CON 202 · Practitioner · Operations track · 10 min read

Certificate of Insurance (COI)

The one-page evidence of a party's insurance coverage — proof that a contractual risk-transfer requirement has actually been met, subject to the policies it summarizes.

Definition — what it is

A certificate of insurance is a standardized one-page document, most commonly the ACORD 25 form, issued by an insurance agent or broker that summarizes the coverages, limits, effective dates, and insurers of a party's insurance policies. In construction it is the routine evidence that a contractor, subcontractor, or vendor carries the insurance its contract requires, and that the party requesting it has been named as an additional insured where the contract demands. A COI is evidence, not a policy: it summarizes coverage but generally confers no rights and amends no policy, and its own disclaimer says so. The document that actually grants additional-insured status or waiver of subrogation is the policy endorsement, which is why a certificate alone — without the underlying endorsements — is a weaker protection than teams often assume.

Also known as: COI, Insurance Certificate, ACORD 25, Evidence of Coverage

Why it matters — what it protects

The COI is how contractual risk transfer is verified rather than merely promised. A prime contract or subcontract requires certain coverages, limits, and additional-insured status; the certificate is the routine proof that the requirement was actually satisfied before work begins. Allowing a party on-site without a compliant certificate leaves the requiring party carrying risk it contracted away on paper but never confirmed in fact.

It is the front line of the additional-insured mechanism that shifts liability up the chain. When a subcontractor's negligence injures someone, additional-insured status lets the general contractor and owner tender the claim to the sub's insurer rather than their own, protecting their loss history and premiums. That protection only exists if the endorsement behind the certificate actually grants it, on the required terms.

It governs continuity of coverage across the life of the work. Policies expire, get canceled, or get non-renewed mid-project, and a lapsed certificate means an uninsured party is on-site. Tracking effective and expiration dates and re-collecting certificates on renewal is unglamorous but is precisely where real exposure hides.

It is where the gap between paper and reality most often opens. A certificate can show the right limits while the policy contains an exclusion — for residential work, for a specific trade, for a completed-operations period — that guts the coverage exactly where a claim would land. The certificate summarizes; only the policy and its endorsements control, and reviewing the certificate without ever reading the endorsements is a common and expensive habit.

Lifecycle — how it moves

  1. Requirement definition

    The contract specifies required coverages, limits, additional-insured and waiver-of-subrogation obligations, and primary-and-noncontributory language. Vague or boilerplate requirements produce certificates that satisfy the letter but not the intent.

  2. Request to the counterparty

    The requiring party asks the counterparty's broker to issue a certificate naming it as certificate holder and, where required, additional insured. The exact wording requested drives what the broker produces.

  3. Issuance by the broker

    The agent or broker issues the ACORD certificate summarizing the counterparty's policies. Because the certificate itself is largely a summary with disclaimers, the meaningful protection depends on the endorsements it references.

  4. Review and verification

    The requiring party checks limits, dates, coverage lines, and additional-insured status against the contract, and — done properly — requests and reviews the actual endorsements. This is the step most often reduced to a glance at the limits.

  5. Acceptance and clearance to work

    A compliant certificate clears the party to begin and is usually a condition of first payment. A missing or deficient certificate should hold both, though schedule pressure often overrides this.

  6. Ongoing tracking

    Effective and expiration dates are tracked so renewals are re-collected before coverage lapses. Cancellation notice from the insurer, where available, is monitored, though modern policies rarely obligate the insurer to notify certificate holders.

  7. Renewal and re-collection

    As policies renew annually, updated certificates are gathered for every active counterparty. On multi-year projects this recurs, and lapses cluster at renewal season when volume overwhelms manual tracking.

  8. Claim and retention

    If a loss occurs, the certificate and endorsements are pulled to tender the claim to the correct insurer. Certificates are retained through the completed-operations tail because claims can arise years after the work is done.

Anatomy — the data it carries

Certificate holder
The party the certificate is furnished to. Being the holder confers no coverage by itself — it only means you received the document.
Named insured
The party actually covered by the policies. Must match the exact legal entity you contracted with, not an affiliate or DBA.
Insurers and ratings
The carriers providing each coverage and their financial strength ratings. A compliant limit from a weak or non-admitted carrier is thin protection.
Coverage lines
General liability, auto, workers' compensation, umbrella/excess, and often professional or pollution liability. Missing a required line is a common deficiency.
Limits
Per-occurrence and aggregate limits for each line, checked against the contract's required minimums. Aggregate erosion over a policy year is a hidden risk.
Policy numbers and effective/expiration dates
Identify each policy and its coverage period. Expiration dates drive the renewal tracking that prevents lapses.
Additional insured indication
Whether the holder is named additional insured. The certificate box is only a summary — the endorsement is what actually grants it.
Waiver of subrogation indication
Whether the insurer waives its right to recover against the holder. Again, only the policy endorsement makes it real.
Primary and noncontributory language
Whether the counterparty's coverage responds first and without contribution from yours. Frequently required and frequently missing from the actual endorsement.
Description of operations
The free-text box tying the certificate to a specific project or contract. Vague descriptions weaken the link between the coverage and your job.
Cancellation provision
The notice, if any, the insurer or broker will give on cancellation. Modern ACORD language usually disclaims any obligation to notify holders.
The disclaimer
The ACORD statement that the certificate confers no rights and does not amend coverage. The reason endorsements, not the certificate, are the real protection.

Failure modes — how it breaks

Certificate accepted without endorsements

The limits and additional-insured box look right, so the certificate is filed and work proceeds. Nobody requests the actual endorsements, and when a claim is tendered the insurer denies additional-insured status the certificate implied but the policy never granted.

Coverage lapse mid-project

A policy expires or is canceled during a long project and no updated certificate is collected. An uninsured party keeps working, and a loss during the gap lands on the requiring party's own insurance.

Hidden exclusion that guts the coverage

The certificate shows a healthy general-liability limit while the policy excludes exactly the work being performed — residential, a specific trade operation, or completed operations. The coverage is nominal precisely where a claim would fall.

Wrong named insured

The certificate names an affiliate, a DBA, or a related entity rather than the exact party under contract. In a claim, the insurer points out that the covered entity is not the one that did the work.

Limits met on paper, eroded in fact

The aggregate limit is shared across all of the insured's projects and has been partially consumed by other claims. The certificate shows the policy limit, but the coverage actually available to your loss is far less.

Missing primary-and-noncontributory endorsement

Additional-insured status exists but the coverage is excess to, and contributory with, yours. Your own insurer ends up sharing a loss the contract intended the counterparty's coverage to absorb first and alone.

Reliance on the cancellation-notice box

The team assumes the insurer will notify them if coverage is canceled, based on the certificate's cancellation language. Modern policies rarely obligate the insurer to do so, and the first sign of a lapse is a denied claim.

Metrics — how it is measured

Certificate compliance rate

Share of active counterparties with a current certificate meeting all contractual coverage, limit, and additional-insured requirements. The core control metric.

Endorsement verification rate

Share of certificates for which the actual additional-insured and waiver endorsements were obtained and reviewed. Separates real protection from paper.

Coverage-lapse incidents

Count of periods where an active counterparty had no valid certificate on file. Direct evidence of tracking failure and uninsured exposure.

Days to compliance

Time from work start or contract execution to a compliant certificate on file. Long lags mean parties working uninsured to the contract's standard.

Deficiency rate at intake

Share of certificates that fail review on first submission (wrong limits, missing line, missing AI). Measures counterparty and requirement quality.

Renewal re-collection rate

Share of expiring certificates replaced before expiration. The metric that most directly prevents lapses at renewal season.

Named-insured match rate

Share of certificates whose named insured exactly matches the contracting entity. Catches the affiliate/DBA mismatch before a claim does.

The AI shift — what actually changes

Conversational

You can ask the certificate file real questions: which active counterparties have coverage expiring in 30 days, which certificates do not meet the additional-insured or limit requirements of the contracts they support, and which name an entity that does not match the party under contract — with the specific certificate and contract cited.

Generative

Review becomes drafting the deficiency letter, not spotting the gap. Given a certificate and the governing contract's insurance requirements, a model produces a line-by-line compliance comparison and a request-to-cure letter itemizing exactly what is missing — wrong limit, missing line, absent additional-insured endorsement — for a reviewer to send.

Orchestrated

The certificate is checked against the contract that demands it and against the endorsements that back it: coverage lines and limits matched to the contract's minimums, named insured matched to the contracting entity, additional-insured and waiver boxes cross-checked against the underlying endorsements, and clearance-to-work and first-payment holds tied to compliance status.

Autonomous

The tracking perimeter runs itself: every active counterparty's certificate monitored against contractual requirements, expirations escalated on a fixed clock before lapse, renewal re-collection requested automatically, and deficiencies flagged at intake — while a human interprets policy endorsements, decides whether a deficiency is acceptable, and authorizes any exception that lets an underinsured party proceed.

Prompts — put it to work

Tool-agnostic and copy-ready. Adapt the specifics — thresholds, contract windows, cost codes — to your own project before you run them.

Conversational — You are onboarding a sub and need to know if the certificate actually complies.

Compare this subcontractor's certificate of insurance against the insurance requirements in our subcontract. For each coverage line the contract requires, tell me whether the certificate shows it, whether the limits meet or exceed our minimums, and whether the effective dates cover our full performance period. Confirm whether the certificate indicates additional-insured status and waiver of subrogation for us, and whether the named insured exactly matches the entity we contracted with. List every deficiency specifically, and separately flag anything that the certificate summarizes but that only a policy endorsement can actually confirm, so I know what to request before I rely on it.

What good output looks like: A line-by-line compliance comparison against the contract with specific deficiencies named, and a clear separation between what the certificate confirms and what requires the underlying endorsement.

Follow-ups:

  • Which of these gaps must be cured before this sub can start work?
  • Draft the endorsement request for additional insured and primary-and-noncontributory.
  • Does the description of operations tie this coverage to our project?

Generative — A certificate came in deficient and you need to request a cure.

Draft a request-to-cure letter to this counterparty's broker. Our subcontract requires commercial general liability of $2 million per occurrence and $4 million aggregate, business auto of $1 million, workers' compensation at statutory limits, and a $5 million umbrella, plus additional-insured status for us and the owner on a primary-and-noncontributory basis and a waiver of subrogation. The submitted certificate shows a $1 million general-liability limit, no umbrella, and does not indicate additional-insured status. Write the letter itemizing each deficiency against the contract requirement, request an updated certificate and the actual additional-insured and primary-and-noncontributory endorsements, and state that a compliant certificate is a condition of starting work and first payment. Keep it firm and professional.

What good output looks like: A firm, itemized cure letter tied to each contract requirement that requests both the corrected certificate and the underlying endorsements, and conditions start and payment on compliance.

Follow-ups:

  • Add a short internal note on which deficiencies are the highest risk if we let them start anyway.
  • Rewrite it as a friendlier first reminder before the formal cure letter.
  • What endorsement forms should we specifically ask for by number?

Orchestrated — You want a project-wide picture of who is actually insured to the contract.

Audit certificate-of-insurance compliance across every active party on this project. For each subcontractor and vendor, match their certificate on file against the insurance requirements of the contract that governs them, and report: coverage lines present versus required, limits versus minimums, effective dates versus their performance period, named-insured match, and additional-insured and waiver status. Flag every party currently working without a compliant certificate, every certificate expiring within 30 days, and every case where the named insured does not match the contracting entity. Tie each finding to the specific certificate and contract, and rank parties by the exposure their deficiency creates.

What good output looks like: A project-wide compliance audit ranked by exposure, tying each deficiency to its certificate and contract and identifying who is working or being paid without valid coverage.

Follow-ups:

  • Draft cure letters for the top five deficiencies by exposure.
  • Which parties should be placed on payment hold until they cure?
  • Which certificates need the actual endorsements pulled before we rely on them?

Autonomous — Standing policy for continuous certificate tracking across the portfolio.

Track certificates of insurance across all active projects under these rules. For every counterparty, hold a current certificate meeting the governing contract's coverage lines, limits, additional-insured, and waiver requirements as a condition of clearance to work and first payment; place and maintain a payment hold on any party without one. Monitor expiration dates and automatically request renewal certificates 45 days before expiry, escalating to the project manager at 30 days and the risk manager at 15 if not received. Flag at intake any certificate with a limit below minimum, a missing required line, a named-insured mismatch, or a missing additional-insured indication. Never accept a certificate as compliant when it lacks a required additional-insured or waiver endorsement, never release a payment hold, and never grant an exception allowing an underinsured party to proceed — route every such decision to a named human with the deficiency detailed.

What good output looks like: A continuously enforced tracking process with a short expiration-and-deficiency queue, where humans interpret endorsements and grant exceptions and every acceptance of insufficient coverage is a human decision on the record.

Follow-ups:

  • Show me every party currently on insurance-related payment hold.
  • Which certificates expire in the next 45 days and have not been renewed?
  • List all named-insured mismatches across the portfolio.

Get the full Construction AI Prompt Catalog — every prompt in the library in one document.

Maturity — locate yourself honestly

  1. Level 0 — Filed on faith

    Certificates are collected once and filed. Limits are glanced at, endorsements are never requested, and expirations are not tracked.

  2. Level 1 — Logged

    A register tracks certificates with expiration dates and a manual compliance check against limits, but endorsement review and renewal re-collection are inconsistent.

  3. Level 2 — Linked

    Certificates are tied to the governing contracts and to payment holds, so compliance status gates clearance and first payment against actual requirements.

  4. Level 3 — Assisted

    Compliance comparisons and cure letters are model-generated, deficiencies are flagged at intake, and expiration and named-insured mismatches are surfaced proactively.

  5. Level 4 — Operated

    Tracking, renewal re-collection, expiration escalation, and intake deficiency flagging run unattended, while humans interpret endorsements and authorize any exception.

Common questions

Why is a certificate of insurance not the same as proof of coverage?

A certificate is a summary issued by a broker for information only, and its own disclaimer states that it confers no rights on the holder and does not amend, extend, or alter the coverage in the policies. The actual coverage, and any grant of additional-insured status or waiver of subrogation, lives in the policy and its endorsements. That is why relying on the certificate alone is risky: it can accurately summarize a policy that contains an exclusion or lacks the endorsement the certificate implies, and only pulling the endorsements confirms what you are really protected by.

What is additional-insured status and why does it matter?

Additional-insured status extends a party's own liability coverage to another party — typically extending a subcontractor's coverage to protect the general contractor and owner for liability arising out of the sub's work. It matters because it lets the upstream parties tender a claim to the sub's insurer instead of their own, protecting their loss history and premiums. But the status is only real if the policy carries the correct additional-insured endorsement on the terms the contract requires, ideally with primary-and-noncontributory language so the sub's coverage responds first.

Should we rely on the cancellation-notice language in the certificate?

Generally no. Older certificates promised the insurer would give the holder advance notice of cancellation, but current ACORD language typically disclaims any such obligation, and insurers rarely commit to notifying certificate holders. Practically, the only reliable protection against a mid-term lapse is to track expiration dates and re-collect certificates on renewal, rather than waiting for a notice that will probably never come. A certificate can be worthless the day after a policy is quietly canceled if nobody is monitoring for it.

Read this article as markdown · Browse all 110 objects