Most property teams collect certificates of insurance. Far fewer can answer, on any given Tuesday, whether the vendor currently standing on a roof has coverage that hasn't lapsed.
Those are different problems. The first is a filing exercise. The second is the one that matters when something goes wrong — and the gap between them is where uninsured work quietly happens.
Insurance requirements vary by jurisdiction, property type, lease terms, and your own carrier's expectations. Your broker or risk manager sets the standard for your portfolio — this article is general information to help you ask better questions, not insurance or legal advice.
A certificate is evidence, not coverage
This is the single most misunderstood thing about COIs, so it's worth being blunt: the certificate itself grants you nothing. It's a summary document — typically an ACORD form — describing policies that exist somewhere else. Most carry explicit language saying they confer no rights and don't amend the underlying policy.
What that means practically:
- It's a snapshot. It describes coverage as of the day it was issued. A policy can be cancelled the following week and the certificate in your folder will look exactly as valid as it did before.
- It's typed by a person. Usually the vendor's broker, often from a request the vendor made. Errors and optimistic descriptions happen.
- The protection lives in the endorsement. If you need to actually be covered under a vendor's policy, that comes from a policy endorsement — the certificate only references it. For high-value work, ask for the endorsement, not just the certificate.
Certificate holder is not additional insured
If you take one technical distinction away from this article, make it this one, because it is routinely confused and the consequences are real.
| Status | What it actually gives you |
|---|---|
| Certificate holder | You receive a copy of the certificate. In some cases you may be notified of cancellation — though notice provisions are often weaker than people assume. It does not extend the vendor's coverage to you. |
| Additional insured | You are added as an insured party under the vendor's policy, generally for liability arising from their work. This is the status that responds if a claim names you. |
Being listed only as certificate holder while assuming you have additional insured protection is a common and expensive misunderstanding. Check which one you are — and confirm the entity name is exactly right. “Fox Grape LLC” and “Fox Grape Property Management, LLC” are not the same legal entity, and a mismatch is precisely the kind of thing that surfaces at claim time.
What to look at on the certificate
Coverage lines
Which lines you require depends on the trade and the work, but commonly:
- Commercial general liability — third-party bodily injury and property damage. The baseline.
- Workers' compensation — arguably the one you can least afford to skip. If an uninsured contractor's employee is injured on your property, exposure can flow in directions people don't anticipate.
- Commercial auto — relevant for anyone driving to sites, which is most vendors.
- Umbrella / excess — sits above the primary limits, often required to reach a contractual threshold.
- Professional liability — for design, engineering, and consulting work where the risk is a bad recommendation rather than a physical accident.
- Pollution or environmental — for trades that disturb hazardous materials.
Limits
Check both the per-occurrence limit and the general aggregate — and remember the aggregate is shared across everything that policy covers for that period. A vendor working across many properties may have far less remaining capacity than the certificate suggests.
The endorsement language
Three terms worth requiring on higher-risk work, and confirming rather than assuming:
- Additional insured — discussed above
- Waiver of subrogation — stops the vendor's insurer from turning around and pursuing you after paying a claim
- Primary and non-contributory — their policy responds first, rather than sharing with yours from dollar one
Dates
Each coverage line has its own effective and expiration date, and they frequently don't align. A vendor can be current on general liability and three months lapsed on workers' comp. Tracking one date per vendor hides exactly this.
Why COI tracking fails in practice
Almost nobody fails at collecting the first certificate. Onboarding is when attention is highest and the vendor is motivated. The failure is what happens over the following eighteen months.
- Policies renew annually; attention doesn't. The certificate you collected in March expires next March, at which point nobody is thinking about that vendor.
- Chasing renewals is low-status work. It means emailing a vendor who has no urgency, then following up. It slips behind anything with a deadline.
- Lapses are invisible. Nothing changes when a certificate expires. The vendor keeps getting assigned work. There's no error, no alert, no friction — until a claim.
- The file is separate from the work. COIs live in a shared drive or a spreadsheet; work assignment happens in a different system. Nobody cross-references at the moment of assignment, because it would mean leaving what they're doing.
Tracking is passive. Enforcement is the point.
Here's the structural insight, and it's the reason spreadsheets don't solve this: a list of expiry dates doesn't stop anyone from assigning work.
You can maintain an immaculate tracker and still have an uninsured vendor on site tomorrow, because the tracker is something you consult and the assignment is something you do. Any control that depends on a busy person remembering to check a second system before acting will eventually fail — not because they're careless, but because that's what happens to every control built on remembering.
The version that works has two halves:
- Alert before the lapse, not after. Thirty to sixty days of warning gives you time to chase the renewal while the vendor is still compliant, instead of scrambling after the fact.
- Enforce at the point of assignment. If a vendor's coverage has lapsed — or they were never approved for that property — assigning them work should be blocked where the assignment happens. Not flagged in a report someone reads later. Blocked, then.
That second one is what converts insurance compliance from a filing habit into an actual control.
When properties have a higher bar
Some sites carry requirements well beyond “has a current COI.” Bank branches are a good example: it's common to see pre-approved vendor lists, background-check requirements, escorted access, higher liability limits, and restrictions on who may work near secure areas — driven by the operator's own regulatory and security obligations. Similar patterns show up in healthcare, data centers, government facilities, and schools.
The operational implication is that approval is per-property, not global. A vendor perfectly acceptable at a suburban office may not be approved for a branch with a vault. Any system enforcing this needs approval scoped to the property or category, not a single company-wide approved flag.
A working checklist
- Required coverage lines and minimum limits are defined in writing, per property type, with your broker's input
- Requirements are in the vendor agreement, not just requested by email
- Your correct legal entity name is confirmed on each certificate
- You know whether you're additional insured or merely certificate holder — and for high-value work, you've seen the endorsement
- Waiver of subrogation and primary/non-contributory are confirmed where required
- Expiry is tracked per coverage line, not one date per vendor
- Alerts fire 30–60 days before expiry, to a named owner
- Approval is scoped per property or category where sites have different standards
- Assignment is blocked for lapsed or unapproved vendors, in the system where assignment happens
- Historical certificates are retained — you may need to prove coverage as of a past date
That last point gets overlooked. Claims surface long after the work. What matters is whether coverage was in force on the day of the incident, which means keeping the certificate that was current then, not just the newest one.
Certificates of insurance attach to vendors and properties in Bedrok Pro with expiry alerts, so lapses surface before they happen rather than during a claim. Per-property approved-vendor rules mean an uninsured or unapproved vendor can't be assigned to a property that requires approval — enforced at assignment, in the same screen where the work order is created.
Because vendors, work orders, and properties live in one system, the compliance check happens where the decision is made instead of in a separate tracker. See how vendor management works, or book a walkthrough.
A useful exercise if you want to know where you actually stand: pull every work order completed in the last quarter, and check whether the assigned vendor's coverage was in force on the completion date. Not today — then. Most teams doing this for the first time find at least one job performed during a lapse, and it's a far better day to find that out than the day a claim arrives.