Independent researcher | AI assurance | OT and ICS security

Research led AI governance for critical infrastructure

I develop research, frameworks, and assurance models for governing AI in high impact operational environments, with a focus on the electric sector, OT/ICS cybersecurity, and cyber physical AI risk.

Suhail Ahmad Rana
AAIGF E Author111 control electric sector AI governance framework
IEEE and ISA Senior MemberResearch and standards engagement
CISM, CISA, CRISCCybersecurity governance and risk
AAIA, AAISMAI audit and AI security management

Research focus

My work sits at the operational seam between AI assurance and ICS cybersecurity, where governance must become testable, auditable, and useful to operators, asset owners, and assurance teams.

01

Electric sector AI governance

Governance and assurance controls for AI systems used in load forecasting, DER coordination, contingency assessment, and operational decision support.

02

OT and ICS AI risk

Research into how agentic and adaptive AI systems interact with operational data, cyber physical processes, and industrial control environments.

03

Framework and control mapping

Mapping AI governance needs to NERC CIP, MITRE ATLAS, NIST AI RMF, ISA IEC 62443, and related assurance frameworks.

AAIGF E

The Adaptive AI Governance Framework for the Electric Sector is a research based framework designed to make AI governance auditable and operationally relevant inside the Bulk Electric System.

111Controls
11Risk domains
7Lifecycle anchors
4+Framework mappings

Framework position

AAIGF E addresses a structural gap in how AI is governed inside electric sector operational environments. It is designed to sit alongside existing compliance rhythms, not replace them.

Lifecycle anchorsGovern, Design, Implement, Assure, Monitor, Respond, and Recover.
Mapped controlsAligned to NERC CIP, MITRE ATLAS, NIST AI RMF, and ISA IEC 62443.
Operational contextFocused on AI systems that may influence operational decisions in high impact environments.

Research led advisory

I am open to business and consulting inquiries where the work is connected to my research: AI governance, OT/ICS security, electric sector assurance, cyber physical AI risk, and control level framework mapping.

A

AI governance reviews

Reviewing AI governance models, assurance controls, policy to control traceability, and gaps in high impact AI deployment plans.

B

OT/ICS AI risk workshops

Structured sessions on agentic AI risk, operational data trust, cyber physical threats, and assurance design for OT environments.

C

Framework mapping and assurance

Mapping AI governance requirements to NERC CIP, NIST AI RMF, ISA IEC 62443, MITRE ATLAS, ISO 42001, and internal controls.

Professional background

  • Cybersecurity GRC and AI assurance across IT, OT, and the energy sector
  • Certified CISM, CISA, CRISC, AAIA, and AAISM
  • Accredited ISO 42001 and ISO 27001 Lead Implementer and Auditor
  • Senior Member of IEEE and ISA
  • Active member and mentor with ISACA
  • Participant in the IEEE P3396 working group on AI risk and impact assessments

Research and collaboration

The AAIGF E preprint and related work are available through SSRN and Google Scholar. I welcome discussion with utilities, national labs, researchers, standards contributors, and organizations working on responsible AI deployment in critical infrastructure.

Open to research aligned advisory inquiries

If your work involves NERC CIP compliance, OT/ICS security, AI deployment at a utility, smart infrastructure assurance, cyber physical AI risk, or AI governance research, I would value a conversation.

Connect on LinkedIn