Compliance-as-Code for Regulated African Banking
DOI:
https://doi.org/10.64751/Abstract
nfrastructure-as-Code (IaC) has made cloud provisioning fast and repeatable, and a substantial body of work now embeds compliance checks directly into IaC pipelines. Almost all of that work, however, is anchored to NIST, ISO, CIS, or GDPR control sets calibrated to North American and European regimes. Banks supervised by African central banks, most notably the Central Bank of Nigeria (CBN), face supervisory obligations on data residency, access accountability, and continuous auditability that these control sets do not name, leaving institutions to bridge the gap by hand at audit time. This paper presents a compliance-as-code approach in which CBN supervisory expectations are expressed as machine-evaluable policy and enforced as a gate inside the Terraform and AWS CloudFormation deployment pipeline, so that no resource can be provisioned outside the control envelope and clause-level audit evidence is produced automatically. The approach is grounded in a production landing-zone product that reduced infrastructure provisioning time by 45%, eliminated configuration drift across managed environments, and embedded automated compliance controls into every deployment pipeline. We describe the policy architecture, an obligation model, a mapping from CBN expectations to policy rules with worked Rego and CloudFormation Guard examples, an evidence-record schema, and an evaluation of provisioning time, drift, control coverage, and gate latency. The contribution is an emerging-market-regulator compliance-as-code pattern that other African financial institutions can adopt directly, accompanied by reusable appendices.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.







