Most property teams collect certificates of insurance. Far fewer verify them, and the gap between those two things is where the exposure lives.
A drawer full of certificates looks like compliance. Then a contractor's scaffold fails, someone is hurt, and the claim goes to a policy that lapsed in March, or to an additional insured endorsement that was never actually issued, or to an aggregate limit that three earlier claims already consumed. The paperwork was complete. The protection was not.
This article covers what a certificate proves and what it does not, how to read one, what to require from vendors, and how to build a tracking process that survives a real loss.
Key takeaways
-
A certificate is a snapshot, not a contract. In its own words it confers no rights on the holder.
-
Additional insured status comes from the policy, not from a tick in a box on the certificate.
-
Three endorsements do the actual risk transfer: additional insured, primary and non-contributory, and waiver of subrogation.
-
The limits shown may already have been reduced by paid claims.
-
The failure mode is not collecting certificates. It is collecting them once and never checking again.
In this guide
-
What is a certificate of insurance?
-
What is the difference between a certificate and an endorsement?
-
How do you read a certificate of insurance?
-
What insurance should you require from vendors?
-
Which endorsements actually transfer risk?
-
How often do certificates need renewing?
-
Do tenants need to provide certificates too?
-
How do you build a COI tracking process that holds?
-
Common mistakes
-
Frequently asked questions
What is a certificate of insurance?
Short answer: A certificate of insurance is a one-page summary of a policy's coverages, limits, and dates as of the day it was issued. In the United States it is usually the ACORD 25 form. It evidences that a policy existed at that moment. It is not the policy, it does not amend the policy, and it can be out of date the day after it is issued.
The form is explicit about this. The header on the ACORD 25 certificate of liability insurance states that it is issued as a matter of information only and confers no rights on the certificate holder, that it does not amend, extend, or alter the coverage afforded by the policies listed, and that it does not constitute a contract between the insurer, the producer, and the holder.
That wording is not defensive boilerplate. It exists because insurance law generally prevents an insurer from creating coverage through anything other than the policy itself. A broker cannot grant you rights by typing them onto a certificate.
The practical consequence is uncomfortable. If your entire vendor insurance process ends at receiving a certificate, you have collected a document that explicitly tells you it gives you nothing.
What is the difference between a certificate and an endorsement?
Short answer: The certificate describes coverage. The endorsement creates it. An endorsement is a document that amends the actual policy, adding a party, waiving a right, or changing a term. A certificate can indicate that an endorsement exists, but it cannot substitute for one.
As insurance advisers put it, the certificate points at coverage while the endorsement is the coverage, and the common failure is a drawer full of certificates collected once and never verified. A policy lapses, an additional insured endorsement was never issued, a limit sits below what the contract required, and none of it surfaces until a loss needs the coverage the certificate implied.
|
Certificate of insurance |
Endorsement |
|
|---|---|---|
|
What it is |
A summary issued for information |
A document amending the policy |
|
Legal effect |
Confers no rights on the holder |
Changes the contract of insurance |
|
Who issues it |
The producer, meaning the broker or agent |
The insurer |
|
Currency |
Accurate on its issue date only |
Effective for the period stated |
|
What it proves |
A policy existed that day |
The specific grant of coverage |
The ACORD 25 carries a second notice below its main disclaimer making the point directly: if the certificate holder is an additional insured, the policy must contain additional insured provisions or be endorsed, and a statement on the certificate does not confer rights in place of that.
The phrase "provisions or be endorsed" was added deliberately in a later edition of the form, because many carriers grant additional insured status through blanket provisions built into the coverage form and triggered by a written contract, rather than by a separate scheduled endorsement. Either route is valid. The point is that the grant has to exist somewhere in the policy. The certificate cannot create it.
How do you read a certificate of insurance?
Six things to check, in order of how often they go wrong.
|
What to check |
What goes wrong |
|---|---|
|
Issue date |
An old certificate proves nothing about today. If it predates the current policy period, it is stale |
|
Policy effective and expiry dates |
The coverage window has to cover the whole engagement, not just the day the vendor was onboarded |
|
Named insured |
The entity on the certificate must be the entity doing the work. Subsidiaries, trading names, and subcontractors are common mismatches |
|
Certificate holder |
Your correct legal entity, named in full. A generic or wrong entity means the certificate is not for you |
|
Coverage types and limits |
Compare line by line against what your contract requires. One limit short is a common reason to hold a job |
|
Additional insured box and endorsements |
A tick indicates a grant is supposed to exist. Ask for the endorsement or the policy provision that creates it |
Two details on the form that catch people out.
The limits may already be spent. The certificate carries a note that limits shown may have been reduced by paid claims. A $2 million aggregate with $1.6 million already paid out this policy year gives you $400,000, and the certificate will not tell you that.
The description of operations box matters. The free-text area, which overflows onto a supplementary form, is where project references, contract wording, and endorsement references sit. It is the part most people skim and the part that most often carries the specifics your contract asked for.
What insurance should you require from vendors?
Short answer: As a baseline for anyone performing work on the property, commercial general liability, workers' compensation, and commercial auto. Higher-risk or larger-scope work usually adds umbrella or excess liability above the general liability limits. Requirements should scale with the risk of the work rather than being uniform across the vendor base.
|
Coverage |
Why you require it |
Typical trigger |
|---|---|---|
|
Commercial general liability |
Third-party bodily injury and property damage arising from the vendor's work |
Every vendor on site |
|
Workers' compensation |
Injury to the vendor's own employees, which otherwise looks for another payer |
Every vendor with employees |
|
Commercial auto |
Vehicles used in the vendor's operations on your property |
Any vendor driving to or on site |
|
Umbrella or excess liability |
Coverage above the primary limits when a loss exceeds them |
Roofing, structural, mechanical, electrical, demolition, major renovation |
|
Professional liability |
Errors in professional judgment rather than physical damage |
Architects, engineers, consultants |
On limits, one million per occurrence and two million aggregate is a common baseline for general liability across residential and commercial property vendors. The two numbers mean different things: per occurrence caps what the carrier pays for a single incident, aggregate caps total payments across the policy year. Contracts usually specify both, and they should.
The judgment worth making is proportionality. A window cleaner and a demolition contractor should not carry the same requirement. A uniform requirement set too high excludes small vendors you need, and set too low leaves you exposed on the work that actually carries risk. Set tiers by trade and scope, write them into your vendor onboarding, and apply them consistently.
Where vendor onboarding, documentation, and approval already sit in a structured process, this becomes a field rather than a project. RIOO's guide to vendor management strategies covers the onboarding side.
Which endorsements actually transfer risk?
This is the part most property teams never get to, and it is the part that determines whether the coverage responds to you at all.
|
Endorsement |
What it does |
Why it matters |
|---|---|---|
|
Additional insured |
Adds your entity as an insured on the vendor's policy |
Without it, you generally have no direct route to claim on their coverage. This is the most commonly assumed and most commonly missing grant |
|
Primary and non-contributory |
Intended to make the vendor's policy respond first rather than sharing with yours |
Without it, your own insurer may end up contributing to a loss the vendor caused |
|
Waiver of subrogation |
Prevents the vendor's insurer recovering from you after paying a claim |
Without it, the money can come back around |
For additional insured status, two standard forms are worth knowing by name. One grants the status for ongoing operations, meaning while the work is being performed. A separate one covers completed operations, meaning claims that surface after the work is finished. Construction and renovation work generally needs both, because a defect can appear years after a contractor left the site. A vendor who provides one and not the other has covered you for half the exposure.
Ask for the endorsement documents themselves, or the policy provision that grants the status, rather than accepting the certificate's indication that they exist. How these provisions operate in a specific loss also depends on the other terms of both policies, which is a conversation for your broker rather than an assumption to carry.
How often do certificates need renewing?
Short answer: Most general liability and workers' compensation policies renew annually, so certificates need refreshing at least once a year. Request the replacement 30 to 60 days before expiry rather than on the day, because chasing a certificate from a vendor who is already working uninsured is the worst position to negotiate from.
What to do when one lapses is a policy decision that should be made before it happens.
-
Record the expiry date at intake, not when someone needs it. This is the single highest-leverage habit in the whole process.
-
Set the reminder well ahead, typically 30 to 45 days.
-
Define the consequence in the contract. A common approach is that if a vendor cannot produce a current certificate within a set number of business days, work is suspended until they can.
-
Gate dispatch on compliance status. A vendor whose insurance has lapsed should not be assignable to a work order until the status is restored. A reminder nobody enforces is a reminder nobody reads.
The last point is where a tracking spreadsheet fails and a system holds. A spreadsheet tells you a certificate expired. It does not stop the dispatcher sending that vendor to a job the following morning.
Do tenants need to provide certificates too?
Short answer: In most commercial leases, yes. Tenants are typically required to carry general liability and to name the landlord or property manager as an additional insured. Requirements vary by lease type, tenant industry, and property class, so the obligation has to be read from each lease rather than applied as a standard.
This creates a second tracking stream with the same mechanics and the same failure mode. Both vendors and tenants require collection, verification, and renewal tracking. Both create exposure when they lapse. The difference is that tenant requirements sit in individual lease documents rather than in a standard vendor policy, so the required coverages, limits, and endorsements have to be extracted per lease and recorded against that tenancy.
How do you build a COI tracking process that holds?
Short answer: One record per vendor rather than per property, expiry dates captured at intake, verification against the contract requirement rather than against the last certificate, and a compliance status that actually gates work.
Six components:
-
One canonical vendor record. A plumber working across six properties should appear once, with one compliance status visible from every property. Folders of forwarded emails and a shared drive of inconsistently named files are not a system.
-
Requirements recorded per vendor tier. What this trade at this scope must carry, so verification is against a standard rather than against memory.
-
Expiry captured at intake. Every certificate, every licence, recorded on receipt.
-
Verification, not just collection. Coverage types, limits, named insured, certificate holder, and endorsements checked against the requirement. A certificate that arrives is not a certificate that passes.
-
Compliance status that gates dispatch. Non-compliant means not assignable, enforced by the system rather than by whoever remembers.
-
An audit trail. What was held, when it was verified, by whom, and what was outstanding. This is what you produce when an insurer or a claimant asks. Keeping it alongside the vendor payment and record history means one vendor record rather than three.
Common mistakes
|
Mistake |
What it costs |
|---|---|
|
Treating the certificate as the coverage |
You hold a document that states it confers no rights |
|
Accepting the additional insured tick box |
The status may never have been granted on the policy |
|
Filing certificates without recording expiry |
Nobody knows what lapsed until a claim asks |
|
One certificate per property rather than per vendor |
The same vendor is compliant on one property and lapsed on another |
|
Requiring identical limits from every vendor |
Over-restricts small vendors, under-protects on high-risk work |
|
Ignoring the aggregate |
The limit shown may already be substantially consumed |
|
Requesting renewals on the expiry date |
You are negotiating with a vendor already working uninsured |
|
No consequence for lapse |
The requirement becomes advisory |
Frequently asked questions
1. What is a certificate of insurance?
A one-page summary of a policy's coverages, limits, and dates as of its issue date, usually on the ACORD 25 form. It evidences that a policy existed at that moment. It is not the policy and does not amend it.
2. Is a certificate of insurance legally binding?
No. The form states that it is issued for information only, confers no rights on the certificate holder, does not amend or alter the coverage in the policies listed, and does not constitute a contract between the insurer, the producer, and the holder.
3. What is the difference between a certificate of insurance and an endorsement?
The certificate describes coverage. The endorsement amends the policy to create it. A certificate can indicate that an endorsement exists but cannot substitute for one, and the form says so explicitly.
4. What is the difference between additional insured and certificate holder?
Certificate holder means you receive a copy of the certificate. Additional insured means your entity is covered under the vendor's policy and can claim on it. They are frequently confused, and only the second one protects you.
5. What insurance should I require from vendors?
As a baseline, commercial general liability, workers' compensation, and commercial auto for anyone working on the property. Higher-risk or larger-scope work generally adds umbrella or excess liability. Requirements should scale with the risk of the work rather than being uniform.
6. What coverage limits should a property manager require?
One million per occurrence and two million aggregate is a common baseline for general liability across property vendors, with higher requirements for higher-risk trades. Per occurrence caps a single incident, aggregate caps the policy year, and contracts should specify both.
7. What is a waiver of subrogation?
An endorsement preventing the vendor's insurer from recovering from you after paying a claim. Without it, a loss the vendor's policy paid can come back to you through their insurer.
8. What does primary and non-contributory mean?
Wording intended to make the vendor's policy respond first without drawing on your own coverage. Without it, your insurer may end up contributing to a loss caused by someone else's work.
9. How often do certificates of insurance need to be renewed?
Most general liability and workers' compensation policies renew annually, so certificates need refreshing at least once a year. Request the replacement 30 to 60 days ahead of expiry.
10. What should you do if a vendor's insurance lapses while they are working?
Suspend the work until a current certificate is produced, and define that consequence in the contract in advance. Compliance status should gate work assignment, so a lapsed vendor cannot be dispatched.
Vendor insurance compliance fails quietly. Nothing goes wrong on the day a certificate expires, or on the day an additional insured endorsement turns out never to have been issued. It goes wrong months later, at the only moment the coverage mattered.
The process that survives that moment is not a more organised filing system. It is verification against a written requirement, recorded at intake, with a compliance status that stops work rather than merely reporting on it.
This article provides general information and is not legal or insurance advice. Insurance requirements, policy forms, and how specific endorsements operate vary by jurisdiction, by carrier, and by contract. Confirm your requirements and your position with your broker and legal adviser.