Vendor COI tracking — the process of collecting, verifying, and monitoring certificates of insurance from contractors, suppliers, and service providers — remains one of the most under-managed risk functions in facilities, procurement, and workplace operations. A certificate of insurance (COI) is a snapshot document issued by a vendor's insurer confirming coverage types and limits: typically commercial general liability (CGL), auto liability, workers' compensation, umbrella/excess liability, and sometimes professional liability. The core problem is that a COI is not a contract, not a policy, and not a guarantee. It is an informational summary that can be outdated the day after it is issued. Best practice therefore treats COI tracking as a continuous verification workflow, not a filing exercise.

What Vendor COI Tracking Actually Involves

Also worth reading: What are the definitive vendor-ops SaaS integration best practices for modern facilities and workplace management teams? · How does vuti.app use AI-driven vendor compliance tracking to solve facility management risks? · What are the definitive NAND voltage monitoring best practices for enterprise-grade flash storage systems?

A mature COI tracking program covers five distinct activities: collection of certificates from vendors before work begins; review against your contractual insurance requirements; follow-up on deficiencies such as missing additional insured endorsements or expired dates; ongoing monitoring for lapses, cancellations, and renewals; and documentation/audit trails proving you exercised due diligence. Most organizations only do the first activity well. Industry surveys consistently show that 30–50% of collected COIs arrive with at least one deficiency — an expired policy date, a missing additional insured endorsement, inadequate limits, or a workers' compensation exclusion — yet many companies file them anyway because nobody has time to chase corrections.

The distinction between a COI and actual coverage matters more than most teams realize. ACORD 25 forms (the standard certificate format) explicitly state they confer no rights upon the certificate holder. If a vendor's policy was cancelled before the certificate date, or if the agent issued a certificate without authority, the certificate holder has no recourse against the insurer. This is why best-practice programs verify through multiple signals: checking the carrier's AM Best rating (A- VII or better is a common threshold), requesting policy numbers and endorsement copies (CG 20 10 / CG 20 37 for ongoing and completed operations additional insured status), and periodically sampling policies directly.

Why COI Tracking Fails at Most Organizations

The failure modes are predictable. First, manual spreadsheet tracking breaks down at scale: a facilities team managing 200 active vendors with annual renewals faces roughly four expiration events per week, each requiring outreach, follow-up, and re-review. Second, responsibility is fragmented — procurement collects the certificate during onboarding, but nobody owns it afterward. Third, requirements are inconsistent: one site demands $2M aggregate CGL while another accepts $1M, creating audit exposure. Fourth, there's no consequence enforcement; vendors learn quickly that work continues even when their COI lapses, which destroys compliance incentives.

There's also a fraud dimension worth taking seriously. Fake or altered certificates circulate widely — forged ACORD forms, certificates naming carriers that don't exist, or legitimate agents issuing certificates without insurer authorization. Red flags include mismatched fonts or formatting, carrier names not appearing in AM Best or state insurance department databases, limits that seem implausibly high for premium levels, and agents who resist providing direct policy verification. For high-value contracts, a direct call or email to the broker listed on the certificate costs ten minutes and eliminates most forgery risk.

Setting Defensible Insurance Requirements

Requirements should scale with risk exposure, not be copy-pasted across all vendors. Typical tiers look like this: low-risk office vendors (cleaning supplies delivery, IT peripherals) may need only general liability at $1M per occurrence / $2M aggregate plus statutory workers' compensation. Medium-risk vendors performing physical work on premises (janitorial, maintenance, moving) usually warrant $1M–$2M CGL, $1M auto liability if driving on site, workers' comp with employer's liability at $1M, and your organization named as additional insured on a primary and non-contributory basis. High-risk trades (electrical, roofing, structural work, anything involving fire, heights, or heavy equipment) commonly require $2M–$5M CGL plus a $5M+ umbrella, waiver of subrogation on workers' comp, and completed operations coverage extending 2–3 years post-project.

Two contractual mechanics deserve attention. Primary and non-contributory language ensures the vendor's policy pays before yours, protecting your loss history and premiums. Waiver of subrogation prevents the vendor's insurer from suing your company after paying a claim. Both must appear as endorsements on the policy, not merely as typed notes on the certificate, to be enforceable. Many organizations also require 30-day notice of cancellation, though note that standard ACORD certificates disclaim this obligation unless the policy itself contains it — another reason to collect the actual endorsement.

Manual vs. Automated Tracking: A Practical Comparison

FeatureSpreadsheet / Email TrackingDedicated COI Compliance PlatformManaged Service (Platform + Review Team)
Collection effortFully manual outreachAutomated requests and remindersVendor-facing portal handles chasing
Review accuracyDepends on staff expertiseRule-based flagging of deficienciesHuman reviewers plus rules
Renewal monitoringCalendar reminders, easily missedAutomatic expiration alertsContinuous monitoring incl. cancellation notices
Audit trailWeak; scattered emailsTimestamped logs per vendorFull documentation package
Typical costStaff time (~$15–30/vendor/year internal)~$2–8/vendor/month SaaS~$5–12/vendor/month including services
Best fitUnder ~50 vendors50–1,000 vendors500+ vendors or regulated industries
The economics favor automation earlier than most teams assume. If a single uninsured incident produces a claim your own policy must absorb — say a $150,000 water damage event caused by an unlicensed contractor whose COI had lapsed eight months earlier — that single event exceeds a decade of platform fees for a mid-sized vendor roster. That said, automation alone doesn't fix bad requirements definitions or non-enforcement; garbage-in problems persist regardless of tooling.

A Step-by-Step Implementation Playbook

Start by inventorying every active vendor and classifying them into the risk tiers described above. Expect this to take two to six weeks for a few hundred vendors. Next, codify written insurance requirements per tier into your standard contract templates and purchase order terms — ambiguity here is the root cause of most downstream disputes. Then establish a hard gate: no certificate, no site access, no PO release. Exceptions require documented sign-off from a named risk owner with an expiration date on the exception itself.

For collection, request certificates at onboarding and set renewal reminders 45–60 days before expiration, giving vendors time to route requests through their brokers (which routinely takes two to three weeks). Review every incoming certificate against a checklist: correct named insured matching your contracted entity, coverage types present, limits meeting tier minimums, policy periods covering the full contract term, additional insured endorsement attached (not just referenced), primary/non-contributory wording, waiver of subrogation where required, and carrier rating verified. Track deficiencies with a defined cure window — 10 business days is common — and escalate automatically if unresolved.

Finally, audit yourself annually. Sample 10% of vendor files and verify that certificates match contract requirements, exceptions were properly approved, and high-risk vendors have current endorsements on file. This self-audit becomes your defense exhibit if a claim occurs and opposing counsel alleges negligent vendor management.

Common Mistakes That Create Real Liability

Accepting a certificate as proof of coverage is mistake number one, covered above. Mistake number two is letting certificates lapse silently: many programs collect at onboarding and never check again, meaning a three-year contract may operate uninsured in years two and three. Mistake number three is inconsistent entity naming — if your contract is with "Acme Holdings LLC" but the certificate names "Acme Inc.," the additional insured status may not protect the right entity. Mistake number four is ignoring subcontractors; prime contractors frequently use subs whose coverage you never see, so require flow-down clauses obligating primes to collect and furnish sub COIs. Mistake number five is treating project-based work as covered by an old annual certificate — project-specific endorsements and per-project aggregate limits exist precisely because blanket certificates often exclude them.

A subtler error is over-collecting. Demanding $5M limits from a flower delivery vendor wastes goodwill, slows onboarding, and trains vendors to ignore your requests. Right-sizing requirements per tier keeps the program credible and enforceable.

When to Act and What It Costs

Act now if any of these apply: you have vendors performing physical work on your sites whose certificates haven't been reviewed in over 12 months; your contracts lack specific insurance requirement language; you cannot produce a current COI for a randomly selected active vendor within one hour; or you've experienced an incident where vendor insurance status was unclear. The remediation sequence is straightforward — freeze new high-risk engagements until requirements are codified, run a 90-day re-certification sweep of existing vendors, then move to steady-state monitoring.

On cost: doing nothing is the most expensive option, since uninsured vendor incidents fall back onto your GL policy, your deductible, and your loss history. Internal manual tracking consumes roughly 20–40 minutes per vendor per year in staff time once chasing is counted. SaaS platforms generally price per active vendor, commonly in the $2–8 per vendor per month range depending on volume and features, with managed-review services adding several dollars more. For a 300-vendor program, budgeting $7,000–$25,000 annually for software-plus-services is realistic, versus one part-time coordinator's salary ($35,000–$55,000 fully loaded) for a manual approach that still misses renewals. Facilities and workplace teams running multi-site operations tend to see the fastest payback because vendor counts scale with locations while headcount doesn't.

Where COI Tracking Is Heading

Three trends are reshaping the function through 2026. Direct data integrations between platforms and insurance carriers/brokers are reducing reliance on PDF certificates altogether, enabling real-time verification instead of point-in-time snapshots. Continuous monitoring services now alert certificate holders to cancellations within days rather than at annual renewal. And vendor-ops platforms increasingly bundle COI compliance alongside broader vendor lifecycle management — onboarding, site access credentials, safety certifications, and contract documents — because facilities teams have made clear they don't want six disconnected tools. Organizations evaluating options in 2026 should weight integration depth and reviewer quality over raw feature lists, since the failure point in nearly every program is human follow-through, not software capability.