· Updated June 6, 2026

COI Compliance Rate: How to Measure and Improve Vendor Insurance Compliance

Most organizations have no idea what their compliance rate is -- and the ones that do are often below 50%. Learn how to measure, benchmark, and improve your vendor insurance compliance rate.

Ask any property manager or risk officer what their vendor insurance compliance rate is, and you will get one of two answers. The first is a confident number -- "around 80%" -- that has never been measured. The second is uncomfortable silence. Neither is good.

When organizations actually measure their compliance rate for the first time, the results are sobering. The average manual compliance rate across industries sits in the low 40% range. That means fewer than half of your vendors have current, compliant certificates of insurance on file. The other 60% are working on your property, on your job site, or under your contracts without verified insurance coverage -- and you are liable for whatever happens.

This guide covers what a compliance rate actually means, how to calculate it correctly, the industry benchmarks you should aim for, the factors that drag your rate down, and a step-by-step plan to take your compliance rate from where it is today to 90% or higher.

What Is a COI Compliance Rate and How to Calculate It

A COI compliance rate is the percentage of your vendors or tenants who have current, verified certificates of insurance on file that meet all of your documented insurance requirements. The formula is simple, but getting the inputs right is where most organizations stumble.

The Compliance Rate Formula

Compliance Rate = (Number of Compliant Vendors / Total Number of Active Vendors) x 100

But each term in this formula requires careful definition:

  • Compliant Vendor: A vendor whose certificate of insurance is (a) not expired, (b) includes all required coverage types at or above minimum limits, and (c) names your organization as additional insured where required. All three conditions must be met. A certificate that is current but has insufficient limits is non-compliant.
  • Active Vendor: Any vendor currently performing work for your organization, under contract, or otherwise engaged in operations on your property or job site. Include vendors whose certificates have lapsed -- they are still active and still a risk. Excluding lapsed vendors from your denominator artificially inflates your compliance rate and hides real liability exposure.

Worked Example

Your organization has 150 active vendors. After auditing, you find:

  • 62 vendors have current certificates that meet all requirements (fully compliant)
  • 38 vendors have current certificates but are missing additional insured status or have insufficient limits (partially compliant -- counted as non-compliant)
  • 28 vendors have expired certificates (non-compliant)
  • 22 vendors have no certificate on file at all (non-compliant)

Your compliance rate: 62 / 150 = 41.3%

This is a typical result for an organization tracking COIs manually. The 88 non-compliant vendors represent real, current liability exposure -- and most organizations do not know which 88 they are until they measure.

Industry Benchmarks for Vendor Insurance Compliance

Context matters. A 60% compliance rate in one industry may be excellent, while in another it is dangerously low. Here is what the data shows across sectors:

Manual Tracking Benchmarks (Spreadsheets, Email, Paper Files)

  • Commercial Real Estate: 35-45% -- driven by high vendor counts, lease-specific requirement variation, and tenant insurance lapses
  • Construction / General Contracting: 40-50% -- subcontractor turnover, per-project requirements, and certificate churn depress rates
  • Property Management: 38-48% -- moderate vendor counts but high policy type variation (GL, workers' comp, auto, umbrella)
  • Healthcare Facilities: 42-52% -- stricter internal policies help, but high vendor volume offsets gains
  • Manufacturing: 45-55% -- generally fewer vendors, but specialized coverage requirements (pollution, product liability) create gaps

The takeaway: manual compliance rates across industries cluster in the low-to-mid 40s. This is not a failure of any one organization's process -- it is the natural ceiling of what spreadsheets and manual tracking can achieve at scale.

Automated Tracking Benchmarks (COI Tracking Software)

Organizations that switch from manual tracking to COI tracking software consistently report dramatic improvements. Industry data from providers including SmartCompliance and Vertikal RMS shows:

  • SmartCompliance client data: Clients moving from manual tracking to their platform report compliance rate improvements from an average of 42% to 94% within 6 months of implementation. The combination of automated expiration alerts and requirement matching eliminates the two biggest causes of non-compliance: missed expirations and insufficient coverage limits.
  • Vertikal RMS client data: Organizations using their risk management platform achieve average compliance rates of 91% across portfolios, with the top quartile exceeding 97%. Key drivers include automated vendor follow-up sequences and real-time compliance dashboards that make non-compliance immediately visible to all stakeholders.
  • COI File user data: Users who import existing vendor spreadsheets and activate automated alerts typically see compliance rates rise from 40-50% to 85%+ within the first 90 days, and 92%+ within 6 months as the alert-and-follow-up cycle becomes self-sustaining.

Software does not make vendors more responsive. It makes you more consistent -- and consistency is what drives compliance rates up.

What Hurts Your Compliance Rate

Improvement starts with diagnosis. These are the five factors that depress compliance rates across every industry, ranked by impact:

1. Missed Expirations (Impact: High)

This is the number one driver of low compliance rates. Certificates expire every day. Without automated alerts, expiration dates are buried in spreadsheets until someone remembers to check -- and someone remembers less often than anyone wants to admit. A vendor with an expired certificate is non-compliant the moment the expiration date passes. If it takes you 45 days to notice, that vendor has been a liability gap for 45 days.

2. Insufficient Coverage Limits (Impact: High)

A vendor submits a certificate showing $500,000 in general liability coverage. Your requirement is $1,000,000. The certificate is current. It is on file. It looks compliant at a glance. But it fails the requirement -- and manual review catches this only if someone cross-references the certificate against the requirement checklist. For organizations tracking 100+ vendors, this cross-referencing happens inconsistently, and insufficient limits become invisible compliance gaps.

3. Missing Additional Insured Endorsements (Impact: High)

This is the single most common specific compliance gap. A vendor's certificate lists your organization as the certificate holder but not as additional insured. As certificate holder, you receive notice if the policy is canceled. As additional insured, you receive direct coverage under the vendor's policy. The difference is enormous -- and it is regularly missed because the additional insured box on an ACORD 25 form is small, often handwritten, and easy to overlook during manual review.

4. Vendor Non-Responsiveness (Impact: Medium-High)

Some vendors simply do not respond to certificate requests. They ignore emails, avoid calls, and hope the requirement goes away. Without an escalation process and real consequences (suspension of work authorization, contract penalties), these vendors become permanent compliance gaps that drag your rate down month after month.

5. Data Decay Between Audits (Impact: Medium)

Organizations that audit compliance quarterly or annually experience data decay between audits. A vendor's certificate expires in month 2. The quarterly audit happens in month 3. For 30 days, that vendor was non-compliant and nobody knew. If you measure compliance only at audit time, your snapshot looks better than your day-to-day reality. Continuous monitoring closes this gap, and it is the single biggest advantage of software over periodic manual audits.

app.coifile.com
COI File compliance dashboard showing vendor compliance percentages with color-coded status indicators for compliant, expiring soon, and expired certificates
A live compliance dashboard shows your real-time compliance rate -- not last quarter's audit snapshot.

How to Measure Your Compliance Rate

Measuring your compliance rate correctly is the foundation of improvement. A miscalculated rate -- whether inflated or understated -- leads to misallocated resources and missed risks. Here is the correct method:

Step 1: Define Your Active Vendor Universe

Pull a complete list of every vendor currently performing work, under contract, or otherwise engaged with your organization. Include vendors with expired certificates. Include vendors with no certificate on file. Every vendor in scope for your insurance compliance program belongs in the denominator. If you exclude vendors because "they never respond" or "we are working on it," your compliance rate becomes a vanity metric that hides real exposure.

Step 2: Define Your Compliance Criteria

Document exactly what constitutes a compliant certificate. This must include:

  • Minimum coverage types required (general liability, workers' comp, auto, umbrella, etc.)
  • Minimum coverage limits for each type
  • Additional insured requirement (yes/no, and which entity must be named)
  • Any required endorsements (waiver of subrogation, primary and non-contributory, etc.)
  • Certificate currency (expiration date must be in the future)

Write this down. If your criteria live in someone's head, they are inconsistent by definition, and your compliance rate cannot be trusted.

Step 3: Audit Every Active Vendor

For each active vendor, locate the most recent certificate on file. Check it against all five criteria above. If any criterion is not met, the vendor is non-compliant. No partial credit. This audit will take 2-3 minutes per vendor if done manually -- for 150 vendors, that is a 5-7.5 hour exercise. Schedule it as a dedicated project, not something to squeeze in between other tasks.

Step 4: Calculate and Document

Apply the formula: Compliant Vendors / Total Active Vendors x 100. Document the date of measurement, the criteria used, and the breakdown of non-compliance reasons (expired, insufficient limits, missing additional insured, missing certificate). This breakdown tells you where to focus improvement efforts.

Step 5: Set a Measurement Cadence

Recalculate monthly. If the monthly process is too time-consuming to sustain, that is itself a signal that you have outgrown manual measurement and should adopt software with a live compliance dashboard. A compliance rate measured once per year is a historical artifact, not a management tool.

How to Improve Your Compliance Rate from 40% to 90%+

Moving from a 40% compliance rate to 90%+ is a process, not an event. It takes most organizations 6-12 months. But the path is well-established, and every organization that has walked it reports the same sequence of steps:

Phase 1: Stop the Bleeding (Months 1-2)

Focus exclusively on expired certificates and missing certificates -- the vendors who are currently generating the most liability exposure. This is triage, not optimization. Send renewal requests to every vendor with an expired certificate. Send initial requests to every vendor with no certificate on file. Set a 30-day deadline with explicit consequences for non-response. Target: move from 40% to 60% compliance by closing the most urgent gaps.

Phase 2: Fix the Requirements Gap (Months 2-4)

Now address the vendors who have current certificates but insufficient limits or missing additional insured endorsements. Send each vendor a specific, documented list of what is wrong and what is required. Attach your insurance requirements document. Set a 30-day deadline for updated certificates. Target: move from 60% to 75% by resolving requirement-specific non-compliance.

Phase 3: Automate Renewal Management (Months 3-6)

This is where compliance rate improvement becomes self-sustaining. Deploy COI tracking software with automated expiration alerts. Every vendor whose certificate is expiring in the next 30 days gets an automatic email. Every vendor whose certificate has insufficient limits gets flagged automatically. The manual follow-up burden drops by 70-80%, and your compliance team can focus on the 10-20% of vendors who genuinely need personal attention. Target: move from 75% to 85%+ by eliminating the missed-expiration problem.

Phase 4: Build a Compliance Culture (Months 6-12)

The final 5-10% of compliance rate improvement comes from changing vendor behavior, not just your internal processes. This requires: (1) consistent enforcement -- vendors who repeatedly fail to provide certificates lose work authorization, (2) contract language that makes insurance compliance a condition of payment, not just a checkbox, and (3) vendor education -- many small vendors genuinely do not understand what additional insured means or why it matters. A 5-minute conversation with a vendor explaining the requirement is often more effective than 5 reminder emails. Target: 90%+ sustained compliance rate.

Key Metric to Track During Improvement

Do not just track the overall compliance rate. Track these leading indicators that predict improvement:

  • Time-to-renewal: Average days between an expiration alert being sent and a renewed certificate being received. Target: under 21 days.
  • First-response rate: Percentage of vendors who respond to the first renewal request (no follow-up needed). Target: above 60%.
  • Requirement gap rate: Percentage of submitted certificates that fail requirement matching on first submission. Target: under 15%.
  • Non-responsive vendor count: Vendors who have not responded after three follow-ups. Target: under 5% of total vendor base.

How COI File Drives Higher Compliance Rates

COI File is purpose-built to move your compliance rate from wherever it is today to 90%+. Here is how the platform addresses each driver of non-compliance:

  1. Automated expiration alerts. COI File sends email alerts at 30, 14, and 7 days before any certificate expires -- to you, your team members, and optionally to the vendor. Extensions in the alert email let vendors upload renewed certificates directly, which eliminates the back-and-forth of "please email me your updated COI." Missed expirations -- the #1 driver of low compliance rates -- become a solved problem.
  2. AI-powered certificate extraction. Upload any certificate format -- PDF, image, ACORD 25 -- and COI File extracts policy types, coverage limits, effective dates, expiration dates, and additional insured status in under 30 seconds. No manual data entry. No transcription errors. Your data is accurate from the moment it enters the system.
  3. Automatic requirement matching. Define your minimum coverage limits and additional insured requirements per vendor type. Every uploaded certificate is automatically checked against these requirements. Certificates with insufficient limits or missing additional insured status are flagged in red on your dashboard -- you see exactly which vendors need follow-up and why.
  4. Live compliance dashboard. Your compliance rate is calculated in real time, not when someone runs a manual report. The dashboard shows compliant, expiring soon, and non-compliant vendors with color-coded statuses. Anyone with access -- property managers, regional directors, risk officers -- sees the same live data without asking you for a report.
  5. Bulk vendor import. Export your existing spreadsheet as CSV and import it into COI File in under 10 minutes. The platform validates your data and flags rows that need cleanup. For organizations tracking 200+ vendors manually, this alone saves 10-15 hours of data re-entry.
  6. Complete audit trail. Every certificate upload, every verification, every status change is timestamped and logged. During audits, you can show exactly when each certificate was received, verified, and flagged -- demonstrating a functioning compliance program, not just a snapshot.

COI File is free for up to 5 vendors, with no credit card required. Paid plans start at $29/month. Start free today.

Frequently Asked Questions

A certificate is compliant only when it meets all three criteria: (1) the certificate is current -- not expired and with an effective date on or before today, (2) all required coverage types are present with limits at or above your minimum requirements, and (3) your organization is named as additional insured where required. A certificate that is current but has insufficient limits counts as non-compliant. One that has correct limits but is expired counts as non-compliant. Partial compliance is not compliance. This is why compliance rates are often lower than organizations expect when they first measure them.
Monthly, at minimum. Certificates expire continuously -- roughly 8-10% of your vendor base each month if policies are evenly distributed across the year. A compliance rate measured in January is stale by March. For organizations with 100+ vendors or those in high-risk industries like construction, weekly recalculation is recommended. COI tracking software provides a live compliance dashboard so you always know your current rate without manual recalculation.
This is the most common reaction when organizations first measure their compliance rate. Three factors drive the gap between perception and reality: (1) expired certificates that nobody noticed because manual systems lack alerts, (2) certificates that were filed as compliant but actually have insufficient coverage limits, and (3) missing additional insured endorsements -- the single most common compliance gap. Organizations typically self-report a compliance rate around 70-80% before measurement. After their first audit with automated tools, the actual rate averages 40-50%.
No. A 100% compliance rate means every certificate on file meets your documented requirements. It does not mean the underlying insurance is adequate for every risk, that policies have not been canceled mid-term, or that exclusions in the policies do not create gaps. A 100% compliance rate is a threshold achievement, not a finish line. You should still conduct periodic policy reviews, require 30-day cancellation notices from insurers, and maintain a risk management program that goes beyond certificate verification.
Non-responsive vendors are the biggest obstacle to improving compliance rates. The escalation path is: (1) automated reminder at 30 days, (2) personal follow-up at 14 days with a clear deadline and consequences stated, (3) final notice at 7 days stating that work authorization will be suspended, (4) actual suspension of vendor status if the certificate is not received by the expiration date. Most vendors respond at step 2 or 3 when consequences are real. If you have never enforced compliance before, expect pushback for the first 60-90 days. After that, vendors learn that compliance is not optional and renewal rates improve dramatically.
Yes. A documented, consistently high compliance rate (90%+) is a material factor in insurance underwriting. It demonstrates that your organization has a functioning risk transfer program, which reduces the likelihood of claims falling through to your own policies. Present your compliance data -- including audit trails showing consistent monthly monitoring -- to your broker during renewal negotiations. Organizations with 90%+ compliance rates have reported premium reductions of 5-15% because underwriters view them as lower risk than industry peers with undocumented compliance programs.

Industry Sources

  • IRMI (International Risk Management Institute) -- Risk management standards, certificate of insurance compliance frameworks, and industry benchmarks. irmi.com
  • SmartCompliance (Mitratech) -- Published client data on compliance rate improvements from automated COI tracking; average improvement from 42% to 94% within 6 months. mitratech.com/solutions/smartcompliance
  • Vertikal RMS -- Risk management platform reporting average client compliance rates of 91% with top-quartile clients exceeding 97%. vertikalrms.com
F

Firdaosh Bano

COI Compliance Specialist

Firdaosh Bano is a COI compliance specialist and the founder of COI File. She spent 6 years managing vendor compliance for commercial properties - tracking 2,000+ COIs across 150+ properties in spreadsheets before building the tool she wished she'd had. She writes about certificate of insurance compliance, vendor risk management, and making insurance tracking less painful for small teams.

Ready to simplify your COI tracking?

Join property managers and contractors who are ditching spreadsheets for good.

Start Free →