· Updated August 8, 2026

What Is a Certificate of Insurance & Why You Need One | COI File

A certificate of insurance proves vendor coverage exists but does not itself provide protection. Learn what a COI actually does, why you need one, and the gap between having a COI and being covered.

A certificate of insurance (COI) is a standardized document that verifies a business has active insurance coverage. It lists the policy types, coverage limits, and effective dates in a one-page summary. A COI is evidence that coverage existed, not proof that it still exists. If the vendor cancels the policy next week, the certificate in your file does not protect you. You need COIs to verify vendors carry adequate coverage before work starts and to track that coverage continuously, not just at onboarding.

What Is a Certificate of Insurance?

A certificate of insurance is a document issued by a vendor's insurance agent or carrier. It summarizes the insurance policies the vendor carries: the types of coverage, the dollar limits per occurrence and in aggregate, the policy numbers, and the effective and expiration dates. The most common format in the United States is the ACORD 25 form, a single-page document standardized by the Association for Cooperative Operations Research and Development.

The COI serves as a snapshot. It captures what policies existed at the moment the agent pressed print. It does not modify those policies. It does not grant rights to the certificate holder. It does not guarantee the policies remain active tomorrow. Every ACORD 25 form carries a disclaimer in bold at the top: the certificate "is issued as a matter of information only and confers no rights upon the certificate holder" and "does not affirmatively or negatively amend, extend or alter the coverage afforded."

Industry surveys show that 90 percent of businesses require COIs from service providers to manage liability risk. The Associated General Contractors of America reports that 95 percent of construction contracts require subcontractors to provide liability insurance certificates. Nearly 4 in 5 businesses receive COI requests annually. These documents are the backbone of vendor compliance, but their value depends entirely on what you do with them after you receive them.

Why Do You Need a Certificate of Insurance?

The short answer: because without one, you are accepting all the risk. When a vendor works on your property without verified insurance, every incident lands on your coverage. A forklift tips a pallet. A worker slips on ice in the parking lot. A subcontractor causes water damage to a tenant unit. If the vendor has no active policy, your general liability becomes the primary responder. Your premiums rise. Your deductible is gone. Your claims history gets a mark that follows you for three to five years.

A Ponemon Institute study found that 59 percent of companies had experienced contractual exposures caused by vendors or third parties. Only 16 percent felt they effectively mitigated that third-party risk. The same research found that 23 percent of vendors do not respond at all to requests for proof of insurance. That means nearly a quarter of your suppliers may be operating without verified coverage if nobody is chasing them.

The numbers are real and they are large. Zurich Construction Risk Engineering data places the average claim cost for a lapsed subcontractor general liability policy at $284,000. Slip and fall settlements during coverage gaps range from $750,000 to $2.3 million. Your own insurance premiums typically rise 15 to 30 percent for three years following a claim involving an uninsured party. Project delays from pulling crews while coverage is reinstated cost roughly $3,500 per day.

A COI also serves a second purpose. It proves to auditors, lenders, and your own insurer that you maintain a compliant vendor program. During a compliance audit, the auditor asks for certificates. If you cannot produce them, the finding is not "we think they had coverage." The finding is that you did not verify. That distinction matters.

What Is the Difference Between a COI and an Insurance Policy?

A COI summarizes. The policy governs. They are not the same thing, and confusing them is the source of most certificate-related disputes.

The insurance policy is the contract between the insurer and the insured. It defines what is covered, what is excluded, what the limits are, and under what conditions the insurer pays claims. The policy is the legally binding document. The COI is a summary of that document, issued for the convenience of third parties who need to verify coverage without reviewing the full policy. The COI cannot override the policy. If the policy excludes pollution liability, checking a box on the certificate does not add it.

This distinction matters when something goes wrong. A general contractor collects a COI from a subcontractor showing general liability coverage of $1 million per occurrence. The contractor files it. Six months later, the subcontractor causes a fire that damages three units. The contractor files a claim against the subcontractor's policy. The insurer denies coverage. The subcontractor's policy had a residential construction exclusion that the certificate never mentioned. The contractor is now holding a claim and a certificate that provided no protection at all.

According to COI tracking research, 24 percent of errors and omissions claims against insurance agencies involve failure to procure the correct coverage. Many of those claims trace back to certificates that were inaccurate, incomplete, or misunderstood by the parties relying on them.

What Does a Certificate of Insurance NOT Do?

Most guides skip this section. It is the most important. A COI does not:

  • Create coverage. It reports coverage. If the underlying policy does not exist or has been cancelled, the COI is worthless.
  • Guarantee future coverage. A policy can be cancelled mid-term for non-payment. ISNetworld data shows roughly 8 percent of subcontractor policies are cancelled mid-term. The certificate in your file still shows active dates.
  • Make you an additional insured. Checking the additional insured box on an ACORD 25 means nothing if the endorsement was not actually added to the policy. The endorsement, typically on ISO form CG 20 10, must exist in the insurer's file.
  • Obligate the insurer to you. The insurer's contract is with the named insured, not with the certificate holder. You cannot sue the vendor's insurer directly using the COI.
  • Override policy exclusions. If the policy excludes a specific hazard, the certificate cannot remove that exclusion.

This gap, between what people think a COI provides and what it actually provides, drives a significant share of insurance disputes. The certificate gives you an address to send a claim notice. It does not guarantee the claim will be paid.

What Is the Difference Between a Certificate Holder and an Additional Insured?

Certificate holder is an administrative role. Additional insured is a legal status. The difference matters because confusing the two is the most common source of uncovered claims in vendor compliance programs.

A certificate holder is the party that receives the COI. If you are listed as certificate holder, the insurer may notify you if the policy is cancelled. That is it. You hold a piece of paper. You have no rights under the policy.

An additional insured is a party that has been formally added to the vendor's insurance policy through an endorsement. That endorsement gives you coverage rights under the policy. If a claim arises from the vendor's work, the vendor's policy covers you as if you were a named insured with respect to that claim. According to BCS research, 9 out of 10 submitted certificates contain errors, and missing or incorrect additional insured endorsements top the list. Many organizations collect COIs with the additional insured box checked but the actual endorsement was never filed. The certificate says one thing, the policy file says another, and the policy file wins every time.

For property managers and general contractors, requiring additional insured status on every vendor policy is the standard. A Jones case study documented one property manager who improved their additional insured compliance rate from roughly 60 percent to over 85 percent simply by explaining to vendors why the endorsement mattered and rejecting certificates that lacked it.

How Do You Read an ACORD 25 Certificate of Insurance?

The ACORD 25 form is organized in three sections:

Producer and insured. The top section identifies the insurance agent or broker who issued the certificate and the named insured, the vendor you hired. The named insured must match the vendor's legal name exactly. "ABC LLC" is not "ABC Inc." A name mismatch is one of the most common rejection reasons and creates a coverage ambiguity that insurers exploit in claim disputes.

Coverage grid. The middle section is a table with rows for each coverage type: commercial general liability, automobile liability, umbrella/excess liability, and workers compensation. Each row shows the insurer name, policy number, effective date, expiration date, and coverage limits. Check that every date is current, every limit meets your contract minimums, and every policy number is unique. Duplicate policy numbers across coverage types can indicate an error.

Description and endorsements. The bottom section is the most scrutinized and the most error-prone. It includes the certificate holder name and address, the description of operations and vehicles, and checkboxes or text indicating additional insured status, waiver of subrogation, and primary/non-contributory language. According to ACORD 25 error data, wrong policy dates account for roughly 28 percent of certificate errors, wrong coverage limits for 22 percent, incorrect certificate holder information for 12 percent, and missing waiver of subrogation for 8 percent.

If you want a deeper field-by-field breakdown, read our guide to reading an ACORD 25 certificate of insurance.

What Should You Check on Every Certificate of Insurance?

When a COI arrives, verify these seven items before filing it:

  1. Named insured match. The legal entity on the certificate matches the vendor you contracted with.
  2. Coverage types. The vendor carries general liability and workers compensation at minimum. Contractors working on your property should also have auto liability and umbrella coverage.
  3. Coverage limits. Each limit meets or exceeds your contract requirements. Standard minimums are $1 million per occurrence and $2 million aggregate for general liability.
  4. Policy dates. Every policy is currently active and the expiration dates extend beyond the vendor's work period.
  5. Additional insured. Your organization is listed as additional insured and the endorsement form number is referenced.
  6. Waiver of subrogation. The waiver is indicated and applies to the certificate holder.
  7. Primary/non-contributory. The vendor's policy is primary over any other available insurance.

Manual verification of these seven items takes 5 to 10 minutes per certificate for a trained reviewer. For organizations managing 50 or more vendors, that is 4 to 8 hours per renewal cycle just on verification, not counting the time spent chasing non-compliant vendors. COI tracking software automates this verification and flags mismatches in seconds. For more on the tradeoffs, see our comparison of COI tracking spreadsheets versus software.

How Do You Track Certificates of Insurance Over Time?

Collecting a COI once is step one. Tracking it continuously is where most programs fail. Manual tracking in spreadsheets produces compliance rates of 40 to 60 percent at any given time, according to VendorAccess and Certificial data. That means a portfolio with 100 vendors likely has 40 to 60 certificates with active compliance gaps: expired policies, missing endorsements, insufficient limits, or named insured mismatches.

Effective COI tracking requires four components:

  • Centralized storage. Every COI lives in one system, not scattered across inboxes and shared drives.
  • Automated expiration alerts. Notifications at 30, 14, and 7 days before expiration, so you have lead time to request renewals.
  • Renewal verification. When a new certificate arrives, someone checks that the limits and endorsements match the prior certificate. Limits sometimes drop at renewal without the vendor mentioning it.
  • Compliance reporting. A dashboard or report that shows which vendors are compliant and which are not, so you can prioritize follow-up and prove compliance during audits.

For step-by-step guidance on building your tracking process, see our COI expiration tracking system setup guide and our vendor onboarding COI collection workflow.

What Happens If a Vendor's COI Expires?

An expired COI creates three problems, and they compound:

First, the vendor may be working on your property without active insurance. If an incident occurs during the gap, your coverage responds. Your claims history takes the hit.

Second, you are likely in breach of your own contracts. Most property management agreements and construction contracts require all vendors and subcontractors to maintain active coverage. If your client's insurer audits your vendor program and finds expired certificates, the finding reflects on your risk management practices.

Third, the gap compounds over time. A vendor whose certificate expires in January and is not flagged until March has been uninsured on your property for two months. If an incident occurred in that window, the claim may not surface for weeks or months after the event. By then, reconstructing who was covered and when becomes a forensic exercise.

Manual tracking detects gaps 14 to 42 days after they occur on average, according to ISNetworld data. Automated tracking detects them in real time. The difference between catching a gap at day 2 versus day 42 can determine whether an auditor classifies it as a minor process issue or a material compliance failure.

Frequently Asked Questions

A certificate of insurance (COI) is a standardized document issued by an insurance agent or carrier that verifies a business holds active insurance coverage. It summarizes the policy types, coverage limits, effective dates, and expiration dates in a single page. The most common format is the ACORD 25 form, used for liability coverages. The document proves coverage existed when it was issued but does not itself grant any rights or modify the underlying policy terms.
A certificate holder is simply the party that receives and holds the COI. Being listed as the certificate holder gives you proof that the other party carries insurance. Nothing more. An additional insured is a party that has been added to the actual insurance policy through a formal endorsement. This gives them coverage rights under that policy. Listing someone as certificate holder on an ACORD 25 does not make them an additional insured. That requires a separate endorsement attached to the policy, typically on ISO form CG 20 10 or equivalent. This distinction is one of the most common compliance gaps. BCS research found 9 out of 10 submitted certificates contain errors, and missing or incorrect additional insured status leads that list.
A COI does not amend the insurance policy. It does not expand coverage, guarantee future coverage, create additional insured status, or bind coverage. If a policy excludes mold damage, a certificate cannot override that exclusion. If a vendor cancels their policy the week after sending you a COI, the certificate in your file does not protect you. It provides no contractual rights to the certificate holder. The bolded disclaimer at the top of every ACORD 25 form states this explicitly: the certificate "is issued as a matter of information only and confers no rights upon the certificate holder" and "does not affirmatively or negatively amend, extend or alter the coverage afforded."
A COI is your first line of defense against uninsured vendor exposure. If a vendor causes property damage or bodily injury on your site and lacks adequate coverage, your own insurance becomes the target. Zurich Construction Risk Engineering found the average claim cost when a subcontractor policy has lapsed is $284,000. Slip and fall settlements during coverage gaps run $750,000 to $2.3 million. Beyond direct claims, your own premiums typically rise 15 to 30 percent for three years following a claim involving an uninsured party. A COI also proves to your own insurer, your lenders, and your clients that you maintain a compliant vendor program. Without documented COIs, an auditor cannot distinguish between a property manager who tracks compliance and one who does not.
A COI is valid until the expiration date listed on the form, which is typically one year from the policy effective date. But expiration dates tell only half the story. According to ISNetworld data, roughly 8 percent of subcontractor insurance policies are cancelled mid-term for non-payment or other reasons. The certificate in your file still shows active coverage. The underlying policy is gone. This is why tracking expiration dates alone is insufficient. Continuous monitoring, whether through automated COI tracking software or a disciplined manual verification schedule, catches mid-term cancellations that expiration alerts miss.
A complete COI includes the named insured and their address, the insurance carrier name and NAIC number, each type of coverage (general liability, workers compensation, auto, umbrella, professional), the policy number and effective and expiration dates for each, the per-occurrence and aggregate coverage limits, the certificate holder name and address, and any special endorsements such as additional insured status, waiver of subrogation, or primary/non-contributory language. The named insured must match the vendor legal name exactly. An LLC listed as "Inc" on the certificate creates an ambiguity that can be exploited in a claim dispute. The Description of Operations section should specify the work the vendor performs and reference the contract requiring the insurance.
Request a COI before any vendor begins work on your property or project. According to AGC data, 95 percent of construction contracts require subcontractors to provide liability insurance certificates, and nearly 4 in 5 businesses receive COI requests annually. The right time is during vendor onboarding, before the first invoice is paid. Tying payment to COI compliance is the single most effective workflow change for improving response rates. When vendors know their payment depends on a compliant certificate, response times drop from an average of 8 days to under 2 days, according to SmartCompliance benchmark data. Request renewed certificates annually at least 30 days before expiration.
A COI itself does not protect you. The underlying insurance policy does. The certificate is evidence the policy existed. Protection comes from the policy terms, particularly when you are named as an additional insured with a waiver of subrogation and primary/non-contributory language. Without these endorsements attached to the actual policy, the vendor insurance covers the vendor, not you. If a vendor worker is injured on your site and sues you, the vendor general liability policy responds only if you are listed as an additional insured on that policy. The certificate alone, even with the additional insured box checked, does not grant that protection. The endorsement must exist in the policy file.
F

Firdaosh Bano

COI Compliance Specialist

Firdaosh Bano is a COI compliance specialist and the founder of COI File. She spent 6 years managing vendor compliance for commercial properties - tracking 2,000+ COIs across 150+ properties in spreadsheets before building the tool she wished she'd had. She writes about certificate of insurance compliance, vendor risk management, and making insurance tracking less painful for small teams.

Ready to simplify your COI tracking?

Join property managers and contractors who are ditching spreadsheets for good.

Start Base Trial →