Ask most property management companies whether their vendors are compliant and they will tell you yes, because there is a certificate of insurance on file for each one. That answer conflates two different things: having a document, and having the protection the document appears to describe.
The gap between those matters most at the worst possible moment. A contractor damages a unit, injures a resident, or leaves work that fails a year later, and the certificate that sat in the folder turns out not to do what everyone assumed it did. This is not a technicality. It is written on the face of the form.
Note before going further: this article describes how these documents work in general terms. Insurance requirements and their enforceability vary by jurisdiction and by contract, so treat it as background rather than legal advice and have your own counsel or broker review your requirements.
What a Certificate of Insurance Actually Proves
The certificate almost every US vendor supplies is the ACORD 25, a one-page summary listing the insurer, policy numbers, coverage types, limits, and dates. It is produced by the vendor's agent or broker, usually free, on request.
It is worth understanding what that means structurally. The certificate is not issued by anyone who is party to your relationship with the vendor. It is a description of a policy, prepared by an intermediary, of a contract between the vendor and their insurer that you have never seen. Every fact on it is accurate as of the moment it was printed and binding on nobody. Most compliance programs treat the certificate as the finish line. It is closer to a receipt.
1. The Form Says So Itself
The ACORD 25 carries a disclaimer near the top stating that it is issued as a matter of information only, that it confers no rights upon the certificate holder, that it does not amend, extend, or alter the coverage afforded by the policies listed, and that it does not constitute a contract between the insurer and the certificate holder.
That is the document telling you, in its own words, that it is not the thing that creates your protection.
2. Certificate Holder Is Not Additional Insured
This is the single most common and most expensive misunderstanding in vendor compliance.
Being listed as the certificate holder means you were sent a copy of the summary. It grants nothing. As Seyfarth Shaw's guidance on insurance certificates in lease transactions puts it, a certificate that merely names the property owner as certificate holder does not make that owner an additional insured, and without additional insured status the holder is not entitled to rights under the policy. Many managers see their company name printed in the certificate holder box and conclude they are covered. They are on a mailing list.
3. The Endorsement Is the Thing
Additional insured status is created by an endorsement attached to the vendor's actual policy, not by anything written on a certificate. In the standard ISO forms, CG 20 10 addresses ongoing operations and CG 20 37 addresses completed operations, which is the exposure that surfaces after the work is finished and the vendor has gone.
That distinction matters in property management specifically. A roofing contractor's ongoing-operations endorsement does nothing for you when the roof fails eighteen months later. If your requirements do not name completed operations, you have covered the smaller of the two risks.
Blanket additional insured endorsements carry conditions of their own, commonly requiring a written contract with the named insured. None of those conditions appear on the certificate. So a vendor can hand you a clean, accurate certificate describing coverage that will not respond, and nothing about the document would tell you.
Why Document Collection Is Not a Compliance Program
If the certificate is only a description, then a filing system full of certificates is a description of a description. Most property management compliance programs are exactly that: someone collects documents at onboarding, files them, and sets a reminder for the expiry date.
That process fails in three predictable ways, and none of them are visible while things are going well. They surface only when a claim arrives, which is why compliance programs tend to look fine right up until the day they do not.
1. The Snapshot Decays
A certificate is accurate on the day it is issued. Policies get cancelled for non-payment, coverage gets reduced at renewal, and a vendor's insurer can change mid-term. None of that generates a notification to you.
The 2016 ACORD 25 states that cancellation notice will be delivered in accordance with the policy provisions, which means the vendor's policy decides whether anyone tells you, and typically the person told is the vendor. A certificate that expires next March tells you nothing about whether the policy behind it is still in force this Tuesday.
2. Nobody Checks at the Moment of Risk
The compliance file is consulted at onboarding and at renewal. The risk occurs at dispatch.
When a unit floods at nine on a Saturday evening and the on-call manager rings whoever answers, nobody opens the compliance folder first. That is not a training failure, it is a sequencing failure: the check lives in a system nobody touches during an emergency, and emergencies are precisely when unvetted vendors get onto your properties.
3. The List Is Incomplete
Most portfolios have two vendor lists. The formal one, held by whoever manages procurement, and the real one, which includes the handyman a site manager has used for years, the vendor a resident called directly, and the subcontractor your general contractor brought along without telling anyone. Compliance programs govern the first list. Losses happen on the second.
What a Real Compliance Program Controls
The shift is from collecting documents to controlling access. A vendor is compliant when they cannot work on your property or receive money unless their status is current, which is a very different design from a folder that gets reviewed quarterly.
The four controls below are ordered by how much risk each removes relative to the effort involved. The first two are policy decisions. The second two are operational ones, and they are where most programs break down.
1. Set Requirements Before Onboarding, in the Contract
Insurance requirements belong in the vendor agreement, with specified minimum limits by vendor type, the named additional insured entities, and explicit reference to the endorsements required rather than to the certificate.
Requirements should scale to exposure. A landscaper and a roofer do not carry the same risk, and applying one blanket requirement to both means you are either over-specifying for the landscaper or under-specifying for the roofer. Our guide to contract management in property management covers what else belongs in the vendor agreement.
2. Ask for the Endorsement, Not Just the Certificate
For higher-exposure vendors, request a copy of the additional insured endorsement itself. This is a small ask that most brokers handle routinely, and it is the only way to confirm that what the certificate describes actually exists on the policy.
Doing this for every vendor is impractical and unnecessary. Doing it for roofers, structural contractors, and anyone working at height or with water is proportionate.
3. Verify at Dispatch, Not at Filing
Compliance status has to be visible at the moment a work order is assigned, in the same system where the assignment happens. If checking requires opening a different application, it will not happen under pressure.
The practical implementation is a status flag on the vendor record that blocks or warns on assignment when insurance has lapsed, with an override that is logged rather than silent. The override matters, because emergencies do require exceptions. What you need is for the exception to be a decision someone made, not something that happened by default.
4. Use Payment as the Enforcement Point
This is the control that actually works, and it is underused because it usually requires the accounts payable system to know something the maintenance system knows.
Vendors respond to payment holds far more reliably than to compliance reminders. A lapsed certificate that generates a fourth polite email gets ignored. A lapsed certificate that holds an invoice gets resolved the same day. Tie compliance status to the payment run and most of your chasing disappears.
The Trade-Off Worth Naming
Tightening compliance shrinks your vendor pool, and in a tight trades market that has a real cost. Small operators, who are often the responsive ones who answer at weekends, are also the ones most likely to carry minimum coverage and least likely to have a broker who returns endorsement requests quickly. Set requirements too high across the board and you lose them, then find yourself paying premium rates to larger firms with slower response times.
The answer is tiering by exposure rather than applying one standard everywhere. A vendor changing light fittings in a common area does not need what a roofer needs. Programs that ignore this either become impossible to comply with or get quietly bypassed by site staff, which is worse than having no program, because it produces documented confidence and undocumented risk at the same time.
Where the Technology Comes In
Everything above depends on one thing: the vendor's compliance status being present in the systems where work gets assigned and money gets paid. When compliance lives in a spreadsheet or a standalone tracker, it is a reference someone consults rather than a control that operates.
That is the problem RIOO is built for, and the split is worth being precise about:
-
Maintenance, work order dispatch, facility management, and vendor records run inside RIOO as a purpose-built property management layer.
-
Accounts payable, multi-entity accounting, and reporting are handled by the NetSuite core RIOO is built on, which is where that depth is native.
-
Both draw on one vendor record, which means the status a compliance team maintains is the same status the dispatch and payables processes can act on, rather than something held separately and consulted occasionally.
That shared record is what makes the difference between compliance as a document review and compliance as a property of how work and money move. RIOO runs more than 180,000 units under management across residential and commercial portfolios on that architecture.
Where to Start
Pull the list of vendors who have been paid in the last ninety days, not the list of approved vendors. The difference between those two lists is your actual exposure, and for most portfolios it is uncomfortable.
Then check three things for the highest-exposure vendors on it: whether the certificate is current, whether your entities are named as additional insured rather than certificate holder, and whether completed operations is included. That is a short exercise and it usually finds something.
Our guide to maintenance as a competitive advantage covers how the same vendor data supports owner reporting once it is in one place.
Book a RIOO Demo
RIOO keeps vendor records, work order dispatch, and payables on one system, so compliance status is enforced where the work and the money actually move. Book a demo and see how it works across your portfolio.
Frequently Asked Questions
1. What does a certificate of insurance actually prove?
It proves that the policies it lists existed on the date it was issued. The ACORD 25 states on its face that it is issued for information only, confers no rights on the certificate holder, and does not amend or alter the coverage in the policies described. It is a summary prepared by the vendor's broker, not a contract between you and the insurer, and it does not guarantee the coverage will still be in force tomorrow.
2. Is being a certificate holder the same as being an additional insured?
No, and this is the most consequential misunderstanding in vendor compliance. Certificate holder means you were sent a copy of the certificate. Additional insured status is created by an endorsement on the vendor's policy, and without it you have no rights under that policy. Seeing your company name in the certificate holder box does not mean you are covered.
3. What is the difference between CG 20 10 and CG 20 37?
Both are standard ISO additional insured endorsements. CG 20 10 grants additional insured status for ongoing operations, meaning while the work is being performed. CG 20 37 grants it for completed operations, meaning claims arising after the work is finished. Property management exposure frequently surfaces after completion, so requirements that name only ongoing operations leave the longer-tail risk uncovered.
4. How often should vendor insurance be verified?
Expiry-date tracking is the minimum, but it is not sufficient, since policies can be cancelled or reduced mid-term without the certificate holder being notified. The more effective approach is to verify at the point of use rather than on a calendar: make compliance status visible when a work order is assigned, and tie it to the payment run so a lapse holds an invoice rather than generating another reminder email.
5. Why do vendor compliance programs fail?
Usually because they collect documents rather than control access. The certificate is filed and reviewed periodically, but nobody consults the file at nine on a Saturday when a vendor is dispatched to an emergency, and the vendors who actually get paid often differ from the approved list. Programs also fail by applying one standard to every vendor, which either excludes small responsive trades or under-specifies for high-risk work.