Permanent concepts

The canonical definitions behind StackWeaver's trust infrastructure category. Each term answers: what it is, why it matters, how StackWeaver applies it, and what it relates to. These pages rarely change — they are reference definitions, not blog posts.

Why a Library

Compliance vocabulary drifts. "Continuous compliance" means one thing to a GRC vendor and another to an engineer. The Library fixes meaning: each concept is defined once, canonically, and every other page on the site links to it rather than redefining it. That is how a knowledge graph stays coherent as it grows past 500 pages.

How to read it

Start from Trust Infrastructure — the umbrella concept — then follow the related links outward into frameworks (TEOM, TEMM, Evidence Architecture) and capabilities (Compliance Engineering, Evidence-Native Systems). Each entry closes with a "related" trail into Solutions, Research, and Evidence.

What it is not

The Library is not the blog and not the research desk. It does not argue a position or report a finding; it defines. Evolving analysis — the State of Trust Infrastructure report, platform evaluations, the automation-vs-consulting debate — lives in Research.

The StackWeaver perspective

Every definition here is written from one stance: compliance is infrastructure, not theatre. A control that cannot produce evidence of its own operation is not a control. That conviction runs through every term below and into the platform that operationalises them.

Foundational

Frameworks

StackWeaver's core frameworks: how trust infrastructure is run (TEOM), how maturity is measured (TEMM), and how evidence is created, connected, and verified (Evidence Architecture). These canonical models ground every practice and solution on this site.

Practice

Compliance Engineering

Treating compliance as something built into systems through engineering -- enforced, tested, and monitored -- rather than added through documentation.

Continuous Compliance

A state in which compliance evidence is generated and verified continuously, so readiness is always current rather than reconstructed for each audit.

Compliance-as-Code

Expressing compliance controls and policies as versioned, testable code in the engineering pipeline.

Compliance Automation

The use of software to collect evidence, enforce controls, and monitor compliance state with minimal manual effort.

Engineering Controls

Controls implemented and enforced through engineering systems -- configuration, code, and automation -- rather than through policy and manual process.

Audit Readiness

The state of being able to satisfy an audit or due-diligence request on demand, with current, mapped, and verifiable evidence.

AI Compliance

The discipline of governing AI systems -- model risk, data provenance, and human oversight -- with the same engineered, evidenced controls used for traditional compliance.

DevSecOps Compliance

Embedding compliance controls and evidence capture directly into the software delivery pipeline, so security and compliance are properties of shipping, not gates before it.

CBN AML/CFT Compliance

The Central Bank of Nigeria's Anti-Money Laundering and Counter-Terrorism Financing framework -- mandatory for all Nigerian financial institutions and fintechs, requiring transaction monitoring, KYC/CDD, sanctions screening, and STR/CTR filing via NFIU GoAML.

NDPA Compliance (Nigeria Data Protection Act)

The Nigeria Data Protection Act 2023 framework -- mandatory for all data controllers and processors in Nigeria, requiring data-subject rights (DSAR), lawful basis, data protection impact assessments (DPIA), breach notification to NDPC, and data protection officer (DPO) appointment.

Fintech Regulatory Compliance

The multi-framework compliance posture required of regulated fintechs -- CBN AML/CFT, NDPA, SOC 2, PCI DSS, and ISO 27001 -- engineered as a unified evidence base rather than separate silos.

Systems

Start with the category

If you are new to the model, begin at Trust Infrastructure — the umbrella concept everything else hangs from — then explore the terms (TEOM, TEMM, Evidence Architecture) that operationalise it. Evolving knowledge — reports, analysis, and buying guides — lives in Research.