Original research from the Cianaa team
Peer-visible, DOI-registered research on AI governance, ISO/IEC 42001 and the evolving legal landscape of artificial intelligence. Every paper is openly licensed and permanently citable.
Published papers
Authored by Cianaa’s assessment and certification team. Cite them, share them, build on them; attribution is all we ask.
Integrating Artificial Intelligence with Cybersecurity Governance: A Framework for Organizational Decision-Makers
Introduces the AI-Cybersecurity Governance Integration (ACGI) Framework from an analysis of 400+ studies, covering governance structures, risk management, EU AI Act compliance and implementation for organisations of all sizes.
AI-Based Phishing Attacks: A Socio-Technical Framework for Criminal Psychology and Forensic Investigation
A socio-technical framework, built from 238 sources, explaining how generative AI transforms phishing realism, attacker economics and forensic attribution, with practical guidance for security and investigation teams.
Credit Card Fraud in Australia: An Empirical Analysis of Physical versus Online Fraud, PCI DSS Challenges and Prevention
An empirical study of Australian fraud data (2020-2024) documenting the shift to card-not-present fraud, persistent PCI DSS implementation gaps, and the case for integrating compliance controls with technical detection.
GDPR Alignment with Japan’s APPI and ISO/IEC 27701: A Cross-Framework Data Protection Report
Analyses the convergence and gaps between GDPR, Japan’s APPI and ISO/IEC 27701, the EU-Japan adequacy decision, and how ISO 27701 operationalises a single harmonised privacy programme across both regimes.
Integrated Cybersecurity Framework Implementation: Evidence for Cost-Effective Multi-Standard Compliance
A mixed-methods study of 257 organisations implementing ISO 27001, PCI DSS, SOC 2, NIST 800-53 and the NIST CSF, showing integrated implementation delivers major cost savings and identifying 22-25 shared control components.
ISO/IEC 42001:2023 AI Management Systems: A Comprehensive Analysis of the World’s First International AI Governance Standard
Examines the standard’s significance, implementation framework and comparative positioning against the NIST AI RMF, ISO/IEC 23894 and IEEE 2857, with strategic insights for organisations considering adoption.
AI Governance Based on ISO/IEC 42001: A Comprehensive Framework for Managing AI Systems
Evidence-based strategies and practical frameworks for implementing responsible AI management systems under ISO/IEC 42001, from clause-level analysis to implementation challenges, benefits and future outlook.
ISO/IEC 42001 Compliance Assessment Framework
A six-component framework for evaluating ISO/IEC 42001 readiness and compliance: readiness assessment, gap analysis, clause-by-clause verification checklists, maturity scoring, implementation roadmap and monitoring dashboard.
The Evolution of the AI Legal Landscape: Regulatory Frameworks, Court Decisions and Future Implications (2019-2025 and Beyond)
Traces AI law from the 2019 Beijing Internet Court precedent to the regulatory maturation of 2024-2025, spanning landmark court decisions, ten national governance approaches, sector impacts and recommendations for policymakers and industry.
Work with the team behind the research
The same assessors who write about ISO/IEC 42001, AI governance and compliance run Cianaa’s certification and assessment engagements across New Zealand and Australia.
Book a scoping call →