All posts

Compliance operations and audit

What a lapsed vendor COI actually costs

A policy expires in March and the file still reads compliant. The claim arrives in September. Here is how the exposure builds and what the arithmetic looks like.

The IDCore Team7 min read

A lapse costs nothing on the day it happens. That is the whole problem.

A policy expires in March. The certificate in your file still reads compliant, because a certificate is a snapshot of a moment that has passed. Nothing alerts, because nothing was watching the date. The vendor keeps working, because nobody told them to stop.

The cost arrives in September.

The sequence, and why nobody catches it in the middle

Five steps, and no decision anywhere in the chain.

Coverage expires with no notification to you. The ACORD 25 does not obligate the carrier to notify the certificate holder of cancellation, despite what many people assume.

The vendor continues working. From their side nothing changed.

An incident occurs during the uncovered window.

The claim surfaces 60 to 180 days later. Property claims lag, especially anything involving water or structural damage.

Your carrier pays, and your loss history absorbs it.

By the time you discover the lapse, the work is finished, the vendor may not be reachable, and you are reconstructing a file rather than producing one.

The arithmetic, with the assumptions visible

Per vendor per year the probability is low. That is exactly why it gets deprioritized, and it is also why it is a volume problem rather than a diligence problem.

A working model, and every input here is arguable:

Non-compliant vendor count at any moment, times an annual incident probability of roughly 0.5%, times a liability per incident.

At 300 active vendors with a 10% lapse rate at any given time, that is 30 exposed vendors. At 0.5% annual incident probability, 0.15 expected incidents a year. At a per-incident cost of $250,000 or more, that is roughly $37,500 of expected annual cost.

Which sounds survivable, and it is, right up until the one incident happens and it is the tail rather than the average. A single uninsured vendor incident can cost $250,000 or more, and in our own portfolio the internal framing was blunter: one uninsured incident could result in multi-million dollar liability landing on the manager's own policies, wiping out a year of NOI growth.

About the $375M figure we publish elsewhere

Worth being precise, because it is the number most likely to be misread.

The methodology is exactly the model above: non-compliant vendor count times an incident probability of about 0.5% a year times a default liability per incident of $1.5M.

It is modeled exposure screened. It is not claims paid, it is not losses avoided, and it is directional rather than actuarial. We label it that way on the site and we would rather say it here too.

The figures that are measured rather than modeled: 283 hours of admin recovered a year, about $8,490 in labor, and a 90% COI automation rate.

The cost you pay whether or not an incident happens

Two of them, and both are certain rather than probabilistic.

Work stops. A vendor who cannot clear compliance cannot start, and in our own portfolio a property needed a pool repair before summer and finding a compliant vendor took a month. By the time someone was on site the season was gone. Two non-renewals tied to the down amenity represented $36,000 in annualized revenue.

Time. 15 to 20 hours a week emailing vendors, chasing expired certificates, and comparing coverage to requirements by hand.

Those are the costs you are definitely paying. The claim is the one you might.

Why calendar reminders fail specifically

Most teams track this with reminders, and it half works.

The failures are structural rather than careless. A vendor carries four policies with four renewal dates, so one vendor is four reminders. A reminder fires, the vendor says the renewal is coming, and there is no mechanism to confirm it arrived. Reminders live in one person's calendar and leave with them. And a renewal certificate that arrives with insufficient coverage gets filed as a renewal rather than caught as a deficiency.

Automatic 30-day expiration alerts against a versioned certificate repository fix the mechanism rather than the diligence. IDCore keeps version history per vendor, so you can show what was on file on any given date rather than only what is current, which is the thing an audit actually asks for.

Run this number this week

Ask how many of your active vendors have a certificate that expired in the last quarter and were not stopped from working.

If nobody can answer from a system, that is the exposure, and the number is almost always larger than the room expects.

What is your current lapse rate?

Keep reading

Schedule a Demo