Research & Publications

Original research from the Cianaa team

Peer-visible, DOI-registered research on AI governance, ISO/IEC 42001 and the evolving legal landscape of artificial intelligence. Every paper is openly licensed and permanently citable.

DOI-registeredOpen access · CC BY 4.0Indexed via Zenodo (CERN)

Published papers

Authored by Cianaa’s assessment and certification team. Cite them, share them, build on them; attribution is all we ask.

Research report · AI Governance

Integrating Artificial Intelligence with Cybersecurity Governance: A Framework for Organizational Decision-Makers

Dr Rizwan Ahmad · Mehar un Nisa · Noor Ul Ain Ali
January 2026 · Cianaa Technologies, Auckland

Introduces the AI-Cybersecurity Governance Integration (ACGI) Framework from an analysis of 400+ studies, covering governance structures, risk management, EU AI Act compliance and implementation for organisations of all sizes.

Research report · Cybersecurity & Forensics

AI-Based Phishing Attacks: A Socio-Technical Framework for Criminal Psychology and Forensic Investigation

Dr Rizwan Ahmad · Mehar un Nisa · Noor Ul Ain Ali
2026 · Cianaa Technologies, Auckland

A socio-technical framework, built from 238 sources, explaining how generative AI transforms phishing realism, attacker economics and forensic attribution, with practical guidance for security and investigation teams.

Research report · Payment Security

Credit Card Fraud in Australia: An Empirical Analysis of Physical versus Online Fraud, PCI DSS Challenges and Prevention

Dr Rizwan Ahmad · Mehar un Nisa · Noor Ul Ain Ali
October 2025 · Cianaa Technologies, Auckland

An empirical study of Australian fraud data (2020-2024) documenting the shift to card-not-present fraud, persistent PCI DSS implementation gaps, and the case for integrating compliance controls with technical detection.

Research report · Privacy & Data Protection

GDPR Alignment with Japan’s APPI and ISO/IEC 27701: A Cross-Framework Data Protection Report

Dr Rizwan Ahmad · Mehar un Nisa · Noor Ul Ain Ali
December 2025 · Cianaa Technologies, Auckland

Analyses the convergence and gaps between GDPR, Japan’s APPI and ISO/IEC 27701, the EU-Japan adequacy decision, and how ISO 27701 operationalises a single harmonised privacy programme across both regimes.

Research report · Multi-Standard Compliance

Integrated Cybersecurity Framework Implementation: Evidence for Cost-Effective Multi-Standard Compliance

Dr Rizwan Ahmad · Mehar un Nisa · Noor Ul Ain Ali
September 2025 · Cianaa Technologies, Auckland

A mixed-methods study of 257 organisations implementing ISO 27001, PCI DSS, SOC 2, NIST 800-53 and the NIST CSF, showing integrated implementation delivers major cost savings and identifying 22-25 shared control components.

Research report · AI Governance

ISO/IEC 42001:2023 AI Management Systems: A Comprehensive Analysis of the World’s First International AI Governance Standard

Dr Rizwan Ahmad · Mehar un Nisa · Noor Ul Ain Ali
August 2025 · Cianaa Technologies, Auckland

Examines the standard’s significance, implementation framework and comparative positioning against the NIST AI RMF, ISO/IEC 23894 and IEEE 2857, with strategic insights for organisations considering adoption.

Research report · AI Governance

AI Governance Based on ISO/IEC 42001: A Comprehensive Framework for Managing AI Systems

Dr Rizwan Ahmad · Mehar un Nisa · Noor Ul Ain Ali
August 2025 · Cianaa Technologies, Auckland

Evidence-based strategies and practical frameworks for implementing responsible AI management systems under ISO/IEC 42001, from clause-level analysis to implementation challenges, benefits and future outlook.

Research report · Assessment Methodology

ISO/IEC 42001 Compliance Assessment Framework

Dr Rizwan Ahmad · Mehar un Nisa · Noor Ul Ain Ali
August 2025 · Cianaa Technologies, Auckland

A six-component framework for evaluating ISO/IEC 42001 readiness and compliance: readiness assessment, gap analysis, clause-by-clause verification checklists, maturity scoring, implementation roadmap and monitoring dashboard.

Research report · AI Law & Policy

The Evolution of the AI Legal Landscape: Regulatory Frameworks, Court Decisions and Future Implications (2019-2025 and Beyond)

Dr Rizwan Ahmad · Mehar un Nisa · Noor Ul Ain Ali
July 2025 · Cianaa Technologies, Auckland

Traces AI law from the 2019 Beijing Internet Court precedent to the regulatory maturation of 2024-2025, spanning landmark court decisions, ten national governance approaches, sector impacts and recommendations for policymakers and industry.

How to cite: every paper carries a permanent Digital Object Identifier (DOI) registered through Zenodo, the open research repository operated at CERN. Click any DOI badge for the full citation in your preferred format. All papers are licensed CC BY 4.0: free to share and adapt with attribution. Our applied guidance lives alongside this research in whitepapers and insights.

Work with the team behind the research

The same assessors who write about ISO/IEC 42001, AI governance and compliance run Cianaa’s certification and assessment engagements across New Zealand and Australia.

Book a scoping call →