Regulation-anchored competency engineering (RACE): A foundational framework for a living science of cyber-technology education

Philippe Funk 1, 2, *

1 Business Administration, Information Technology and Cybertech, Signum Magnum College (SMC), Portomaso Business Centre, Portomaso, St. Julians PTM 01, Malta.
2 Polytechnic Cyber Institute, 3, rue Nicolas Petit, L-2326 Luxembourg, Grand Duchy of Luxembourg.
Research Article
Open Access Research Journal of Science and Technology, 2026, 17(02), 008–017.
Article DOI: 10.53022/oarjst.2026.17.2.0069
Publication history: 
Received on 09 June 2026; revised on 14 July 2026; accepted on 17 July 2026
 
Abstract: 
Curricula in cybersecurity, artificial intelligence governance, and data protection begin to age the moment they are approved. A module written against the regulations in force in one academic year is, by its second delivery, teaching a snapshot; by its third, nobody can say precisely which parts have gone stale without rereading everything. I argue that this is not primarily a problem of academic effort or funding, but of modelling. We have no formal representation of what a curriculum is anchored to, so we cannot compute what has changed. This paper proposes regulation-anchored competency engineering (RACE), which treats regulatory and competency obligations as dated, versioned artifacts that curricula are compiled from, rather than as background documents consulted occasionally. RACE adds a fourth vertex to constructive alignment: alongside learning outcomes, teaching activities, and assessment, there is an explicit obligation layer to which all three must be traced. Curricula then become typed property graphs across five layers, namely regulation, competency, outcome, activity and assessment. Three things follow: a drift metric that quantifies curriculum obsolescence, a continuous-integration discipline called CurriculumOps that flags affected courses when an upstream instrument changes, and compilation of syllabi and traceability matrices from the source. Generality is demonstrated through anchor maps for two domains and two complete module compilations, one in cybersecurity risk assessment and one in AI governance. The framework is conceptual and analytically evaluated. It has not yet been piloted, and I set out what would count as evidence for and against it.
 
Keywords: 
Curriculum engineering; Competency-based education; Constructive alignment; Regulatory compliance; Cybersecurity education; Artificial intelligence governance
 
Full text article in PDF: