The AI Compliance Workbench
Governed AI for compliance teams at regional banks and credit unions. The Workbench answers policy questions with citations into your own documents, keeps a human reviewer in front of every AI output, and produces evidence packs you can hand to an examiner.
Early access & demos — Oct 1, 2026 See the evidence
What it does
- Cited answers, or no answer. Ask a policy question; the answer cites the exact passages it came from in your document corpus. Citations are validated before an answer is ever shown — an answer that cannot support itself is rejected, and when the evidence isn’t there, the Workbench says so and names what’s missing instead of guessing.
- A human in front of everything. AI output enters the same draft-review-approve workflow your team already runs. Nothing is final until a person approves it, and every step lands in a tamper-evident audit trail.
- Evidence that survives. Every AI answer is recorded with the question, the exact passages it relied on, and the model that produced it — frozen at the moment of generation. Evidence packs export as PDFs built for examiner and auditor review.
- Workflow kill switches. An administrator can disable any AI workflow instantly, mid-stream included.
- Your data stays yours. AI runs on local model infrastructure only — no third-party AI APIs. Documents, questions, and answers never leave the environment the institution controls.
What we are — and what we are not
Kodama Mirai builds audit-readiness software and advisory. We help compliance teams prepare, document, and evidence their control environment. We are not a licensed CPA firm and we do not issue SOC 2 opinions, ISO certifications, or attestation reports — your auditors and certification bodies do that. Our job is that when they arrive, you’re ready.
The applications
Kodama Hub — our enterprise risk management platform, live in production: risk register and scoring, controls, NIST CSF 2.0 readiness assessment with maker-checker review workflows, and executive reporting. Kodama Hub — customer sign-in (the Hub is a protected customer environment; the sign-in page is what you should expect to see).
AI Compliance Workbench — this page. Version 1 complete September 2026; early access opens October 1, 2026.
Kodama Forge — our agent factory: specialized IT-controls audit agents built to written specifications, with the same evidence discipline as everything else we ship. Wave 1 general availability is targeted for December 1, 2026; agents are specified, not shipped, until they ship.
Scam Tricker — an AI persona that answers scam calls so a real person never has to, and keeps the caller talking. Privacy-first and fail-closed by design; today a working simulated demo, with a limited real-call trial targeted for December 15, 2026, pending legal review. The Scam Tricker pages.
Founder
Innocent founded Kodama Mirai to help organizations build control environments that hold up under scrutiny — whether that scrutiny comes from a regulator, an external auditor, or an adversary. His career spans 14+ years across the Big 4 (EY, PwC, Deloitte, and KPMG) and global consulting firms including Protiviti, Crowe, and Vaco, advising Fortune 500 companies and Tier-1 financial institutions as a trusted advisor to C-suite and audit-committee stakeholders: end-to-end SOX 302/404 and FDICIA programs, NIST CSF cybersecurity assessments, ERP security and segregation-of-duties reviews, and IT risk framework remediation for a Tier-1 financial institution operating under a consent order. His recent focus is the governance of artificial intelligence, applying the NIST AI Risk Management Framework and ISO/IEC 42001, following a postgraduate program in AI and machine learning at The University of Texas at Austin.
SOX 302/404 · ITGC · application & automated controls · key reports & IPE · FDICIA · PCAOB & SEC · SOC 1 / SOC 2 · OCC & FDIC · HIPAA · PCI DSS
NIST CSF & 800-53 · ISO 27001/27002 · MITRE ATT&CK · FFIEC · ERM & IT GRC · COSO & COBIT · third-party & vendor risk · PAM/IAM & SoD · threat-centric risk assessment
SAP S/4HANA · Oracle E-Business Suite · JD Edwards · Workday · NetSuite · AWS · Azure · GCP · ACL · Tableau · Power BI · CAATs
Engagement & program management · executive reporting (CIO/CISO/CFO/audit committee) · regulatory remediation · team leadership & training
Contact
General inquiries: enable JavaScript for the email link
Phone: 1‑833‑KODAMA7
Demos, early access, and partnerships: the request form.
KODAMA