All posts

Compliance operations and audit

An insurance audit asks for one vendor's file, not your compliance rate

Owners, lenders, and carriers audit vendor compliance by sampling. A 94% portfolio rate does not help if the four they picked are in the 6%.

The IDCore Team8 min read

Three parties audit your vendor compliance, and they ask completely different questions.

Your insurance carrier wants to know whether you transferred risk to your contractors, because it affects your premium. Your lender wants to know whether the covenants in the loan documents are being met. Your owner wants to know whether their asset is exposed.

None of them ask for your compliance percentage. Each of them picks specific vendors and asks for those files.

Sampling is why an aggregate number does not protect you

A portfolio at 94% compliance sounds defensible until an auditor picks four vendors and two of them are in the other 6%.

The auditor's conclusion from that sample is not "94% compliant." It is that half the files they checked had gaps, which is a finding about your process rather than about those two vendors.

That asymmetry is the whole reason to care about the tail rather than the average. The vendors most likely to be in your non-compliant 6% are also the ones an auditor is most likely to select, because auditors select on risk. The roofer, the abatement contractor, and the pool company get picked. The office supply vendor does not.

So the operationally correct target is not a higher portfolio percentage. It is zero gaps among high-risk trades, with a known and explained set of gaps elsewhere.

What a file has to contain to survive a sample

For each sampled vendor, an auditor typically wants:

The current certificate of insurance, in force on the date of the work being examined. Not the current one, the one that was current then. This is the request most programs cannot fill, because they overwrite rather than archive.

The endorsements the certificate references. Additional insured, waiver of subrogation, primary and non-contributory. The certificate's description box claiming them is not the endorsement.

The signed vendor agreement, showing the insurance and indemnity requirements the certificate is being measured against.

Evidence of continuous coverage across the work period, meaning no gap between the expiration of one policy and the inception of the next.

Your review record: who checked it, when, against which requirement set, and what they found.

That fifth item is the one that separates a program from a filing cabinet. An auditor reading a folder of certificates with no review trail concludes documents were collected. A review record with a date, a reviewer, and a result concludes the requirement was enforced.

Gaps between renewals are the finding auditors reach for

A vendor with a policy expiring March 31 and a new one incepting April 8 has an eight-day gap.

If any work happened in those eight days, that work was uninsured, and the certificate on file for April looks perfectly compliant. Nothing in a current-state compliance view shows the gap, because both certificates are valid documents.

Finding these requires comparing consecutive policy periods per vendor and flagging any discontinuity, then checking whether work orders fell inside it. It is a straightforward query and it is not something most programs run, which is exactly why an auditor asks.

Worth being clear that IDCore tracks expiration and sends reminders ahead of it, and that reminder-based prevention is a different thing from retrospective gap detection across archived certificate versions. Preventing the gap is what the reminders are for. Proving there was never one is a reporting question.

The description box is where audits find soft failures

Certificate description boxes routinely carry language like "Additional insured status applies per written contract" or "Waiver of subrogation applies where required by written agreement."

Both are conditional statements about what the policy might do. Neither is an endorsement, and an auditor who knows the difference treats them as unverified.

The endorsement forms are the evidence: the CG 20 10 or CG 20 37 family for additional insured on general liability, a separate form for the waiver, and something equivalent on the auto and umbrella policies if your requirements reach them.

Requiring endorsement copies rather than certificate language is more friction at onboarding and it is the difference between a file that passes and a file that generates a finding.

Run the audit on yourself first, on eight vendors

The cheapest preparation is a self-sample, and it should be biased the way a real auditor's would be.

Pick eight vendors: your two highest-risk trades, your two highest-spend vendors, two that were onboarded in the last ninety days, and two that have been with you for years without review.

For each, assemble the five items above. Time yourself.

The last two in that list are usually where it falls apart, because a vendor onboarded six years ago against a requirement set you have since raised is compliant against the old standard and nobody re-checked.

What the platform does with this

Vendor records with expiration-tracked documents, requirement sets configurable per trade, AI reading of the ACORD form against those requirements, automated vendor reminders, and reporting on which vendors fail which specific check rather than a single compliance score.

The reason the reporting matters more than the score: an auditor asks about vendors, so the useful output is a list of named vendors with named gaps. ResProp's own program recovered 283 hours a year, about $8,490 in administrative cost, by moving that from manual chasing to automated tracking, and the audit benefit was separate from the time saved.

Where we stop: we do not represent you in an audit, we do not certify compliance to a third party, and we do not interpret whether your requirement set satisfies your loan covenants. The first two are yours, and the third belongs to counsel who has read the loan documents.

Pick eight and time it

If assembling five items for eight vendors takes more than an hour, an audit will find that out on your behalf, at a worse moment.

How long did it take?

Keep reading

Compliance operations and audit

What a lapsed vendor COI actually costs

A policy expires in March and the file still reads compliant. The claim arrives in September. Here is how the exposure builds and what the arithmetic looks like.

7 min read
Schedule a Demo