Guide

Vendor insurance compliance: the complete guide

By Daniel Siryakov, Founder · Updated July 8, 2026

Vendor insurance compliance is the ongoing discipline of requiring, collecting, verifying, and monitoring proof of insurance from the third parties you hire—so that when one of them causes a loss, their coverage responds instead of yours. A working program sets requirements by risk, gates work on a valid certificate of insurance, checks limits and endorsements, and watches every policy until the engagement ends—which is why most teams run it on insurance compliance software rather than a spreadsheet.

What vendor insurance compliance means

Every time you hire an outside business—a subcontractor, a maintenance crew, an IT firm, a landscaper, a franchisee—you inherit some of their risk. If they injure someone or damage property while working for you, you can be pulled into the claim. Vendor insurance compliance is the system you use to make sure that risk lands on the vendor’s insurer, not on your balance sheet.

The mechanics come down to four repeating jobs: define what coverage each vendor must carry, collect a certificate of insurance proving they carry it, verify that the certificate actually meets your requirements, and monitor every policy so it never lapses while the vendor is still working for you. A certificate is only accurate the day it’s issued—so compliance is a continuous program, not a one-time file.

This applies well beyond construction. Property managers track vendors at every building, facility managers track service providers, procurement teams track suppliers, and franchisors track franchisees. The coverage lines differ, but the discipline is identical.

Why it matters: risk transfer, indemnification, and audits

Your contract can say a vendor is responsible for their own negligence, but words alone don’t pay claims—an active insurance policy does. Compliance is how you confirm that the risk-transfer language in your agreement is actually backed by coverage before a loss occurs, not discovered to be worthless afterward.

  • Risk transfer: a compliant vendor’s policy responds to a claim arising from their work, keeping the loss off your own coverage.
  • Indemnification support: indemnity clauses are only as good as the insurance standing behind them—additional insured status gives you direct rights under the vendor’s policy.
  • Claim protection: if a vendor’s policy lapsed mid-engagement, their carrier can deny the tender—leaving your insurer, or you, to absorb it.
  • Contract & audit compliance: owners, lenders, insurers, and franchise agreements routinely require documented proof that you verify downstream coverage.
  • Premium impact: uninsured vendor losses can flow onto your loss runs and raise your future premiums.

The failure is usually silent. A missing endorsement or an expired policy causes no problem at all—until an incident triggers a claim, and by then it’s too late to fix.

Step 1 — Set requirements and contract language

A good program starts before any certificate arrives, by deciding what each vendor must carry. Requirements should scale with risk rather than applying one blanket rule to everyone.

  • High-risk vendors (contractors, maintenance crews, anyone doing physical on-site work): general liability, workers’ compensation, commercial auto, and often umbrella/excess limits.
  • Medium-risk vendors (IT, security, staffing, consultants with facility or data access): general liability plus professional liability / errors & omissions.
  • Low-risk vendors (remote software providers with no site or data access): minimal requirements, sometimes none.

Set specific minimum limits per line of coverage, and specify the endorsements you need: additional insured, waiver of subrogation, and primary and non-contributory. Then write it all into the contract—including the right to request updated certificates during the term, and the right to suspend or terminate for non-compliance. Requirements you don’t put in the contract are requirements you can’t enforce.

Step 2 — Collect COIs at onboarding

The single most effective control in the whole program is a hard gate: no work begins until a valid certificate is on file. Once a vendor is already on site, leverage to obtain paperwork evaporates.

Vendors provide proof on an ACORD 25—the standardized certificate of liability insurance—typically requested from their agent or broker. Make sure your company is named correctly as the certificate holder, and confirm the required endorsements are actually attached rather than merely promised. Collection also has to repeat: request a fresh certificate at every policy renewal and whenever the scope of work changes.

The number-one friction point

Most programs stall at collection. Chasing certificates over email, or forcing vendors through a clunky login portal, produces slow responses and stale files. The fix is to make submission effortless—ideally a link a vendor (or their broker) can use without creating an account.

Step 3 — Verify coverage, limits, and endorsements

Filing a certificate is not verifying it. Verification means reading each field on the ACORD 25 and checking it against the requirements in your contract—the step where “false compliance” hides. A certificate can sit on file looking complete while missing the exact things that make it worthless in a claim.

  • Coverage types present—general liability, auto, workers’ compensation, umbrella/excess where required.
  • Limits that meet or exceed your minimums on every line.
  • Endorsementsadditional insured, waiver of subrogation, and primary and non-contributory status, confirmed on the actual policy, not just implied on the certificate.
  • Effective and expiration dates covering the vendor’s full scope of work.
  • Named insured matching the legal entity you contracted with—entity-name variations are a classic gap.

Watching for these details by eye is slow and error-prone, which is why COI grading that scores each certificate against your rules is the highest-leverage part of any software-driven program.

Step 4 — Monitor renewals and stay audit-ready

Monitoring is where most programs quietly break down. A vendor compliant at onboarding becomes non-compliant later when a policy lapses, limits drop, an endorsement is removed, or a renewal certificate is simply never submitted. Because nothing visibly changes, the gap goes unnoticed—until a claim exposes it.

A durable program builds in advance-notice reminders (commonly at 60, 30, 15, and 7 days before expiration), a defined escalation path for non-responsive vendors, and a cure period after which work is suspended. See expiration tracking for how automated monitoring closes this gap.

Audit readiness is the payoff. When an owner, lender, insurer, or internal auditor asks who is compliant, a mature program answers in real time from a single source of truth—not by digging through a folder of emails and PDFs the week before the audit.

Manual program vs. software-driven program

A spreadsheet works for a handful of vendors. It cannot read a certificate, flag a missing endorsement, or warn you before a policy expires—so it fails exactly when the program matters most. Most organizations hit the limits of manual tracking somewhere between 25 and 50 active vendors.

Program capabilityManual / spreadsheet Software-driven
Collect certificatesChase over emailNo-login upload link
Read the ACORD 25Manual data entryRead automatically
Verify against your rulesEyeball each formAutomatic A–F grading
Track endorsements
Expiration reminders
Audit-ready reportingCompile by handReal-time dashboard
Scales past ~30 vendors

For a fuller breakdown of tools, see the best COI tracking software comparison, or compare approaches side by side.

Common failure modes to design around

  • Portal friction: login-gated submission slows vendors down and leaves files stale. Frictionless upload beats a fancy portal every time.
  • Silent expirations: without reminders, policies lapse mid-engagement and nobody notices until a claim.
  • Missing endorsements: a certificate with the right limits but no additional insured or waiver still leaves you exposed.
  • Certificate vs. policy confusion: a COI proves coverage existed at issuance—it doesn’t guarantee the policy is still active today.
  • No clear owner: when risk, procurement, legal, and operations all “sort of” own compliance, gaps open between departments.

The bottom line

Vendor insurance compliance is proof-of-insurance kept current. Set requirements by risk, gate work on a verified certificate, confirm limits and endorsements, and monitor every policy until the engagement ends. Do that consistently and an uninsured vendor never becomes your loss.

Wardly is free COI tracking software for general contractors: send subcontractors a no-login upload link, get an automatic A–F grade on every certificate, and let Wardly watch every expiration date. See the best COI tracking software comparison or explore the features.

General information, not legal or insurance advice.

Frequently asked questions

What is a vendor insurance compliance program?

It is the documented system an organization uses to define insurance requirements by vendor type, collect certificates of insurance before work begins, verify that each certificate meets contract-specific standards, and monitor expirations with renewal workflows so coverage never lapses. The goal is to make sure a vendor’s insurance responds to a loss instead of yours.

What insurance should you require from vendors?

It depends on the vendor’s risk. On-site and physical-work vendors typically need general liability, workers’ compensation, commercial auto, and sometimes umbrella limits. Professional-service vendors usually need general liability plus professional liability / errors & omissions. Set specific minimum limits and require additional insured, waiver of subrogation, and primary and non-contributory endorsements where appropriate.

How often should you verify vendor COIs?

At minimum, at onboarding and at each annual policy renewal, plus whenever the scope of work changes. For high-risk vendors on long-running engagements, a mid-term review every six months catches coverage changes that would otherwise go undetected between renewals.

Who is responsible for vendor insurance compliance?

The vendor’s insured business requests the certificate and their agent issues it, but responsibility for running the program sits with you—the hiring party. Define ownership before launch, since risk, procurement, legal, operations, and project teams may all touch vendor compliance and gaps appear at the handoffs between them.

Is a certificate of insurance enough to prove compliance?

Not on its own. A certificate proves coverage existed on the day it was issued; it doesn’t confirm the policy is still active, that limits are adequate, or that required endorsements are actually attached to the underlying policy. Verifying those details—and monitoring them over time—is what turns a filed certificate into real compliance.

What happens if a vendor’s COI expires mid-engagement?

An expired certificate means you no longer have documented proof of current coverage. A well-structured program sends advance-expiration reminders, escalates to non-responsive vendors, and suspends work authorization after a defined cure period if an updated certificate isn’t provided.

What is insurance compliance software?

Insurance compliance software (also called vendor compliance software or certificate of insurance tracking software) automates the four jobs of a program: collecting certificates from vendors, reading each ACORD 25, verifying coverage, limits, and endorsements against your rules, and monitoring expirations with renewal reminders. It replaces the spreadsheet and email chase that manual vendor insurance compliance relies on, and keeps a real-time, audit-ready record of who is compliant.

Run your vendor insurance compliance program for free.

Wardly collects vendor certificates from a no-login link, grades each one A–F against your requirements, tracks additional insured and waiver of subrogation, and watches every expiration date. Free forever, unlimited vendors.

Get started free