If you've ever hired a contractor, leased space to a business, or brought on a vendor and someone said "send over your COI," this is the explainer you needed at the time. A certificate of insurance sounds bureaucratic, but it's a simple document that answers one question: if this vendor causes damage or someone gets hurt, is there an insurance policy that covers it — or does it become your problem?
What a certificate of insurance actually is
A certificate of insurance (COI) is a one-page summary, issued by an insurance company or agent, that lists the insurance policies a business currently has in force. It's not the policy itself — it's proof that a policy exists, along with the key details: what type of coverage, how much, and when it expires.
A typical COI for a contractor or vendor lists two coverages side by side:
- General liability (GL) — covers bodily injury or property damage the business causes to someone else while doing the work.
- Workers' compensation (WC) — covers medical costs and lost wages if one of the vendor's own employees is injured on the job.
Depending on the industry, a COI might also show commercial auto coverage, an umbrella/excess liability policy, or professional liability (errors & omissions) coverage.
Why businesses require a COI before letting a vendor start work
The reason COIs exist is liability transfer. When you hire a subcontractor, a landscaper, a cleaning crew, or any outside vendor, you want their insurance to pay for accidents they cause — not yours. Requiring a current COI before work starts is how a business confirms that protection is actually in place, instead of taking someone's word for it.
This matters even more than it looks like on the surface, because of how commercial insurance premium audits work. If a vendor working on your site turns out to be uninsured — no current GL or WC policy — your own carrier can reclassify that vendor's crew as your employees during your annual audit. Their payroll gets added to yours, at your rate, which can mean a five- or six-figure surprise on your next audit bill. A current certificate on file is what protects you from that.
That's why general contractors require COIs from every subcontractor, why property managers require them from landscaping and maintenance vendors, and why farms and ag operations increasingly require them from custom harvesters, equipment lessors, and seasonal labor contractors. It's the same exposure in every case: an uninsured vendor's risk becomes your risk the moment they're on-site without one.
What to actually check on a certificate before you file it away
Not every COI that lands in your inbox is good enough to rely on. Before treating a certificate as current and compliant, check these four things:
1. The coverage limits
Most contracts specify a minimum — commonly $1 million per occurrence / $2 million aggregate for general liability. A certificate showing lower limits than your contract requires doesn't satisfy the requirement, even if the coverage type is correct.
2. Additional insured status
If your contract requires it, you (or your business) should be listed as an "additional insured" on the vendor's general liability policy — usually noted in the description box or on a separate endorsement page. This extends some of their coverage's protection to you directly, rather than relying on them to make a claim on your behalf.
3. The expiration date
This is the one that causes the most damage, because it's silent — a certificate that was perfectly valid the day you filed it can lapse eight months later with nobody noticing until an accident happens or an audit asks for proof.
4. Who issued it
A legitimate COI comes from a licensed insurance agent or carrier, not from the vendor themselves. If something looks off — no agent contact information, no policy number, inconsistent formatting — it's worth a quick call to confirm the coverage is real.
Checking a certificate once is easy. Checking every vendor's certificate, tracking every expiration date, and following up before each one lapses is the part that turns into a full-time job once you have more than a handful of vendors. That's the specific problem CertWatch exists to solve — it emails your vendors' agents automatically as renewal dates approach and keeps following up until a current certificate is on file, so nothing quietly expires in a folder nobody checks.
The bottom line
A certificate of insurance is proof, not paperwork for its own sake. Requiring one from every vendor — and actually verifying the limits, the additional insured status, and the expiration date — is how a business keeps someone else's risk from becoming its own. The hard part isn't understanding what a COI is. It's staying on top of dozens or hundreds of them without a system.