How to Verify a Certificate of Insurance: The 12-Point Checklist
A COI that looks legitimate can still leave you exposed. Learn a systematic verification process that catches errors, omissions, and fraud, before an uninsured vendor costs you six figures.
Here is an uncomfortable truth: fake certificates of insurance exist, and they are not rare. Anyone with a PDF editor and a basic internet connection can produce a convincing COI in under ten minutes. The ACORD 25 form, the industry standard, is publicly available. Insurance company logos are a quick Google search away. And most organizations receiving certificates never verify them beyond a glance.
According to data from SmartCompliance, common fraud indicators include mismatched fonts, misaligned dates, NAIC numbers that do not match the insurer name, and producer contact information that leads nowhere. These red flags are easy to miss if you are not looking for them systematically, and they are exactly what a motivated vendor exploits.
This guide provides a systematic 12-point verification process that catches errors, omissions, and fraud before an uninsured vendor steps onto your property. Even if you are not dealing with deliberate fraud, honest mistakes, wrong limits, missing endorsements, outdated dates, can leave you equally exposed. Use this checklist on every certificate you receive.
The 12-Point COI Verification Checklist
Work through these twelve checks in order. They progress from the most obvious red flags to the most detailed verification steps. For routine low-risk vendors, the first eight checks may be sufficient. For high-risk trades, high-value contracts, or anything that looks questionable, go through all twelve.
1. Verify the Producer/Agent Information
The producer is the insurance agent or broker who issued the certificate. Look up their agency name online. Call the phone number listed. If the agency does not exist, the number is disconnected, or the agency has never heard of the vendor, the COI is likely fraudulent. A real agent will confirm whether they issued the certificate and whether the policy is active. This single step catches the majority of fake certificates.
2. Match the Insured Name Against the Vendor's Legal Name
The name in the "Insured" box must exactly match the vendor's legal business name. Cross-reference against the vendor's W-9, contract, or state business registration. "ABC Plumbing" is not the same as "ABC Plumbing, LLC" or "ABC Plumbing Services Inc." A mismatch can mean the certificate belongs to a different entity entirely, or that the vendor is using someone else's insurance.
3. Verify the Insurance Company Is Real and Rated
Look up the insurance company name and NAIC number on AMBest.com. The insurer should exist, be rated (ideally A- or better by A.M. Best), and be authorized to do business in your state. If the NAIC number on the COI does not match the insurer name in the AM Best database, the certificate is suspect. You can also check your state's insurance department website for admitted carriers.
4. Check Policy Effective and Expiration Dates
The policy effective date should be on or before the date work begins. The expiration date should be well after the expected completion of work, ideally with at least a 30-day buffer. If the policy expires within 30 days, flag it for renewal tracking. If the effective date is in the future, the coverage is not yet active. If the dates are positioned outside the center of the field or in an inconsistent font, suspect tampering.
5. Verify Coverage Types Match Your Requirements
Check each coverage type row. At minimum, general liability should be marked with "Occurrence" (not "Claims Made"). Workers' compensation should show statutory limits. Verify that auto liability, umbrella, professional liability, or any other required coverage types are listed with the correct policy numbers and dates. A blank row where coverage should exist is a gap that needs addressing.
6. Confirm Coverage Limits Meet Your Minimums
Each coverage type has a limits column. Verify that general liability shows at least $1,000,000 per occurrence and $2,000,000 general aggregate, the industry standard minimum. Higher-risk trades may require $2M/$4M or higher. Check workers' comp, auto, umbrella, and any other required coverage limits. A common fraud technique: showing inflated limits that do not match the actual policy. Cross-reference high limits against the insurer's typical capacity.
7. Verify Your Organization Is Listed as Certificate Holder
Your organization's name and address should appear in the Certificate Holder box (bottom left of the ACORD 25 form). The name must match your legal entity name exactly. While being a certificate holder alone does not grant you coverage rights (see our additional insured guide), it is a baseline requirement, and if it is missing, the certificate was not even intended for you.
8. Check the Additional Insured Endorsement
Look at the "Description of Operations" box. It should explicitly state that your organization is named as additional insured, typically with language like "Certificate Holder is named as Additional Insured per written contract" and a reference to the endorsement form number (CG 20 10, CG 20 37, or equivalent). Request a copy of the endorsement itself, the COI notation is not legally sufficient. Verify the endorsement form provides the scope of coverage you require (ongoing operations at minimum; completed operations for construction).
9. Inspect the Cancellation Clause
The standard ACORD 25 cancellation clause reads: "Should any of the above described policies be cancelled before the expiration date thereof, notice will be delivered in accordance with the policy provisions." The word "should" is critical, it is not "shall" or "will." This means the insurer may or may not notify you of cancellation, and many policies do not require notice to certificate holders or additional insureds. Do not rely on cancellation notices. Monitor expiration dates proactively through your own tracking system.
10. Check for Waiver of Subrogation
If your contract requires a waiver of subrogation, verify it is noted on the COI, typically in the Description of Operations box. Without this endorsement, the vendor's insurer can pay a claim and then sue you to recover their costs. Request a copy of the waiver of subrogation endorsement to confirm it exists and applies to your organization.
11. Inspect the Form for Editing Artifacts
Open the PDF at high zoom (300-400%) and look for: inconsistent fonts within the same field, text that appears sharper or blurrier than surrounding text, misaligned text that does not sit on the form's grid lines, visible edit boxes or selection handles, different text colors (some entries darker or lighter than others), and checkboxes that appear hand-drawn rather than digitally marked. These artifacts indicate post-issuance editing. A professionally issued COI should have uniform font rendering and no visible editing marks.
12. Verbally Confirm with the Agent (for High-Risk or High-Value Vendors)
For any vendor performing high-risk work (roofing, demolition, electrical on occupied buildings) or any contract over $50,000 in value, call the agent listed in the Producer section. Do not use the phone number on the COI, look up the agency independently online and call their published number. Ask the agent to confirm: that the policy is active, that the coverage limits match what is shown on the COI, that your organization is listed as additional insured, and that the policy has not been cancelled or modified since issuance. Document the call: date, time, agent name, and a summary of what was confirmed. This step takes five minutes and can prevent six-figure losses.
Common COI Errors That Are Not Fraud, But Still Dangerous
Not every problem on a COI is deliberate fraud. Honest mistakes from agents and brokers are common, and they create the same liability gaps as intentional deception. Here are the most frequent errors to watch for:
- Wrong additional insured name. The agent uses a shorthand version of your organization's name ("ABC Properties" instead of "ABC Properties Management, LLC"), creating ambiguity about whether coverage applies to you.
- Outdated endorsement form. The agent uses an older version of the additional insured endorsement that provides narrower coverage than what your contract requires.
- Incorrect coverage limits. The agent enters the wrong aggregate limit or omits a coverage type that the policy actually includes, both can trigger unnecessary compliance flags or, worse, give you a false sense of security.
- Missing umbrella or excess coverage. The underlying general liability policy meets your limits, but the umbrella policy that stacks on top is not listed, leaving you unaware of the total coverage available.
- Cancellation notice not guaranteed. The agent checks the cancellation notice box but the actual policy does not require notice to certificate holders, a common disconnect that creates false confidence.
These errors are why systematic verification matters. You are not just looking for fraud, you are validating that the COI accurately reflects the coverage your vendor is supposed to carry.
Why Manual COI Verification Does Not Scale
This 12-point checklist is thorough, and time-consuming. At 10-15 minutes per certificate, verifying 50 vendor COIs takes 8-12 hours. At 200 vendors, you need a dedicated person whose entire job is certificate verification. At 500, even a dedicated person cannot keep up without automation.
The bottleneck is not the checklist, it is the manual data extraction. Every certificate arrives as a PDF. Someone has to open each one, find the producer name, the insured name, the policy numbers, the limits, the dates, the additional insured notation, and type or mentally compare each field against the requirements. This is repetitive, error-prone work. After verifying ten certificates in a row, the human brain stops noticing subtle inconsistencies.
COI tracking software with AI extraction eliminates this bottleneck. The AI reads every field in under 30 seconds, compares it against your defined requirements, and flags discrepancies automatically. Your team reviews the exceptions, not every certificate. This reduces verification time per COI from 10-15 minutes to under one minute for routine certificates, freeing your team for the complex cases that genuinely need human judgment.
COI File automates the full verification workflow, from AI extraction through requirement matching to expiration monitoring. Start free today with up to 5 vendors.
Frequently Asked Questions
Sources & References
- SmartCompliance, How to Spot Fake Certificates of Insurance, Industry guide to COI fraud detection with 8-point checklist for spotting fraudulent certificates. smartcompliance.co
- A.M. Best, Independent insurance company rating agency. Verify insurer financial strength and NAIC number matching. ambest.com
- ACORD, Official standards organization for insurance forms, including the ACORD 25 certificate of liability insurance. acord.org
- NAIC, State Insurance Departments, Directory of state insurance regulators where you can verify insurer licensing and authorization. naic.org
- IRMI, Certificates of Insurance: Issues and Answers, Authoritative analysis of COI legal limitations and verification best practices. irmi.com
Related Resources
- Certificate of Insurance, Complete Guide, what a COI is, how to read an ACORD 25 form, and who needs one
- Additional Insured, Complete Guide, the difference between certificate holder and additional insured, and why it matters
- ACORD 25 Form Guide, line-by-line breakdown of every field on the standard COI form
- COI Requirements by Industry, minimum insurance requirements for every vendor type and trade
- COI Tracking, Complete Guide, automate vendor compliance tracking with software
- COI File Features, see how AI-powered verification works in practice
Firdaosh Bano
COI Compliance Specialist
Firdaosh Bano is a COI compliance specialist and the founder of COI File. She spent 6 years managing vendor compliance for commercial properties - tracking 2,000+ COIs across 150+ properties in spreadsheets before building the tool she wished she'd had. She writes about certificate of insurance compliance, vendor risk management, and making insurance tracking less painful for small teams.