All posts

Compliance operations and audit

The COI review checklist: twelve checks before you clear a vendor

Twelve checks per certificate at 15 to 30 minutes each is where a compliance program dies. Here is the full list, and which four you can skip if you only have five minutes.

The IDCore Team8 min read

A complete certificate review is twelve checks. At 15 to 30 minutes each, a portfolio with a few hundred active vendors cannot keep up, which is why teams report 15 to 20 hours a week on this and still fall behind.

Here is the full list, and then the short version for when you have five minutes and a vendor who needs to start.

The twelve, in the order that fails fastest

1. Named insured matches the contracted entity exactly, including DBA. "Lone Star Plumbing LLC" against a master vendor agreement with "Lone Star Plumbing & Heating, Inc." is a mismatch. Same trucks, same crew, different legal person, and carriers notice at claim time even when nobody noticed at onboarding.

2. Your legal entity is named as certificate holder. The management company, the ownership entity, or both, depending on your agreement.

3. General liability per occurrence meets your minimum. Commonly $1M.

4. General liability aggregate meets your minimum. Commonly $2M, and check whether it is per project or shared. A vendor who has already had two large claims this year has a nearly exhausted aggregate and a perfectly valid certificate. The form has no field for how much is left.

5. Effective date is on or before the work start date.

6. Expiration date is after expected completion. A certificate collected in March for a policy expiring in June is compliant in March and useless in July.

7. Additional insured box checked on general liability.

8. Endorsement form numbers present. CG 20 10 for ongoing operations, CG 20 37 for completed operations. A vendor providing only the first is not covered for work after they finish, which is when many property claims arise.

9. Primary and non-contributory wording present. No box for this. Read the description of operations field.

10. Waiver of subrogation present. Same field, and ask about the workers compensation policy separately.

11. Workers compensation active, with employer liability limits. Or a documented exemption if the vendor is legitimately a sole proprietor in your state.

12. Description of operations read in full, with no exclusion touching your work. A roofing exclusion on a roofer's policy is real and survives review because the limits above it look correct.

Which of the twelve are actually hard

Worth separating, because the effort is not evenly distributed.

Checks 3 through 7 are boxes on a standardized form. Reading them is fast and a junior person can do it reliably.

Checks 8 through 10 and 12 are the ones that consume the time, because they require reading free text, requesting endorsement forms the vendor did not send, and knowing what an exclusion means for a specific trade. Those four are also where nearly all the real exposure sits.

So a program that degrades under load degrades in exactly the wrong direction: it keeps the easy checks and drops the ones that matter.

Check 1 fails more than people expect

Entity mismatch deserves its own note because it is the most common quiet failure.

Small trades often operate under a DBA, get insured under one entity, and sign contracts under another. Everyone involved considers them the same company because functionally they are.

At claim time the carrier reads the named insured, and if the entity you contracted with is not the entity insured, you have a certificate for a different company.

IDCore requires a W-9 at onboarding with EIN or SSN, which ties the tax identity to the compliance record and makes this mismatch visible rather than latent.

What automation collapses, and what it does not

Reading the boxes is a solved problem. IDCore extracts policy numbers, carrier, per-occurrence and aggregate limits, effective and expiration dates, named and additional insureds, endorsements, and exclusions, then matches all of it against your per-property requirement set. That takes checks 3 through 12 from half an hour to seconds, at a 90% automation rate with the remaining 10% flagged for a person.

Being clear about the limit: automation does not make an insufficient certificate sufficient. If a vendor genuinely does not carry what you require, no amount of reading gets you to compliant. Somebody has to place coverage or the work does not happen.

That is where most compliance tools stop, and it is why IDCore can write the policy in the flow through InsurePro at roughly $99 per vendor per year in 49 states rather than only reporting the deficiency.

The measured outcome in our own portfolio: 283 hours of admin recovered a year, worth about $8,490 in labor.

Sort your rejections by check number for one month

That is the diagnostic worth running.

If most of your rejections are checks 5 and 6, your problem is expiration tracking and a calendar is not solving it. If they are checks 8 through 10, your master vendor agreement is probably silent on requirements the endorsements are conditional on. If they are check 1, your onboarding is not capturing the legal entity.

Three different problems, three different owners, and you cannot tell which you have from a rejection count.

Which check do your rejections cluster on?

Keep reading

Compliance operations and audit

What a lapsed vendor COI actually costs

A policy expires in March and the file still reads compliant. The claim arrives in September. Here is how the exposure builds and what the arithmetic looks like.

7 min read
Schedule a Demo