Vendor Certificate of Insurance Verification A roofer shows up with a one-page certificate, you glance at the limits, and the crew starts work that afternoon. Most property owners, general contractors, and multi-site operators have done exactly this, and most of the time nothing goes wrong.

But when a vendor causes a fire, a data breach, or a workplace injury without valid coverage behind that certificate, the gap becomes your liability, not theirs.

Vendor Certificate of Insurance (COI) verification is the risk-control step that catches this before a contract is signed. It isn't about distrust. It's about confirming that the paper actually matches the policy.

This guide covers what to check on a vendor COI, how to confirm coverage with the issuing broker or carrier, how to read discrepancies and red flags, and how to keep records current, by hand or with a monitoring tool like Muster, so verification doesn't expire the moment the file gets closed.

Key Takeaways

  • A COI summarizes coverage; it's not the policy itself. Verify underlying terms when exposure warrants it
  • Match legal name, coverage types, limits, dates, certificate holder, and endorsements to the contract
  • Contact the broker or insurer directly when details are missing, inconsistent, or tied to high-risk work
  • Treat verification as ongoing: track expirations, scope changes, and renewals—not a one-time file-and-forget

What You Need to Verify on a Vendor COI

Reliable verification needs more than a quick scan. You need the COI itself, the vendor agreement or insurance requirements, the vendor's legal business details, and a documented review process. Miss any one of those, and you're guessing rather than verifying.

Tools and Records Required

Before reviewing a single certificate, gather:

  • The current COI from the vendor
  • The contract or vendor onboarding insurance requirements
  • The vendor's legal name and address, matching state business filings
  • Project or property details and expected work dates
  • Required coverage limits by risk category
  • Broker or carrier contact information, sourced independently rather than pulled only from the certificate

Keep a review record for every COI you touch. Capture:

  • Document received and date reviewed
  • Who reviewed it and the verification source used
  • Findings and follow-up requests
  • Final approval status

Without this, there's no audit trail if a claim ever gets disputed.

COI Fields and Supporting Documents to Compare

The current ACORD 25 (2025/12) certificate is the standard form used by most U.S. insurers and brokers. Inspect these fields on every certificate (ACORD 25, 2025/12):

  • Producer and insurer identity (with NAIC numbers)
  • Named insured
  • Policy numbers for each coverage line
  • Coverage types and limits
  • Effective and expiration dates
  • Certificate holder
  • Description of operations
  • Cancellation or notice language

None of these fields stand alone. Compare them against:

  • Applicable policy endorsements
  • Policy declarations pages
  • Contract insurance clauses
  • State-specific requirements

State rules vary more than most reviewers assume. Texas generally allows private employers to opt out of workers' compensation, while California requires it even with only one employee. Don't apply one state's standard everywhere; check the rule for where the work actually happens.

Texas versus California workers compensation requirements comparison

Preconditions and Scope

Complete the review before the vendor starts work, enters the property, transports goods, handles customer data, or performs higher-risk activity. Once a truck is on-site, verification stops being a safeguard and starts being paperwork.

Also confirm:

  • The named insured matches the entity you're actually hiring, not a parent company or a similarly named affiliate
  • The described operations, location, project, and dates align with the real engagement

Methods to Verify a Vendor COI

There are three verification methods. How deep you go depends on the vendor's work, exposure, contract requirements, and whether anything on the document looks off.

  • Document review against contract requirements
  • Direct confirmation with the broker or insurer
  • Ongoing monitoring after onboarding

Method 1: Review the COI Against Contract Requirements

This is document-level screening. You're checking whether the COI shows the coverage, limits, dates, named entities, and endorsements your agreement requires.

What you need:

  • Current COI and the contract
  • Insurance requirements and internal checklist
  • Vendor legal name, project timeline, and work description

Steps:

  1. Confirm the named insured, insurer, policy numbers, certificate holder, and certificate issue date
  2. Match each required coverage and limit to the COI (auto, workers' comp, professional, cyber, pollution, products, or umbrella as applicable)
  3. Confirm policy dates cover the full engagement
  4. Verify additional insured, waiver of subrogation, or primary-and-noncontributory wording is backed by an endorsement

Four-step vendor COI document review process flow

This method is fast and creates a consistent paper trail. Its limit: a COI alone can't confirm exclusions, cancellation terms, or whether an endorsement genuinely exists.

Method 2: Confirm Coverage Directly With the Broker or Insurer

Use this when the COI is incomplete, unusual, tied to a high-stakes project, or just hard to interpret.

What you need:

  • Broker or carrier contacts found independently
  • Policy numbers and named insured
  • Vendor authorization if requested, plus your specific questions

Steps:

  1. Find the producer or insurer details and independently verify that contact information is legitimate before sharing anything sensitive
  2. Ask the broker or carrier to confirm the policy's active status, relevant coverage, limits, effective dates, and required endorsements as of today
  3. Record who you contacted, when, what they confirmed, any limitations on their response, and whether an updated COI or endorsement was requested

When spotting fake certificates, Great American Insurance Group recommends calling the insurer or broker with publicly available contact information—not the number on the certificate—to confirm insured name, policy number, limits, and expiration.

This produces stronger evidence than a document review alone. A broker's verbal confirmation still isn't an endorsement, and it shouldn't replace written documentation when the contract requires it.

Method 3: Monitor COIs Throughout the Vendor Relationship

A COI is a point-in-time snapshot. Verification has to continue after onboarding.

What you need:

  • Renewal calendar and updated COIs
  • Vendor database or workflow system
  • Escalation rules and clear task ownership

Steps:

  1. Record every policy expiration date and set reminders far enough ahead to resolve missing renewals before work continues
  2. Trigger a new review whenever the vendor's work, location, contract value, staffing, vehicles, data access, or risk profile changes
  3. Escalate non-responsive vendors before their current coverage lapses, not after

For teams tracking dozens or hundreds of vendors, manual follow-up breaks down fastest here. Salvara's Contractor Compliance Monitoring and Muster services run recurring checks against public license, bond, and insurance registries and flag expiring coverage and status changes on a monthly cycle.

That monitoring organizes evidence and catches expiry cliffs early. It still doesn't replace direct broker or carrier confirmation when a specific policy question needs an answer.

Ongoing monitoring cuts reliance on outdated paperwork. Someone still has to own the process and escalate when a vendor stops responding.

How to Interpret the Verification Results

A COI review should end in a documented decision, not just a filed PDF. Distinguish between verified compliance, unresolved questions, and evidence that the vendor shouldn't start or continue work.

Result What it means Next step
Verified / Acceptable Identity, coverage, limits, dates, certificate holder, and endorsements align with the contract Log verification date, source checked, documents retained, and the next recheck date
Minor or Correctable Misspelled legal name, incomplete certificate holder, missing project description, unclear endorsement wording Send a written correction request; decide whether work or payment pauses until it's resolved
Out-of-Spec / Unverified Expired policy, limits below requirement, missing coverage, mismatched named insured, broker unable to confirm Notify procurement or risk management, pause affected work, request corrected documents, or consider alternative vendors
Suspicious / Fraudulent Inconsistent fonts or policy numbers, altered dates, implausible insurer details, broker denying issuance Preserve the file, contact the insurer through independently verified channels, escalate internally

That last category isn't theoretical. In January 2024, the California Department of Insurance reported that a trucking company owner faced felony charges for allegedly creating at least 13 fraudulent certificates of insurance and submitting them to 12 employers or prospective employers, using forged agent signatures and false coverage details (California Department of Insurance).

Nothing about those certificates necessarily looked wrong at first glance. That is exactly why independent confirmation matters on higher-risk engagements.

If something looks suspicious, don't accuse the vendor before you confirm. Then:

  • Preserve the original file and all related communications
  • Verify through independently sourced broker or insurer contacts
  • Escalate to internal or legal authorities if fraud seems likely

Common Errors and Safety/Best Practices

A few mistakes show up repeatedly in vendor COI reviews.

Treating the COI as proof of complete protection. It's a summary, not a policy amendment. It doesn't guarantee payment, remove exclusions, or automatically grant additional insured status, regardless of what's written in a description box. Confirm additional insured status and key coverage terms against the actual endorsements.

Applying one standard to every vendor. A landscaping crew, a data processor, and an events contractor carry different exposures. Running identical checks on all of them misses risk on some vendors and wastes effort on others. Match verification depth to each vendor's exposure and the work being performed.

Failing to control access and records. To avoid this:

  • Don't let work begin before required verification is complete
  • Restrict site or data access when coverage is unresolved
  • Store COIs and related documents securely
  • Limit sensitive policy details to authorized personnel
  • Document every exception or conditional approval, including who signed off

Conclusion

Dependable vendor COI verification combines field-by-field document review, independent confirmation with the broker or insurer when the stakes call for it, and ongoing monitoring of dates and scope changes.

Get that combination right, and you catch a coverage gap while it's still paperwork. Skip it, and you find out about the gap during a claim, when it's too late to fix.

Frequently Asked Questions

What does a certificate of insurance (COI) mean for vendors?

A vendor COI is a summary issued by an insurer or broker showing key policy information, including coverage types, limits, policy dates, and insured parties. It is not the insurance policy itself.

How hard is it to get a certificate of insurance (COI)?

Vendors typically request one from their insurance broker or carrier, and it's usually quick. Obtaining a fully compliant COI can take longer when a client requires specific limits, certificate holder language, or endorsements.

What insurance do you need as a vendor?

Requirements depend on the vendor's work, contract, location, and risk. Common options include general liability, workers' compensation, commercial auto, professional liability, cyber, product, pollution, or umbrella coverage, though no single combination applies universally.

How do you verify a vendor's certificate of insurance?

Compare it against the contract: check names, policy numbers, coverage, limits, dates, and endorsements. Then confirm material details directly with the issuing broker or insurer, especially on higher-risk engagements.

Can a vendor COI expire?

Yes. The COI reflects the policy dates shown at the time it was issued, and it becomes insufficient once those dates pass or the underlying policy changes. Request an updated certificate before expiration and recheck ongoing work.

Does being listed as a certificate holder make you an additional insured?

No. Certificate holder is an informational role. Additional insured status generally requires specific policy wording or an endorsement, which should be confirmed against the actual policy documentation, not assumed from the COI alone.