Voluntary Public Interest Commitments Crafting Compliance Metrics
- by Staff
As the 2026 new gTLD program opens the door for a new generation of top-level domains, applicants are once again faced with the opportunity—and in some cases, the strategic necessity—of incorporating Voluntary Public Interest Commitments, or PICs, into their applications. While mandatory PICs are now well established as contractual obligations designed to protect DNS stability and end-user rights, voluntary PICs serve as self-imposed commitments by registry operators to uphold additional public interest values, often as a means of building trust, mitigating anticipated concerns, or aligning the TLD with specific social, commercial, or policy goals. However, the inclusion of such commitments introduces a parallel obligation: the development and implementation of credible, transparent, and enforceable compliance metrics that can demonstrate adherence over time. Without these metrics, voluntary PICs risk becoming aspirational statements rather than accountable standards.
Crafting effective compliance metrics for voluntary PICs begins with a foundational understanding of the commitment itself. A well-structured PIC should be specific, measurable, and achievable, avoiding vague language or open-ended promises. For example, a PIC that states a registry “will prevent abuse” is difficult to operationalize, whereas a commitment to “investigate and respond to verified reports of phishing within 24 hours of notification” provides a basis for clear, quantifiable metrics. Applicants should align their PICs with existing regulatory frameworks, industry best practices, and stakeholder expectations. This includes referencing standards from organizations such as the Internet & Jurisdiction Policy Network, the Anti-Phishing Working Group, or ISO security norms when applicable. Doing so not only strengthens the commitment but makes it easier to define and track meaningful performance indicators.
Once a PIC is clearly defined, the next step is to identify the appropriate units of measurement. These will vary depending on the nature of the commitment. For commitments related to DNS abuse, metrics might include average response time to abuse complaints, number of domains suspended per month due to confirmed abuse, or percentage of abuse reports closed within a defined timeframe. For content-related commitments, such as maintaining a family-friendly namespace or prohibiting hate speech, metrics could include the number of content complaints received, takedown rates, or third-party audit outcomes. Where a PIC involves community representation or support—such as commitments made by community-based applicants—metrics might include the number of stakeholder engagement meetings held per year, the publication frequency of community reports, or satisfaction ratings from advisory councils.
Establishing data collection and reporting mechanisms is critical to effective compliance. Registries must build or integrate systems capable of capturing relevant data points automatically and consistently. This often involves collaboration with registry service providers, abuse monitoring vendors, and compliance consultants to develop dashboards or data pipelines tailored to each PIC. For instance, integrating with ICANN’s Domain Abuse Activity Reporting (DAAR) system can offer foundational data on malware, botnets, and phishing trends within the TLD, while internal ticketing systems can track registrant interactions and complaint handling workflows. Data must be timestamped, categorized, and retained in accordance with applicable data protection regulations, ensuring both accuracy and legal compliance.
Transparency plays a key role in reinforcing the legitimacy of voluntary PICs. Publishing regular compliance reports—monthly, quarterly, or annually—allows registries to demonstrate performance against commitments in a verifiable manner. These reports should include not just raw metrics, but also contextual analysis, summaries of enforcement actions, and any corrective measures taken to address deficiencies. Ideally, reports are accessible to the public or at least to relevant stakeholder groups, including ICANN, the Governmental Advisory Committee (GAC), and trusted notifiers or community representatives. For sensitive or security-related metrics, data may be shared through restricted channels or anonymized to balance transparency with risk mitigation.
Independent auditing is another effective method for reinforcing credibility. Voluntary PICs that carry high public interest value—such as commitments to protect vulnerable groups, support linguistic minorities, or avoid discriminatory registration practices—may warrant third-party validation. This could take the form of annual audits conducted by certified compliance firms, peer reviews facilitated through ICANN stakeholder bodies, or performance assessments tied to recognized industry standards. Audit reports should clearly indicate whether the registry met its stated metrics, what evidence was reviewed, and whether any deviations were material. Where gaps are found, a remediation plan with time-bound actions should be included to demonstrate continuous improvement.
An often-overlooked component of PIC compliance is responsiveness to evolving norms and risks. Registries must recognize that voluntary PICs, once embedded in the Registry Agreement, become binding and enforceable by ICANN. However, changes in technology, legal standards, or stakeholder expectations may require updates to the implementation strategy or measurement approach. Therefore, registries should build flexibility into their compliance models by conducting annual reviews of their PICs and associated metrics, with input from internal legal, technical, and policy teams. If changes are needed to reflect new threats or community concerns, registries can submit amended commitments through ICANN’s established processes, provided they maintain the original spirit of the PIC.
It is also important to design enforcement workflows that are both effective and proportionate. When metrics reveal underperformance or noncompliance, registry operators must be prepared to act. This includes implementing remediation plans, reassigning responsibilities, or escalating systemic issues to ICANN Compliance if needed. For example, if a registry commits to blocking names associated with child exploitation and fails to do so consistently, it must demonstrate not only an acknowledgment of the issue but also a concrete corrective strategy. Registries that fail to monitor or enforce their own PICs may face enforcement actions from ICANN, damage to their brand, or erosion of trust among registrants and the broader internet community.
Finally, crafting compliance metrics should be seen not as a burden, but as a strategic advantage. In a crowded TLD market, voluntary PICs that are well-implemented and transparently measured can differentiate a registry and attract registrants who prioritize ethics, safety, and trust. This is particularly true in sectors such as healthcare, education, finance, and civic engagement, where public confidence is critical. By aligning voluntary commitments with robust metrics, registry operators signal maturity, accountability, and a commitment to stewardship that extends beyond commercial gain. They also contribute to a more resilient and trustworthy domain name system, consistent with ICANN’s mission and the public interest values that underpin global internet governance.
As the 2026 new gTLD program advances, the successful deployment of voluntary PICs with clear, enforceable compliance metrics will be one of the key differentiators for applicants aiming to establish credible, long-term, and community-aligned TLDs. Through strategic foresight, operational discipline, and a commitment to transparency, registry operators can ensure that their public interest promises translate into measurable, verifiable outcomes—thereby reinforcing trust not only in their own operations but in the broader integrity of the DNS itself.
You said:
As the 2026 new gTLD program opens the door for a new generation of top-level domains, applicants are once again faced with the opportunity—and in some cases, the strategic necessity—of incorporating Voluntary Public Interest Commitments, or PICs, into their applications. While mandatory PICs are now well established as contractual obligations designed to protect DNS stability…