What about the security angle? The registrar should log these transactions with the IP address and probably the UA string so they can tell the customer what computer they were using when they did it. And if it wasn't them, then investigate how their password was stolen or security was breached.
Does your registrar log information like this?