Most HR and IT leaders are convinced they have evidence of their workforce’s capabilities. But that same confidence is often the problem.
Ask if they have the right people, in the right roles, with the right skills. The answer is almost always yes. Then you ask for the proof.
HRIS records, LMS completions, certifications, performance reviews, job descriptions, skills profiles, manager ratings, years of experience. Maybe even an AI-generated skills inference engine sitting on top of all of it.
On the surface, it looks and feels like evidence. But from an evidence perspective, much of it falls short.
What are we actually measuring?
- Course completion proves that someone completed a course. It does not prove they can apply the skill.
- Certifications may demonstrate that knowledge was evidenced by a specific assessment. That does not automatically prove workplace competence.
- Manager ratings are opinions. Sometimes well-informed, but still subjective unless anchored to defined criteria and observable evidence.
- Years of experience measure time.
- Job titles measure organizational labeling.
- Resumes are largely self-reported history.
- A skills inference engine is still just an inference. Calling an assumption “AI-powered” does not magically make it evidence.
Yet organizations pile all this data into dashboards and start treating the output as objective truth.
That is where things get risky.
Imagine a major cybersecurity breach. Six months later, lawyers, regulators, and the board are working through what happened.
Someone asks: “You assigned this individual responsibility for this critical function. What evidence did you have that they possessed the required competence?”
The company provides a training transcript, 5 certifications, 12 years of experience, and a manager assessment stating that the employee “exceeds expectations.”
“That proves a lot of activity. But what proves competence?” That is a completely different standard.
We would never accept this level of evidence in financial assurance. Imagine telling an auditor that the numbers are trustworthy because the finance department has completed all required training, has decades of experience, and has received strong performance reviews.
The auditor would still ask for real evidence. Controls, testing, defined criteria, traceability, repeatability, and independent verification where appropriate.
Because assurance is not built on confidence. It is built on evidence.
Yet workforce capability is still treated differently. Even when people are running critical infrastructure, guarding sensitive data, governing AI, managing billions in technology, or making decisions that could expose the organization to massive risk.
Now, organizations are adding AI agents to the workforce. That should make this conversation even more urgent.
- If an autonomous agent is doing the work, what skills or capabilities does that require?
- At what level?
- Where are the boundaries?
- What evidence shows the agent can perform reliably?
The same questions should apply to humans.
This is the skills assumption conundrum.
Organizations have mountains of workforce data, but far less objective evidence of capability than they think. That distinction is about to matter a whole lot more.
Sooner or later, someone will stop asking, “What skills do you have?” and start asking the question that could collapse the entire house of cards: “Show me the proof.”