Compliance operations and audit
What a lapsed vendor COI actually costs
A policy expires in March and the file still reads compliant. The claim arrives in September. Here is how the exposure builds and what the arithmetic looks like.
A lapse costs nothing on the day it happens. That is the whole problem.
A policy expires in March. The certificate in your file still reads compliant, because a certificate is a snapshot of a moment that has passed. Nothing alerts, because nothing was watching the date. The vendor keeps working, because nobody told them to stop.
The cost arrives in September.
The sequence, and why nobody catches it in the middle
Five steps, and no decision anywhere in the chain.
Coverage expires with no notification to you. The ACORD 25 does not obligate the carrier to notify the certificate holder of cancellation, despite what many people assume.
The vendor continues working. From their side nothing changed.
An incident occurs during the uncovered window.
The claim surfaces 60 to 180 days later. Property claims lag, especially anything involving water or structural damage.
Your carrier pays, and your loss history absorbs it.
By the time you discover the lapse, the work is finished, the vendor may not be reachable, and you are reconstructing a file rather than producing one.
The arithmetic, with the assumptions visible
Per vendor per year the probability is low. That is exactly why it gets deprioritized, and it is also why it is a volume problem rather than a diligence problem.
A working model, and every input here is arguable:
Non-compliant vendor count at any moment, times an annual incident probability of roughly 0.5%, times a liability per incident.
At 300 active vendors with a 10% lapse rate at any given time, that is 30 exposed vendors. At 0.5% annual incident probability, 0.15 expected incidents a year. At a per-incident cost of $250,000 or more, that is roughly $37,500 of expected annual cost.
Which sounds survivable, and it is, right up until the one incident happens and it is the tail rather than the average. A single uninsured vendor incident can cost $250,000 or more, and in our own portfolio the internal framing was blunter: one uninsured incident could result in multi-million dollar liability landing on the manager's own policies, wiping out a year of NOI growth.
About the $375M figure we publish elsewhere
Worth being precise, because it is the number most likely to be misread.
The methodology is exactly the model above: non-compliant vendor count times an incident probability of about 0.5% a year times a default liability per incident of $1.5M.
It is modeled exposure screened. It is not claims paid, it is not losses avoided, and it is directional rather than actuarial. We label it that way on the site and we would rather say it here too.
The figures that are measured rather than modeled: 283 hours of admin recovered a year, about $8,490 in labor, and a 90% COI automation rate.
The cost you pay whether or not an incident happens
Two of them, and both are certain rather than probabilistic.
Work stops. A vendor who cannot clear compliance cannot start, and in our own portfolio a property needed a pool repair before summer and finding a compliant vendor took a month. By the time someone was on site the season was gone. Two non-renewals tied to the down amenity represented $36,000 in annualized revenue.
Time. 15 to 20 hours a week emailing vendors, chasing expired certificates, and comparing coverage to requirements by hand.
Those are the costs you are definitely paying. The claim is the one you might.
Why calendar reminders fail specifically
Most teams track this with reminders, and it half works.
The failures are structural rather than careless. A vendor carries four policies with four renewal dates, so one vendor is four reminders. A reminder fires, the vendor says the renewal is coming, and there is no mechanism to confirm it arrived. Reminders live in one person's calendar and leave with them. And a renewal certificate that arrives with insufficient coverage gets filed as a renewal rather than caught as a deficiency.
Automatic 30-day expiration alerts against a versioned certificate repository fix the mechanism rather than the diligence. IDCore keeps version history per vendor, so you can show what was on file on any given date rather than only what is current, which is the thing an audit actually asks for.
Run this number this week
Ask how many of your active vendors have a certificate that expired in the last quarter and were not stopped from working.
If nobody can answer from a system, that is the exposure, and the number is almost always larger than the room expects.
What is your current lapse rate?
Keep reading
Compliance operations and audit
The COI review checklist: twelve checks before you clear a vendor
Twelve checks per certificate at 15 to 30 minutes each is where a compliance program dies. Here is the full list, and which four you can skip if you only have five minutes.
COI mechanics and document literacy
Waiver of subrogation and primary and non-contributory, in plain English
Two clauses decide whether your carrier pays for somebody else's negligence. Neither is a checkbox on the ACORD form, so most compliance programs never confirm them.
Compliance operations and audit
EMR is the only number on a vendor's insurance that predicts future losses
Limits tell you what a policy pays. Experience modification rate tells you how often that vendor's crews get hurt, and it is the one number worth asking for.