Relevant Authority
Legal and commercial rights Contracts, transactions, corporate authority and other legally relevant rights Contracting parties, applicable law and competent legal mechanisms
Registry state Maintaining relevant Internet number-resource information Relevant Internet number registry under its applicable processes
Routing authorisation Expressing and validating intended route-origin relationships Resource administrators, network operators and routing-security systems
Operational use Running the network, applications and infrastructure Network operator

These layers need to interact.

But interaction does not make them identical.

A registry record is not automatically a legal property judgment.

A commercial agreement does not automatically update registry state.

An RPKI ROA does not establish every commercial right.

A BGP announcement does not prove legal ownership.

Good governance keeps these layers sufficiently aligned without turning one layer into the source of authority over all the others.

How Technical Coordination Can Become Broader Governance Power

Mandate expansion does not necessarily happen through one dramatic policy decision.

It can develop gradually.

A hypothetical progression could look like this:

  1. A genuine technical problem exists. Networks require unique IP addresses and accurate registry information.
  2. An institution is created to coordinate that problem. The institution maintains records and administrative processes.
  3. Policies develop around those functions. Procedures are needed for predictable administration.
  4. The policy process becomes a source of institutional legitimacy. Participation and community process strengthen confidence in decision-making.
  5. The institution begins addressing broader questions. Rules may move into areas involving commercial models, geography, market structure or operator behaviour.
  6. The expanded authority is justified using the legitimacy of the original coordination mandate.

Lu Heng describes this final step as mandate laundering.

The framework does not prove that every broader policy is invalid.

It asks whether the broader rule has an independent and sufficient justification.

A Community Process Does Not Automatically Create Unlimited Authority

Multistakeholder and community-based policy development can provide important benefits.

These may include:

  • transparency;
  • technical expertise;
  • operator participation;
  • public discussion;
  • documentation;
  • consensus-building; and
  • institutional accountability.

But the existence of an inclusive process does not by itself determine the legitimate scope of every possible rule.

A process can answer:

How should this institution make decisions?

It does not automatically answer:

Which decisions should this institution have authority to make?

These are separate governance questions.

Why This Matters More After IPv4 Exhaustion

Earlier Internet number-resource systems developed during a period when allocation of previously available IPv4 space was a major function.

After exhaustion, IPv4 increasingly moves through:

  • transfers;
  • leasing;
  • corporate restructuring;
  • market transactions;
  • cloud deployment;
  • BYOIP;
  • network migration; and
  • provider-neutral infrastructure.

This means registry systems increasingly interact with resources that already have significant economic and operational relationships.

The governance challenge therefore changes.

The system is no longer only deciding how unused resources are distributed. It is also recording and coordinating changes involving resources already embedded in running networks and commercial relationships.

Distribution Authority and Registry Authority Are Different

When previously unallocated resources are being distributed, an institution may legitimately need rules governing eligibility and allocation.

But transferred or already-operational resources raise different questions.

These may involve:

  • existing commercial rights;
  • existing customers;
  • running routes;
  • long-standing infrastructure;
  • established security relationships;
  • corporate succession; and
  • business continuity.

The existence of authority over a free pool does not automatically answer how much authority should apply to every subsequent market transaction involving already-deployed resources.

This distinction is especially important as the IPv4 market matures.

Registry Recognition Is Important, but It Is Not the Entire Legitimacy Model

Registry recognition matters.

It can affect:

  • registry records;
  • transfer processing;
  • RPKI;
  • reverse DNS;
  • contact information;
  • resource administration; and
  • other coordination functions.

But broader legitimacy may involve additional factors such as:

  • commercial agreements;
  • applicable law;
  • corporate authority;
  • historical resource relationships;
  • legitimate operational delegation;
  • routing authorisation; and
  • actual network operation.

Registry recognition is an important coordination fact. It should not automatically become the complete definition of every legal, commercial or operational right.

The Registry Should Record Reality, Not Replace It

A registry performs its strongest coordination role when its information accurately reflects relevant and verifiable changes in the network-resource environment.

Those changes can include:

  • eligible transfers;
  • corporate succession;
  • mergers and acquisitions;
  • operational delegation;
  • routing relationships;
  • security assertions;
  • contact changes; and
  • other legitimate resource relationships.

When operational reality evolves, the coordination system should be capable of representing relevant changes accurately.

A registry record describes an important coordination state. The record should not be mistaken for the source of every underlying right.

IPv4 Leasing Is a Useful Test Case

IPv4 leasing demonstrates why coordination and operational control need to be separated.

In a leasing arrangement:

  • one organisation may carry the upstream resource relationship;
  • another organisation may provide the customer-facing service;
  • the customer may operate the network;
  • the customer's ASN may originate the prefix;
  • RPKI and IRR information may need to reflect that use; and
  • third-party systems may depend on the resulting IPv4 identity.

This does not make the arrangement illegitimate.

The relevant coordination questions are whether:

  • uniqueness remains protected;
  • responsible parties remain identifiable;
  • routing authorisation remains accurate;
  • abuse contacts remain usable;
  • duplicate claims are avoided;
  • fraud can be addressed; and
  • continuity responsibilities are clear.

For an overview of different leasing structures, read IP Leasing: How IPv4 Leasing Works, Models, Costs & Benefits .

Commercial Intermediation Is Not Mandate Laundering

Another important distinction is between institutional authority and commercial intermediation.

Brokers, marketplaces and resellers may provide:

  • market discovery;
  • transaction matching;
  • customer support;
  • technical services;
  • commercial execution; and
  • regional business relationships.

These relationships may create operational dependencies, but they do not automatically represent mandate laundering.

Mandate laundering concerns institutional authority. Commercial intermediation concerns service and market structure.

The two should not be confused.

Running-Code Primacy: A Proposed Test for Compulsory Governance

Lu Heng proposes a related framework called Running-Code Primacy.

Running-Code Primacy is a governance proposal, not a currently universal Internet standard.

The framework asks:

Does this compulsory rule protect something independently operated networks genuinely need in order to interoperate?

Under this test, stronger justification exists for common rules protecting:

  • resource uniqueness;
  • accurate registry state;
  • contactability;
  • routing-security assertions;
  • fraud resistance;
  • legible changes in resource relationships; and
  • operational continuity.

By contrast, rules primarily intended to regulate:

  • commercial pricing;
  • preferred business models;
  • commercial morality;
  • customer geography;
  • regional economic policy; or
  • other non-technical market decisions

may require a different source of authority if they are to become compulsory.

Minimum Common Rules, Local Operator Decisions

Running-Code Primacy also suggests a distinction between common coordination requirements and local decisions.

The common layer can define the minimum information necessary for independent networks to interoperate.

Beyond that minimum, operators can often make their own decisions.

For example:

  • a common system may define how a route-origin authorisation is expressed;
  • each network may decide how it uses that information in local routing policy;
  • a registry may maintain accurate resource information;
  • an operator may decide how its own infrastructure is deployed;
  • a system may require valid contactability;
  • commercial parties may negotiate their own pricing and service structure.

Common where interoperability requires it. Local where independent operation can safely decide it.

When Registry Authority Can Become Operational Power

The governance boundary becomes particularly important when registry-layer decisions can affect running infrastructure.

Relevant dependencies can include:

  • RPKI authority;
  • reverse DNS;
  • resource records;
  • transfer eligibility;
  • account access;
  • recognition of corporate changes;
  • recognition of operational delegation; and
  • dispute-related administrative actions.

This does not mean every registry action controls the running network.

BGP remains operated by independent networks.

But certain registry-supported systems can have significant downstream effects.

The greater those effects, the stronger the case for procedural safeguards.

Authority Should Be Matched by Accountability

A useful governance principle is that institutional authority should remain proportionate to the function being performed.

Where a decision may materially affect network operations, useful safeguards can include:

  • clear authority;
  • published rules;
  • transparent procedures;
  • auditability;
  • appropriate due process;
  • proportionality;
  • review mechanisms where appropriate; and
  • continuity safeguards.

This does not make a registry liable for every downstream network incident.

It means significant institutional authority should be exercised through processes that recognise the consequences of that authority.

Mandate Expansion and Enforcement Creep

Registries need mechanisms to maintain accurate information and respond to legitimate fraud and security concerns.

The risk of enforcement creep appears when mechanisms created for one narrow function gradually become tools for regulating unrelated commercial or operational behaviour.

For example, accurate abuse contacts serve a legitimate coordination purpose.

A separate question is whether every failure associated with administrative contact management should automatically create consequences for a running network.

The stronger the operational consequence, the stronger the need for clear scope, due process and proportionality.

Administrative Disputes Should Not Automatically Become Network Outages

The distinction between registry coordination and operational control becomes especially important during disputes.

A dispute may involve:

  • contract interpretation;
  • corporate authority;
  • registry information;
  • transfer eligibility;
  • fraud allegations;
  • resource status; or
  • legal proceedings.

These questions may require investigation or adjudication.

But where a legitimate production network is already operating, continuity consequences should also be considered.

Where appropriate, preserving the last verified state while a dispute is resolved can reduce unnecessary disruption without prejudging the final outcome.

This does not prevent action against fraud or compliance with valid legal decisions.

It separates dispute resolution from unnecessary operational disruption.

For a detailed explanation, read What Happens When IPv4 Resources Are Recalled or Disputed? .

Registry Stability Is Not the Same as Running-Network Stability

Stable registry functions are valuable.

Operators may depend on:

  • registration records;
  • RPKI;
  • reverse DNS;
  • transfer records;
  • organisation data;
  • contact information; and
  • other coordination services.

But institutional continuity and functional continuity are not necessarily the same thing.

The institution matters because the function matters. The ultimate operational objective is continued interoperability and continuity of running networks.

A resilient registry architecture should therefore consider whether important functions are:

  • auditable;
  • recoverable;
  • exportable where appropriate;
  • replicable where appropriate;
  • portable; and
  • capable of continuing during institutional disruption.

Portability Is a Useful Test of Governance Scope

IPv4 addresses can become embedded in long-term network identity.

A prefix may appear in:

  • customer allowlists;
  • APIs;
  • firewalls;
  • VPNs;
  • banking integrations;
  • payment systems;
  • security platforms;
  • partner networks; and
  • compliance documentation.

Once this happens, forced renumbering can become a business-continuity event.

A useful governance question is:

Is a restriction on portability genuinely necessary to preserve uniqueness, security or interoperability, or does it create unnecessary provider or institutional lock-in?

Portability is not unlimited.

Technical feasibility, routing scale, contracts, security and applicable processes still matter.

But where continuity can be preserved without compromising shared technical requirements, reducing unnecessary lock-in can strengthen operator independence.

Registry Region Should Not Become Geographic Ownership

Regional Internet Registries operate within defined service regions.

Those regions help organise registry services, membership and policy development.

But a registry service region should not automatically be treated as geographic ownership of the Internet number resources administered through that registry.

Registry region alone does not determine:

  • where a prefix can be routed;
  • where a network's customers must be located;
  • where services using the prefix must operate;
  • where the address space has commercial value; or
  • every legal right associated with the resource.

Registry region describes an administrative coordination relationship. It does not automatically create geographic ownership.

Operational Delegation Should Be Representable

IPv4 leasing and delegated use are part of the modern operational Internet.

A resource may be registered through one organisational relationship while another network legitimately uses it.

Coordination systems do not necessarily need to publish every commercial detail of that arrangement.

But they benefit from being able to represent information relevant to technical coordination, such as:

  • responsible contacts;
  • abuse contacts;
  • routing relationships;
  • origin-ASN information;
  • security assertions;
  • reverse DNS responsibility; and
  • other operational delegation where useful.

Accurate representation of legitimate delegation can improve registry quality. Ignoring operational reality can reduce it.

What a Thin but Strong Registry Layer Would Do

A thin registry layer does not mean a weak registry.

It means a registry that is strong within a clearly defined coordination mandate.

Such a system could prioritise:

  1. Uniqueness. Prevent conflicting number-resource claims.
  2. Accurate registry state. Maintain relevant and verifiable resource information.
  3. Contactability. Ensure responsible parties can be reached.
  4. Fraud resistance. Protect the integrity of registry changes.
  5. Transfer legibility. Record legitimate changes in resource relationships.
  6. Routing-security integrity. Support accurate RPKI and related security assertions.
  7. Operational delegation. Allow relevant operational relationships to be represented accurately.
  8. Continuity. Avoid unnecessary disruption to legitimate running networks.
  9. Resilience. Make critical coordination functions auditable and recoverable.

Thin coordination therefore does not mean eliminating registration, security or accountability.

It means limiting compulsory common authority to the functions the common system genuinely needs to perform.

How This Applies to LARUS Customers

For an enterprise leasing IPv4, governance theory becomes relevant when institutional dependencies can affect service continuity.

A useful separation is:

Customer

→ controls its network, applications, BGP policy and infrastructure

IPv4 service provider

→ carries defined commercial and registry-facing responsibilities associated with delivering the service

Registry layer

→ provides number-resource coordination functions

The goal is not to centralise every layer with the provider.

The goal is to make service responsibility clear while preserving customer operational independence.

Clear accountability is more useful than unnecessary concentration of control.

Organisations where long-term public network identity matters can learn more about LARUS IPv4 Leasing Continuity Assurance .

Mandate Laundering vs Legitimate Registry Authority

Function Strong Coordination Justification?
Maintain unique resource records Yes — directly supports global coordination
Maintain accurate organisation and contact information Yes — supports coordination and accountability
Protect registry changes against fraud Yes — protects integrity of the common state
Support RPKI and routing-security information Yes — supports secure routing coordination
Determine market prices Generally requires a separate justification
Decide preferred commercial business models Generally requires a separate justification
Control customer geography when not technically required Generally requires a separate justification
Operate the customer's network No — network operation belongs to the operator

Frequently Asked Questions

What is mandate laundering?

Mandate laundering is a governance concept proposed by Lu Heng. It describes how authority derived from a narrow coordination function may be presented through institutional, policy or community legitimacy as supporting broader compulsory authority.

Is mandate laundering an official RIR concept?

No. It is an analytical framework proposed by Lu Heng, not an official term used by the RIR system or a universal Internet standard.

Are Regional Internet Registries illegitimate?

No. RIRs perform important number-resource registration, allocation, transfer, RPKI, reverse DNS and coordination functions. The governance question concerns the appropriate scope of compulsory authority, not whether registry coordination should exist.

Does community policy development create legitimate authority?

Community participation can strengthen transparency, expertise and accountability. But the quality of a decision-making process and the scope of the institution's mandate are separate questions.

What is governance drift?

Governance drift describes the gradual expansion, reinterpretation or changing practical effect of policies and institutional practices over time.

What is Running-Code Primacy?

Running-Code Primacy is a governance framework proposed by Lu Heng. It argues that compulsory common rules should focus primarily on functions independently operated networks actually require for safe interoperability.

Does registry recognition equal ownership?

No. Registry state is an important coordination fact, while legal rights, commercial rights, routing authorisation and operational use are separate layers.

Does RPKI give a registry operational control of a network?

No. RPKI provides routing-security information that networks may use in route-origin validation. Network operators still make and execute their own routing policies.

Is IPv4 leasing a governance problem?

Not inherently. Leasing is a commercial and operational arrangement. The coordination challenge is ensuring relevant registry, routing, security and contact information accurately supports legitimate use.

Can registry rules affect running networks?

Some registry-supported functions can have operational consequences, particularly where RPKI, reverse DNS, resource status or administrative access are involved. This is why clear authority, due process and continuity safeguards matter.

What is a thin registry layer?

A thin registry layer is not a weak registry. It is a coordination system focused on the common functions necessary for uniqueness, accurate resource state, security, contactability and interoperability without unnecessarily controlling unrelated commercial or operational decisions.

How can businesses reduce registry-layer dependency?

Businesses can clarify commercial rights, maintain accurate resource information, understand who manages RPKI, IRR and reverse DNS, document upstream dependencies, preserve routing independence where practical and plan continuity before a prefix becomes difficult to replace.

Conclusion

Internet number-resource coordination is necessary.

Global networks need unique identifiers, accurate records, contactability and routing-security information.

But necessary coordination does not answer every question about the legitimate scope of institutional authority.

Lu Heng's mandate-laundering framework asks whether authority created for a technical coordination function can gradually expand into broader commercial or operational governance without a sufficiently independent justification.

A useful way to preserve the boundary is to keep four layers distinct:

legal and commercial rights + registry state + routing authorisation + operational use

Registries have an important role in the registry layer.

Network operators remain responsible for running their networks.

Commercial parties determine contractual relationships.

Appropriate legal mechanisms address legal disputes.

These layers should coordinate with one another, but they should not automatically collapse into one source of authority.

Strong coordination does not require unlimited governance power. It requires clear scope, accurate records, appropriate accountability and enough common infrastructure for independent networks to keep running.

For Lu Heng's broader analysis of mandate laundering, read Mandate Laundering: From RIR Fantasy to Transition Architecture .

For the related framework on minimum common coordination, read The Policy Mirror .

For a broader introduction to Internet governance, read Internet Governance: What It Is and Why It Matters .

For more on registry state, ownership and operational control, read Who Owns IP Addresses? .

For organisations where stable IPv4 identity is important to production infrastructure, explore LARUS IPv4 Leasing Continuity Assurance .

Keep your network moving

Turn the next answer into your next network move.

Build with Unlimited IPv4 and explore LARUS Continuity for the network your customers depend on.

Explore IPv4 Continuity