top of page

Beware of the "Experts", confidence and competence are not the same

4 days ago
6 min read

Updated: 4 days ago

The scariest mistakes I’ve seen didn’t come from junior people guessing. They came from experienced people who were sure they were right. That’s what makes this hard. In most companies, you’re constantly surrounded by confident opinions—vendors, marketers, leaders, “experts” online. Very few people say, “I’m not sure.”


They say:“We’ve always done it this way.”“I know this market.”“The vendor confirmed it.”


Sometimes they’re right. Sometimes they’re confidently wrong.


And if you can’t tell the difference, you end up building decisions on noise instead of reality.


Confidence can sound a lot like expertise


One of the hardest parts of the job is separating real knowledge from familiar-sounding confidence. The loudest person in the room might have deep expertise. They might also have a quota, a deadline, or a long history of doing something a certain way. But confidence creates a dangerous shortcut. It feels like clarity, especially when you're under pressure to move fast.

Real expertise behaves differently. A confident person answers quickly.


A knowledgeable person can show you why they’re right.


The difference between confidence and actual expertise affects how you spend money, how you design systems, what risks you take, and how quickly problems spread.


Privacy is just one of the fastest ways to see the damage. A bad assumption doesn’t stay contained. It turns into downstream issues—process gaps, bad data, legal exposure, reporting errors, and months of cleanup.


The problem isn’t that people are careless. It’s that confidence gets treated like proof.


Story 1: The EMEA privacy process looked off


A couple of years after GDPR came into force, I joined a company to lead Revenue Operations. One of my first projects was to audit privacy and data processes.

That meant reviewing how leads entered the database, how consent was captured, and whether regional practices matched what we claimed to be doing.


As I looked at parts of the EMEA process, something felt off.

For a few EU countries, marketing permissions appeared to be treated more like opt-out than opt-in—or at least far looser than expected. So I started asking basic questions:


How are we capturing permission? What did the person actually see before submitting the form? Where is the consent language stored? Who approved this for these countries?

The responses came back with confidence. The marketers explained that I didn’t fully understand the local laws. They were experienced. They worked in the region. This was how things had always been handled. And to be fair—that’s a reasonable argument on the surface.

Local knowledge matters. Good Corporate Operations teams don’t assume they’re the smartest person in the room. But good Corporate Operations teams also don’t drop an issue just because someone sounds certain. So I brought in legal. Not to win an argument. Not to prove anyone wrong. But because privacy law shouldn’t be settled by whoever sounds more confident on a call.


Legal reviewed the process. My concerns were valid. The local team was wrong.

That was the lesson that stuck. Local experience is valuable—but it’s not the same as verified expertise. Especially after a major regulatory changes, process drift is real.

People remember old rules. They copy past approaches. Over time, “approved” starts to mean “nobody stopped us.”


That’s not good enough.


Story 2: Vendor leads that weren’t what they claimed


Our second story involved a US digital marketer who wanted to upload vendor-provided leads into the system. The claim was simple: the leads were “opted in,” so there was no issue.


That phrase—“opted in”—always makes me slow down. Opted in to what?

A white paper?An event?A single company?A network of partners?


Those are not the same thing. So I asked to see how the vendor collected the data. Again, there was pushback. The marketer was experienced. The vendor was well-known. The reasoning was familiar:

“They wouldn’t still be in business if they weren’t doing it right.”


That sounds practical. It’s not evidence.


Plenty of companies operate in grey areas. Some rely on customers not asking hard questions. Some shift risk through contracts. Some just haven’t been challenged yet.

Vendor confidence does not transfer risk away from your company.


So we reviewed the actual collection process—flows, consent language, and what individuals had agreed to. The vendor was not doing it right. The leads could not be used the way the marketer assumed.


That should have been a clean expected outcome. We caught the issue. The vendor audit process worked. But the reaction wasn’t relief—it was frustration. The marketer pushed back, arguing that compliance was getting in the way of hitting targets and they had already signed agreements with the vendor for their campaigns. That reaction revealed the underlying issue.


This wasn’t just about have competency in privacy. It was about pressure.

When someone is measured on pipeline, lead volume, or campaign performance, questionable data starts to look tempting. Compliance feels like friction.

That’s when bad decisions happen. Here a fun ad showing a marketers giving into the pressure and making bad decisions.

What we learned

In both instances, a significant issue arose from a lack of true expertise. The individuals involved were skilled marketers, and their confidence often led others to assume they possessed competence in all areas they addressed. The belief was that if they spoke with certainty, they must be knowledgeable; otherwise, they wouldn’t display such confidence.


The Paradox of Experience

Both situations shared a common thread: the participants were seasoned professionals. This made the circumstances even more challenging. When a junior team member makes an error, colleagues typically take the initiative to verify the work. However, when a senior individual approves something, the team tends to relax their scrutiny. The authority of the title often becomes the benchmark for trust rather than actual experience and competence.


This approach is fundamentally flawed. While experience can enhance efficiency, it does not guarantee correctness when it wasn't check in the first place or if the environment has changed. We always need to have a verification and a check when environments have shifted.


How to recognize real expertise

The goal isn’t to turn every conversation into a debate or treat people like suspects. The goal is to put simple proof standards around decisions that carry risk. If you want to separate real expertise from confident noise, a few checks go a long way:


Ask what rule they’re relying on

When someone says, “This is allowed,” ask which rule supports it.

A strong answer is specific. A weak answer sounds like:

  • “We’ve always done it this way”

  • “Other companies do it”

  • “The vendor said it was fine”

Those are signals to slow down.


Ask for the collection path

For any data source, ask how the data entered the system.

What was collected at the time of entry? What was the exact context? What systems did it propagate to and what data processing was applied.


Separate incentives from decisions

The person responsible for hitting a target should not be the final authority on whether a data source is compliant.

That’s not about trust. It’s about incentives.

Better decisions happen when responsibility is shared across marketing, operations, legal, and vendor management.


Require vendors to show, not tell

Questionnaires aren’t enough.

Ask for proof—screenshots, flows, language, and terms that match your use case. The best approach is a mini pilot. But not all vendors are willing to do this at no/low cost.

A simple rule helps:

No proof, no trust.


Document decisions

If a decision only exists in someone’s memory, it will eventually become a problem.

You don’t need perfect documentation. You need traceability.

If someone asks six months later why data was used, the answer shouldn’t be “we thought it was fine.”


Recheck old processes

A process that was safe three years ago may not be safe now.

Laws change. Vendors change. Systems change.

The more important the process, the more often it should be reviewed.


The role of escalation


One reason these issues get messy is that escalation is treated like an accusation.


It’s not.


Bringing in legal doesn’t mean someone is wrong. It means the decision carries enough risk to deserve proper review. Operations doesn’t need to know every law. It needs to recognize when a claim lacks evidence—and when the next step is validation, not debate.


The Takeaway


The lesson isn’t to distrust everyone. It’s to stop outsourcing judgment to confidence. The people who actually know what they’re doing can handle being asked to show their reasoning. They might not love it, but they won’t fall apart under it.

The people who can’t—and get defensive instead.


And the most reliable way to tell the difference isn’t instinct. It’s knowledge. You don’t need to be an expert in everything. But you do need depth in your domain—and enough understanding of adjacent areas to recognize when something doesn’t add up.

That’s your real “BS detector.”


It’s built over time. Like a skyscraper—layer by layer. You can’t skip levels, and you can’t rush the foundation. Shortcuts don’t build judgment. They just borrow it. Relying on summaries, vendor claims, or even AI to think for you might get you answers faster—but it doesn’t build understanding. And without understanding, you can’t evaluate whether those answers are right. That’s how people become confidently wrong.


In a world full of opinions, confidence is cheap. Proof is not. And the ability to tell the difference is something you have to build.




Comments


buymeacoffee_sq.png
subscribe_sq.png
SOCIAL
  • LinkedIn
  • Twitter
  • flipboard
  • buymeacoffee_sq
bottom of page