· Updated August 8, 2026

Vendor Onboarding COI Collection: Step-by-Step Guide | COI File

How to build a vendor onboarding COI collection workflow that reduces compliance gaps. Covers request templates, timelines, common mistakes, and automation thresholds.

A vendor onboarding COI collection workflow is a repeatable process for requesting, receiving, verifying, and filing certificates of insurance before a vendor starts work. Most property managers and general contractors do not have one. They handle COIs through scattered emails, shared drives, and personal reminders. The result: roughly 40 to 60 percent of vendors have active compliance gaps at any given time, based on VendorAccess and Certificial portfolio data. A structured workflow closes that gap by making insurance verification a condition of onboarding, not an afterthought.

This guide walks through the workflow step by step. It covers what to request, how to request it, where the bottlenecks live, and when manual processes stop being adequate.

Why does manual COI collection break during vendor onboarding?

The typical manual process works like this. A project manager emails a vendor asking for "proof of insurance." The vendor forwards it to their insurance agent. The agent emails a COI back. The vendor forwards it to the project manager. The project manager glances at it, files it in a folder. Nobody checked the additional insured endorsement. Nobody set a renewal reminder. Nobody verified the policy limits against the contract.

This is structural noncompliance. The Association of General Contractors uses that term for systems that produce the appearance of compliance without the substance. A COI in a folder looks compliant. A spreadsheet row with a checkmark looks compliant. Neither tells you whether the coverage actually meets your requirements.

BCS research found that 9 out of 10 submitted certificates contain errors. Missing additional insured endorsements are the most common gap by a wide margin. Insufficient limits and named insured mismatches are right behind. A manual workflow catches these errors maybe half the time, and only if someone reads the COI carefully. Most people do not. They see a document and check the box.

What should a COI request include to get compliant certificates on the first try?

The biggest leverage point in the entire workflow costs nothing and takes about an hour. Write down exactly what insurance every vendor category needs. Send it before you ask for the certificate.

A commercial roofing contractor needs general liability at $1 million per occurrence and $2 million aggregate, workers compensation at statutory limits, commercial auto if vehicles enter the property, and umbrella coverage of $2 million or more. They also need an additional insured endorsement using ISO form CG 20 10, a waiver of subrogation, and primary/noncontributory wording. A cleaning service with two employees and no vehicles on site needs far less.

Create a one page requirements document for each vendor tier. Attach it to the vendor agreement. Vendors who receive specific requirements upfront submit compliant COIs on the first attempt roughly 60 percent more often than vendors asked to "send proof of insurance" through a generic email, according to compliance team benchmarks.

If you are not sure what requirements to set for each vendor type, start with the COI requirements by industry guide or the guide to requirements by contract type.

A request that produces compliant certificates on the first try includes:

  • Coverage types. General liability, workers compensation, auto, umbrella. List each one you require.
  • Minimum limits. $1M per occurrence, $2M aggregate for general liability. State-specific for workers comp. Name the numbers.
  • Certificate holder. Your legal entity name and mailing address, exactly as they should appear on the ACORD 25.
  • Additional insured. Specify the endorsement form. ISO CG 20 10 is standard. Some states require different forms. Name the one you need.
  • Waiver of subrogation. If you require it, say so. Most vendors do not include it unless asked.
  • Deadline. "Before work begins" is not a deadline. "Submit by October 15" is a deadline.

Vendors who receive requests this specific submit certificates that pass first review roughly two thirds more often. The request template itself does the compliance work.

What should you verify on every COI before filing it?

Filing a COI without verifying it is the most expensive shortcut in the entire process. Checking a single certificate for the basics takes 2 to 3 minutes. Teams that skip this step trade 3 minutes now for months of undetected exposure.

Verification means checking each of these fields against your requirements document:

  1. Named insured. Does the legal entity on the COI match the legal entity in your contract? ABC LLC and ABC Inc are different entities with different policies.
  2. Policy dates. Is the effective date before work starts? Is the expiration date after work ends?
  3. Coverage types. Does the vendor carry every type you require? General liability without workers comp means a gap.
  4. Limits. Do the per occurrence and aggregate limits meet your minimums? A policy with $500,000 per occurrence does not satisfy a $1 million requirement.
  5. Additional insured. Did the agent actually attach the endorsement, or did they just check a box on the ACORD 25? A checked box is not an endorsement. Only the attached form creates coverage.
  6. Waiver of subrogation. Is it included? Look for the actual endorsement, not just a mention in the description box.

Manual verification of all six fields per certificate, across 50 vendors, takes roughly 2.5 to 5 hours per month. COI tracking software cuts this to seconds per certificate by extracting and validating fields automatically. Free COI tracking tools can handle the basics for smaller vendor lists.

How do you enforce COI requirements when vendors push back?

When a COI fails verification, the vendor goes into a gap queue. The gap queue is where most manual workflows die. A vendor submits a noncompliant COI. Someone emails them about the issue. The vendor does not respond. The person forgets to follow up. The vendor starts work anyway. The COI on file still shows a gap that nobody is tracking.

Coupling the COI to payment is the most reliable enforcement mechanism. Vendors who know their first invoice will not be released until a compliant COI is on file respond within 2 days on average, compared to 8 days without a payment trigger, based on SmartCompliance client data. This approach only works if it is communicated upfront and enforced consistently. Exceptions for "urgent" work create a precedent that erodes the entire workflow within a few months.

Project managers want the work started. Compliance wants the gap closed. These two goals conflict, and project managers usually win unless leadership makes the rule explicit. Someone in charge has to say: no COI means no payment means nobody starts work.

How do you track COIs after onboarding is complete?

Onboarding a vendor with a verified COI does not end the workflow. It starts the tracking cycle. The COI expires in 12 months. Around month 10, someone needs to request a renewal certificate. Around month 11, someone needs to verify that the new certificate maintains the same coverage limits and endorsements as the original.

Without tracking, renewal requests happen when someone remembers to do them. Memory-based compliance produces exactly the result you would expect. ISNetworld data puts manual COI tracking compliance at 40 to 60 percent at any given time. Automated tracking pushes that number past 90 percent by scheduling renewal requests, verifying the new certificate fields against the original requirements, and escalating nonresponses automatically.

For a framework on setting up expiration tracking from scratch, see the COI expiration tracking system setup guide. It covers alert schedules, escalation paths, and the differences between manual and automated approaches.

At what vendor count does manual COI collection stop working?

Manual COI collection works at small scale. If you onboard 2 or 3 vendors per quarter and each relationship lasts years, a spreadsheet and a Gmail folder serve you fine. The problems compound with volume.

The first failure point arrives at roughly 10 to 15 vendors. Renewal dates start overlapping. Someone misses a 30-day warning. A vendor submits an updated certificate that changed coverage limits and nobody notices because the old limits are still in the spreadsheet.

The second failure point hits around 20 to 25 vendors when a second person starts helping with COIs. Two people edit the same spreadsheet. Version conflicts start. Nobody knows who sent the last reminder to which vendor.

Beyond 30 vendors, the audit trail disappears. There is no record of who verified which certificate, when they verified it, or what requirements they checked it against. If an insurer or a lender asks for your compliance records, you cannot produce a defensible paper trail from a shared spreadsheet.

Switching to COI tracking software replaces memory with verification. Certificates come through a single portal. Every field gets extracted and validated. Gaps get flagged automatically. Renewal reminders go out on schedule. The audit trail survives an auditor's review. Teams that switch from manual to automated COI tracking report a 62 percent reduction in compliance errors, based on industry data compiled by PolicyManagerHub, and processing times drop by roughly 70 percent compared to manual workflows.

Automated systems still need a human to handle exceptions and vendor relationships. What they eliminate is the busywork: the email chasing, the date scanning, the manual field comparison that eats up 15 to 20 hours per week for a mid-sized vendor list.

What does a failed COI collection process actually cost?

A missed COI during onboarding is not a paperwork error. It is a liability exposure that compounds over time.

The average general liability claim involving an uninsured vendor runs $284,000 according to Zurich Construction Risk Engineering. Slip and fall settlements during coverage gaps range from $750,000 to $2.3 million. Your own insurance might cover the loss, but premiums typically rise 15 to 30 percent for three years following a claim involving an uninsured party.

The labor cost of manual COI administration is significant on its own. Teams managing 50 to 100 vendors spend roughly 15 to 20 hours per week on COI tasks at an estimated $45 per hour, totaling approximately $36,400 per year. This is just the administrative cost. It does not factor in the liability exposure from gaps the workflow cannot see.

A structured vendor onboarding COI collection workflow turns these exposures from unknown risks into managed processes. It will not eliminate every gap. No system does. What it eliminates are the preventable ones: the certificates that were never requested, the endorsements that were never specified, the renewals that were never tracked.

Before you send a single email, define your insurance requirements in writing. Create a document that lists minimum coverage types, limits, and endorsements for each vendor category. Contractors doing roof work need different requirements than a cleaning service. Send this document with your vendor agreement, not as an afterthought. Vendors who know the requirements upfront submit compliant COIs on the first try roughly 60 percent more often than vendors who get requirements piecemeal through email chains.
Manual COI collection typically adds 5 to 12 business days to vendor onboarding, based on TechnologyMatch vendor tiering data. Tier 3 vendors providing simple services can complete onboarding in 1 to 3 days when requirements are clear. Tier 2 vendors average 5 to 8 days. Tier 1 vendors with complex insurance requirements may take 12 to 20 days. The variance is not the vendor category. It is the clarity of the request. Vendors who receive a specific list of required coverage types, limits, and endorsements submit compliant certificates on the first attempt significantly more often than vendors who get vague requests like "send us your insurance."
Requesting the COI without specifying the endorsements. A property manager asks for "proof of insurance" and the vendor sends an ACORD 25 showing general liability. The property manager files it and considers the vendor compliant. Three months later, an incident happens. The certificate holder box on the ACORD 25 is filled in, but the actual additional insured endorsement was never attached to the policy. The insurer has no obligation to defend or indemnify the property manager. BCS research found 9 out of 10 submitted certificates contain errors, and missing endorsements are the most common gap because COI request emails rarely mention them by name.
Neither team should own COI collection in isolation. Procurement initiates the relationship and is best positioned to make insurance requirements part of the contract negotiation. The compliance team verifies that what arrives matches what was required. The handoff between these two functions is where most organizations lose COIs. A vendor submits a certificate to procurement. Procurement forwards it to compliance three days later. Compliance reviews it and finds an issue. Compliance emails the vendor. The vendor sends a revised COI to procurement. Procurement forwards it again. Each handoff adds 2 to 4 days to the onboarding timeline. The fix is a single submission portal that routes to the right reviewer regardless of who the vendor emailed.
Tie the COI to payment. The simplest workflow change that produces the largest compliance improvement is making the certificate a condition of releasing the first invoice. When vendors know their payment depends on a compliant COI, response times drop from an average of 8 days to under 2 days according to compliance team benchmarks from SmartCompliance. The approach needs to be communicated upfront and consistently enforced. Exceptions for urgent work create a precedent that erodes the entire workflow within a few months.
A good COI request is specific enough that a vendor can hand it to their insurance agent without asking follow-up questions. It lists the coverage types required (general liability, workers compensation, auto, umbrella), the minimum limits for each, the certificate holder name and address exactly as it should appear, the additional insured language required (ISO CG 20 10 or equivalent), whether a waiver of subrogation is needed, and whether primary/noncontributory wording is required. It also includes a deadline and a submission method. Vendors who receive requests that meet this level of specificity submit certificates that pass first review roughly two-thirds more often than vendors who receive generic "send your insurance" emails.
Most liability policies are annual, so the collection cycle runs every 12 months per vendor. The challenge is that vendor onboarding happens continuously. You onboard 3 vendors this month and 8 next month. Their renewals also arrive continuously, not all at once. Without a tracking system, the person responsible for COI management spends roughly 15 to 20 hours per week just monitoring dates and sending renewal reminders for a portfolio of 50 to 100 vendors, based on BCS compliance team data. Automated tracking systems handle this continuously so no human needs to remember which vendor renews in which month.
You can improve the workflow with what you already have. A shared inbox with template responses, a spreadsheet with conditional formatting for expiration alerts, and a standard requirements document are better than scattered personal email and a file folder. The limitation is that spreadsheets and shared inboxes do not validate. They store what someone typed. They do not check whether the additional insured endorsement is actually attached to the policy or whether coverage limits changed at the last renewal. Software handles these verification steps automatically. The question is not whether you can survive without software. It is whether the 40 to 60 percent compliance rate that manual workflows produce is acceptable for your risk tolerance.
F

Firdaosh Bano

COI Compliance Specialist

Firdaosh Bano is a COI compliance specialist and the founder of COI File. She spent 6 years managing vendor compliance for commercial properties - tracking 2,000+ COIs across 150+ properties in spreadsheets before building the tool she wished she'd had. She writes about certificate of insurance compliance, vendor risk management, and making insurance tracking less painful for small teams.

Ready to simplify your COI tracking?

Join property managers and contractors who are ditching spreadsheets for good.

Start Base Trial →