Most boards now have an AI policy problem. The real one sits underneath it, in how decisions actually get made.
Ninety-two per cent of board directors now use AI in their board work, up from sixty-nine per cent a year earlier. Sixty per cent of them sit on boards with no formal policy on how to use it. A separate review of more than three thousand US companies found that only eight per cent disclosed board-level AI oversight.
Mitzi Danielson-Kaslik has built her consultancy, VERITAS, on the years she spent inside compliance functions watching that exact kind of gap. Boards do not usually lack policies, she says. They lack a clear view of how decisions actually get made underneath the ones they have.
The mistake, in her view, is to treat governance as a paperwork problem rather than a decision-making one. What follows is how she reads that gap, and what she tells boards to fix before they touch another policy document.
In Brief

Mitzi Danielson-Kaslik is a Douglas, Isle of Man-based governance, risk and compliance consultant and the founder and chief consultant of VERITAS. VERITAS is an independent governance, risk and compliance consultancy providing board advisory, governance and risk consulting, remediation and training for regulated organisations working through financial crime, operational resilience, AI governance and geopolitical risk. She built her early career across compliance roles before founding VERITAS in 2026, and holds the ICA Outstanding Achievement Award in Anti-Money Laundering. “Governance shouldn’t live in a policy document. It should live in the decisions an organisation makes,” she says.
The Difference Between Having Governance and Being Governed
Ask Danielson-Kaslik what she sees most often, and it isn’t a missing policy. It’s a policy that nobody is actually using.
One of the biggest mistakes I see is confusing having governance with being well governed. An organisation can have an immaculate policy suite, beautifully documented committees and every required box ticked, while the actual decisions being made inside the business bear very little relationship to any of it. I tend to become interested in the gap between what an organisation says happens and what actually happens. Who really makes the decision? What information did they have when they made it?
That gap is where she works. Not whether a framework exists, but whether anyone inside the organisation could explain, after the fact, why a decision was reasonable.
Start With the Decision, Not the Technology
She started out in compliance, and the question she asks now, of AI, is the same one she was trained to ask of any new process: what decision is this actually changing.
With AI, the first thing I would tell a board is not to start with the technology. Start with the decision you are trying to make, the problem you are trying to solve and the risk you are actually introducing. There is a tendency either to become enormously excited about AI and implement it without enough governance, or to become frightened of it and create so much governance that nobody can do anything useful with it. Neither is particularly helpful.
She doesn’t see governance as a brake on commercial activity. Done properly, she argues, it gives people the confidence to do more, because they understand where their boundaries actually sit.
Where the Documentation Stops and the Real Problem Starts
A pattern she keeps meeting: an organisation arrives believing it has a documentation problem, when the real issue is a decision-making one.
You can rewrite a policy relatively easily. It is much more interesting to understand why that policy wasn’t influencing behaviour in the first place. A lot of my work therefore starts with looking beyond the documents: how responsibilities are understood in practice, where information moves, where decisions get stuck, where assumptions have developed and whether the governance structure reflects the organisation that exists today rather than the organisation that existed when the framework was written.
Rewriting the policy is the easy part. Finding out why the last version never changed anyone’s behaviour is the actual job.
The Advantage of the Annoying Question
Danielson-Kaslik describes her working style plainly: “I ask an irritating number of questions.” She isn’t satisfied with “that’s the way we’ve always done it” as an explanation for anything, and wants to know why a process exists, what it was meant to solve, and whether that problem is even still there.
She has connected that habit publicly to an adult diagnosis of autism and ADHD. Writing about a safari trip before a recent speaking engagement, she described watching a herd of zebra and recalling something she read after her diagnosis: that you can spend your life thinking you’re a poor horse, when you were actually a good zebra all along. The point wasn’t about animals. It was about benchmarks built around one way of thinking, and what gets missed when someone is measured against the wrong one.
In governance work, that shows up as a refusal to accept the tidy version of how an organisation says it operates.
From Compliance Analyst to Founder
Danielson-Kaslik built her early career across compliance roles before founding VERITAS.
Along the way she earned the ICA Diploma in Governance, Risk and Compliance, became a Member of the International Compliance Association, and was named a finalist for Be The Ladder. In May 2025, the ICA gave her its Outstanding Achievement Award in Anti-Money Laundering. She now chairs the Emerging Leaders group at the Institute of Directors, Isle of Man, and her advice to anyone starting out is a short one.
“Don’t mistake being the youngest or least experienced person in a room for having nothing useful to contribute,” she says.
Where Mitzi Is Now
Danielson-Kaslik works from Douglas, Isle of Man, though the work itself is increasingly international. Through VERITAS she provides board advisory, governance and risk consulting, remediation support and training for regulated organisations working through AI governance, financial crime, operational resilience and geopolitical risk. That work has taken her onto international stages too: she recently spoke on financial crime and governance at The African Circuit conference in Mauritius, one stop in a growing list of engagements outside the Isle of Man.
“I want to continue building VERITAS internationally,” she says, “while contributing to the conversations shaping what good governance looks like as technology, regulation and geopolitical risk evolve.”
The Mitzi Danielson-Kaslik Playbook: Governing the Decision, Not the Document
- Start with the decision, not the tool. Before governing a new technology, name the specific decision it changes and the risk it actually introduces.
- Ask why the policy exists at all. If nobody can explain the original problem it solved, rewriting it won’t fix the behaviour underneath it.
- Check the framework against today’s organisation. A governance structure built for a company that no longer exists won’t govern the one that does.
- Don’t mistake inexperience for having nothing to say. The quality of the questions matters more than the length of the CV asking them.
- Treat governance as permission, not a brake. People move faster when they understand exactly where their boundaries sit, not when they’re told to slow down.
Mitzi Danielson-Kaslik helps boards and regulated organisations govern their decisions, not just their paperwork, through VERITAS.


