Questions
Scepticism is the job — so here are straight answers about what the AI does, what it never does, and what happens to your clients' data.
What the co-auditor does — and the line it never crosses.
A platform that automates the mechanical work of a compliance audit — mapping evidence to controls, detecting gaps, drafting findings and generating deliverables — while a human auditor keeps every decision, including severity and final sign-off. The word co-auditor is the point: it works alongside you, it doesn't audit for you.
No. Kimova drafts and suggests — every judgment call is yours. It never sets a severity, closes a finding or signs off a cycle on its own, and you can change anything it proposed.
Yes — and it holds up better than most hand-typed work. Every AI output carries its model, rationale and source, sits in a field separate from your edits, and has a named human signature on it. That makes it more traceable, not less: you can always show what the machine suggested, what a person changed, and why.
Always. Every AI output is labelled with the model that produced it and carries its rationale and the source it drew on — the requirement, the document and the passage. You can check the machine's work rather than take it on faith, and nothing is final until a human approves it.
Fitting Kimova to your methodology, not the other way round.
ISO 27001, SOC 2 Type II, ISO 42001, ISO 9001 and ISO 27701 as lead frameworks — plus any framework you bring, mapped to controls by the agentic framework decoder.
No. You load your own finding templates, label sets, severity scales and default owners once, and every engagement starts from your firm's standard. Kimova captures your methodology rather than imposing ours.
Both, with different shapes. Firms run every client engagement from one account, each in its own sealed workspace, reusing one methodology across the book. In-house teams use it to get audit-ready — spotting policy gaps early and keeping evidence, findings and sign-off in one place.
Isolation, access and the trail behind every action.
Yes — separated at the database layer, not just hidden behind a filter in the UI. One client's users can never reach another's data, and every access is logged.
Yes — it's what the platform is built for. Partners run the whole book from one account, while each client stays sealed in its own workspace, with reusable templates and label sets shared across them.
Yes. An auditee sees only the tasks assigned to them — not the control register, not other findings, not the rest of the engagement. You can bring a client into the tool without opening the audit to them.
What the first week actually looks like.
You can create a workspace, pick a framework and start loading evidence on day one. The control register is generated for the framework you choose, so there's no checklist to build by hand before you begin.
A scoped walkthrough on your own framework, then loading your methodology — finding templates, label sets and default owners — so your first cycle starts from your firm's standard rather than a generic one. Custom plans include guided onboarding.
More answers
How pricing scales, how AI usage is metered, pilots, and what happens to your data if you leave.
Pricing FAQAuditing a standard we don’t list, whether Kimova certifies you, and what’s ever paywalled.
Framework FAQA person reads every message. You’ll usually hear back within one business day.
Contact us