Early access opens October 1, 2026
Audit Readiness · Governed AI · Advisory

The future of audit readiness.

We help compliance teams build control environments that hold up under scrutiny — readiness assessments led by Big 4-trained practitioners, and software where every AI answer carries its citations and a human review.

4
Applications
Oct 1
Early Access
5
Founder Certifications
The Applications
ApplicationWhat it isStatus
Kodama Hub Enterprise risk management — live in production LIVE Customer sign-in →
AI Compliance Workbench Cited answers · human review · evidence packs EARLY ACCESS OCT 1 Product wiki →
Kodama Forge Specialist audit agents, built to written specifications WAVE 1 · DEC 1 The catalog →
Scam Tricker An AI that wastes scam callers' time — not your family's TRIAL TARGET DEC 15 The pages →
Kodama Hub is live for customers today. The other dates are targets, and we say so everywhere they appear.
What We Do

Audit readiness, end to end.

Readiness assessments led by Big 4-trained practitioners, with software that keeps every AI-assisted step cited, reviewed, and evidenced. We prepare you for the audit — we don't perform it.

01Readiness
IT SOX / ITGC Readiness
Readiness assessment across access, change management, operations, and SDLC — the control domains examiners and external auditors test — with findings and a practical remediation roadmap.
ITGC · SOX 302/404 · FDICIA
02Preparation
Certification Preparation
SOC 2 and ISO 27001 readiness: gap assessment against the criteria your auditor or certification body will apply, evidence preparation, and remediation support before they arrive.
SOC 2 · ISO 27001
03ERP
ERP Security & SoD
Security configuration and segregation-of-duties reviews across SAP, Oracle, Workday, and NetSuite — role conflicts mapped to financial risk, with remediation that operations can live with.
SAP · Oracle · SoD
04Cyber
Cybersecurity Readiness
Assessments anchored to the NIST Cybersecurity Framework and the FFIEC IT Examination Handbook — the lens regulators actually apply to financial institutions.
NIST CSF · FFIEC
05AI Governance
AI Governance Readiness
Extend audit coverage over AI systems entering production, leveraging the NIST AI Risk Management Framework and ISO/IEC 42001.
NIST AI RMF · ISO/IEC 42001
06Software
Governed AI Software
The AI Compliance Workbench: policy questions answered with validated citations into your own documents, human review on every output, and examiner-ready evidence packs.
Cited Answers · Human Review · Evidence
Who We Are

Big 4 rigor. AI-native precision.

Kodama Mirai Inc. builds audit-readiness technology and provides readiness advisory. Founded by a Big 4-trained practitioner, we help organizations prepare their control environments for the scrutiny of regulators, external auditors, and adversaries — with software where every AI-assisted step is cited, human-reviewed, and evidenced.

KODAMA
A name rooted in the Japanese concept of deep, present intelligence — the idea that wisdom exists within natural systems, quietly processing what others overlook. Our work embodies this philosophy: methodical, thorough, ever-present.
KOMOREBI
Sunlight filtering through a forest canopy — the kind of insight we deliver: not blunt illumination, but precise, dappled clarity that reveals exactly what needs to be seen.
MIRAI
Future. We are building the future of enterprise assurance — quietly, precisely, and continuously.
Founder
Innocent Githua Muchiri
Big 4 — EY, PwC, Deloitte, KPMGCareer
Protiviti · Crowe · VacoConsulting
SOX 302/404 & FDICIA programsLed
ERP security & SoD — SAP, Oracle, Workday, NetSuiteReviews
AI governance — NIST AI RMF, ISO/IEC 42001Focus
MBA · CISA · CRISC · CISM · CAMS · CFECredentials
Innocent Githua Muchiri
Founder & CEO
MBACISACRISCCISMCAMSCFE
"Control environments should hold up under scrutiny — whether it comes from a regulator, an external auditor, or an adversary."

A career across the Big 4 (EY, PwC, Deloitte, and KPMG) and global consulting firms including Protiviti, Crowe, and Vaco — SOX 302/404 and FDICIA programs, NIST CSF assessments, ERP security and segregation-of-duties reviews, and consent-order remediation for a Tier-1 financial institution. Recent focus: the governance of artificial intelligence under the NIST AI RMF and ISO/IEC 42001. The full profile is on the wiki →

Our Approach

How we think about audit.

01
Human-Reviewed AI
AI accelerates the work; a person owns it. In our software, nothing an AI produces is final until a human reviews and approves it — and the record shows who did.
02
Structured Methodology
We work from the frameworks your assessors actually use — ISACA practices, COBIT, NIST CSF, the FFIEC IT Examination Handbook — so readiness maps one-to-one onto what gets tested.
03
Evidence Chain
Every AI answer in the Workbench carries validated citations to its exact sources, preserved immutably at generation time — reviewable by a human at any point, exportable as an evidence pack.
Services

Everything readiness actually requires.

From scoping to the remediation roadmap, a practitioner leads every engagement — with AI assistance that stays cited, reviewed, and on the record.

01
Scope
Define the systems, control domains, and framework criteria your assessment will be measured against.
02
Test Plan
A tailored readiness test plan: controls, procedures, and the evidence each one requires.
03
Assess
Practitioner-led testing with AI-assisted evidence collection — every finding tied to its evidence.
04
Report
A readiness report in the format your auditors and examiners are used to reading: findings, ratings, recommendations.
05
Remediate
A prioritized remediation roadmap, with re-testing support until the gaps are closed.
Coverage
Frameworks we work in
FrameworkDomainHow we support it
IT SOX / ITGC (SOX 302/404, FDICIA)Financial ControlsReadiness assessment and remediation across ERP, cloud, and infrastructure
NIST CSF 2.0 & FFIEC IT HandbookCybersecurityAssessments in the frameworks financial-institution examiners apply
SOC 2Security & AvailabilityReadiness and evidence preparation ahead of your auditor's examination
ISO 27001Information SecurityPre-certification gap assessment and preparation
NIST AI RMF & ISO/IEC 42001AI GovernanceExtending audit coverage over AI systems entering production
COBIT & ISACA practicesIT GovernanceThe methodological backbone of our readiness work
We prepare organizations for audits and certifications. We are not a licensed CPA firm and do not issue SOC 2 opinions, ISO certificates, or attestation reports.
IT SOX Readiness

Sarbanes-Oxley readiness for the modern enterprise.

IT General Controls work is among the most time-intensive parts of SOX. We get you ready for it — practitioner-led ITGC readiness assessments, AI-assisted where it helps and human-reviewed everywhere, across the ERP platforms and infrastructure your auditors will test.

Platform coverage — practitioner experience
SAPOracleWorkdayNetSuiteOthers on request
AWSMicrosoft AzureGoogle Cloud
Active Directory / Entra IDOktaSQL ServerOracle DB
ITGC control domains
01Access to Programs and Data
02Change Management Controls
03Computer Operations Controls
04System Development Lifecycle (SDLC)
05Logical Security & User Provisioning
06Segregation of Duties (SoD)
07Backup & Recovery Controls
08Incident & Problem Management
09Patch & Vulnerability Management
10Third-Party & Vendor Management
ITGC Readiness Coverage

Every ITGC domain, readiness-tested.

01Access
Access & Identity
Logical access readiness across ERP and infrastructure — user provisioning and de-provisioning, privileged access, role assignments, and SoD conflicts, with the evidence each control requires.
Access Controls · SoD · Privileged Access
02Change
Change Management
Change process readiness — approval workflows, testing evidence, emergency change procedures, and segregation of developer and production access.
Change Mgmt · SDLC · Approvals
03Operations
Computer Operations
Job scheduling, batch processing, backup and recovery procedures, incident management, and operational monitoring — reviewed the way your auditor will review them.
Backup · Recovery · Job Scheduling
04ERP
ERP Configuration
Security configurations, table-level controls, authorization objects, and financial module settings across SAP, Oracle, Workday, and NetSuite.
SAP · Oracle · Workday
05SoD
Segregation of Duties
SoD conflict analysis across ERP roles and user profiles, mapped to financial risk, with remediation recommendations that operations can actually implement.
SoD Matrix · Role Analysis · Risk
06Reporting
Readiness Reporting
Findings synthesized into an ITGC readiness report in the format auditors are used to reading — control descriptions, test procedures, evidence listings, exceptions, and remediation plans.
Section 404 · Reporting
Readiness Lifecycle

From scoping to remediation.

01
Scoping
Define in-scope systems, financial processes, and control objectives aligned with Section 302 and 404 requirements.
02
Risk Assessment
Identify key IT dependencies and map financial risks to ITGC control areas across all in-scope systems.
03
Testing
Practitioner-led control testing with AI-assisted evidence collection across access, change, operations, and configuration domains.
04
Exceptions
Gaps classified the way your auditor will classify them — control deficiencies, significant deficiencies, material weaknesses — with supporting evidence.
05
Report
An ITGC readiness report with executive summary, findings register, remediation roadmap, and re-testing schedule.
Kodama Hub

Enterprise risk management, live in production.

Kodama Hub is our ERM platform, operating in production for customer use.

01Risk
Risk Register & Scoring
A living risk register with weighted component scoring, composite risk bands, and quantified scenario analysis for financial exposure.
Risk Register · Scoring
02Readiness
NIST CSF 2.0 Readiness
A structured readiness assessment engine over the NIST Cybersecurity Framework — maturity scoring, findings with remediation tracking, and examiner-ready reporting packs.
NIST CSF 2.0 · Assessments
03Review
Reviewed, Not Just Recorded
Maker-checker review workflows: assessments and findings pass through an assigned reviewer before they're final, with the audit trail to prove it.
Maker-Checker · Audit Trail
Customer Sign-in Request a Demo

The Hub is a protected customer environment — the sign-in gate is what you should expect to see. Not a customer yet? Request a demo and we'll show it to you live.

Kodama Forge · The Agent Factory

Specified, not shipped — until they ship.

Kodama Forge is where our specialist audit agents are built: 158 agents specified across 24 audit and compliance domains — specialists rather than generalists, in every area we test — sequenced in four waves.

158
Agents Specified
24
Domains
13
In Wave 1
Dec 1
Wave 1 GA Target
Scope and sequencing on this page are current as of September 2026 and describe work in specification and build. Wave 1 is a target date; later waves are sequenced and not yet dated. Agent counts are what has been specified, not what is in production today — there is nothing to deploy yet. We will update this page as each wave enters build.
Coverage

Six areas. A specialist for each.

The programme gives each domain a specialist rather than a generalist. Agent counts below are what is specified and budgeted, not what is shipped.

26 AGENTS3 domains
IT SOX & ITGC
ERP-specific and cross-platform ITGC, plus the financial close and reporting platforms that carry the numbers.
Spec — fixed schemaSpecified
21 AGENTS4 domains
Cloud, Infrastructure & Identity
Cloud platform configuration, operating system and network hardening, identity and access governance, and CI/CD pipeline control.
Spec — fixed schemaFirst in build
16 AGENTS3 domains
Security & Application Assurance
Cybersecurity control testing, application security review, and payment security under PCI DSS v4.
Spec — fixed schemaSpecified
29 AGENTS4 domains
Attestation & Standards
SOC 1 and SOC 2 readiness and testing, the ISO 27000 family, and the NIST frameworks.
Spec — fixed schemaSpecified
38 AGENTS5 domains
Regulatory & Privacy
Financial institution regulatory examination readiness, healthcare compliance, privacy and data protection, international regimes, and enterprise risk governance.
Spec — fixed schemaSpecified
28 AGENTS5 domains
Platforms, Data & AI Governance
SaaS and business applications, data and analytics platforms, HR and payroll, AI governance, and the reporting and advisory layer.
Spec — fixed schemaSpecified
Sequence

Four waves. One dated.

We date the wave we can stand behind. The rest are sequenced and will be dated as each one enters build.

WAVE 1 · 13 AGENTS
Cloud and ITGC core
The agents everything else depends on — cloud platform testing and the core ITGC set.
TARGET DEC 1, 2026
WAVE 2 · 58 AGENTS
Attestation, regulatory and identity
SOC 1 and SOC 2, the ISO 27000 family and the NIST frameworks, financial institution regulatory, and identity governance.
SEQUENCED
WAVE 3 · 66 AGENTS
Platform depth, privacy and international
ERP and SaaS specialists, data platforms, privacy regimes, and regional regulatory coverage outside the United States.
SEQUENCED
WAVE 4 · 21 AGENTS
Advisory, synthesis and emerging technology
Report synthesis, board-level advisory, and the AI governance agents that assess AI systems themselves.
SEQUENCED
Method

How these agents are built.

Regulation moves faster than model training. Four commitments follow from that, and they shape every agent in the programme.

01
Retrieval over fine-tuning
Regulatory knowledge lives in a versioned corpus, not baked into model weights. When a standard is superseded we update the corpus, not the model — no retraining cycle stands between a rule change and a correct answer.
02
Withdrawn guidance is blocked
A model trained on fifteen years of a superseded standard will reach for it over its months-old replacement. Every affected agent is specified with a retrieval filter that excludes withdrawn documents, and an acceptance test that fails the agent for citing one.
03
A human review gate on every agent
Each agent has a defined point at which a qualified reviewer signs off. No finding will reach a client deliverable without passing it. The gate is part of the specification, not a policy bolted on afterwards.
04
Open weights, our own environment
Models run on infrastructure we control, chosen for licences that permit commercial audit-readiness work. Client evidence is never used to train a model — not ours, and not a third party's.
Where We Are Today

The groundwork is done.

A roadmap is only worth reading if the foundations under it are real. Here is what already exists.

GroundworkWhat existsStatus
A rebuilt ITGC work plan library Platform audit work plans across ERP, cloud, database and infrastructure, rebuilt against current standards, with every test traced to its control and framework. COMPLETE
Full build specifications All 158 agents specified to a fixed schema — purpose, retrieval sources, output contract, acceptance tests and review gate — ahead of build, so the build has a fixed target to hit. COMPLETE
The first agent services Cloud audit agent services are in build against those specifications. Wave 1 is where the first of them reach general availability. IN BUILD
Stay Tuned

Be there when Wave 1 lands.

Early access opens ahead of December 1 for a small number of design partners: first access to Wave 1 agents, and input on what ships in Wave 2. One update per wave — we are not going to fill your inbox.

Contact

Start the conversation.

Tell us about your organization and what you're preparing for. A person reads and answers every message — no automated sequences.

Emailenable JavaScript for the email link
OperationsRemote-first, United States
"Like light through a forest canopy — we illuminate what was always there."
— Kodama Mirai philosophy
Fastest paths

For demos, early access, and partnership conversations, use the request form on the wiki — it routes your message with the right context attached. For anything else, email or call.

Request a Demo or Early Access → Email Us

Early access to the AI Compliance Workbench opens October 1, 2026.