Vendor Compliance

Certificate of Insurance (COI) Requirements for Vendors and Contractors

Learn what a Certificate of Insurance should show, common COI requirements for vendors and contractors, and how procurement teams can manage insurance documentation.

Certificate of Insurance (COI) Requirements for Vendors and Contractors

Certificate of Insurance (COI) Requirements for Vendors and Contractors

Organizations often require vendors and contractors to provide evidence of insurance before they begin work.

A Certificate of Insurance (COI) is commonly used to summarize insurance coverage and provide evidence that a vendor or contractor has the policies required by a contract or company policy.

For procurement, vendor management, facilities, logistics, manufacturing, and warehouse teams, collecting a COI is only the beginning.

Teams also need to understand which coverage is required, check policy dates, monitor documentation, and follow up when certificates expire or requirements change.

In this guide, we’ll explain common COI requirements, what procurement teams should check, and how organizations can manage insurance documentation as part of their broader vendor compliance process.


What Is a Certificate of Insurance?

A Certificate of Insurance is a document that provides information about an insurance policy or policies held by an insured party.

A COI commonly shows information such as:

  • Insured organization
  • Insurance carrier
  • Policy type
  • Policy number
  • Effective date
  • Expiration date
  • Coverage limits
  • Certificate holder
  • Additional information or remarks where applicable

A COI is generally used as evidence of insurance rather than as a replacement for the underlying insurance policy.

Organizations should review their contracts, insurance requirements, and applicable professional advice when determining whether coverage is adequate.


Why Do Vendors and Contractors Need a COI?

Companies work with vendors and contractors that may create different types of operational and financial risk.

For example:

  • A construction contractor may work on company premises.
  • A logistics provider may operate commercial vehicles.
  • A maintenance contractor may perform higher-risk physical work.
  • An IT provider may provide professional services.
  • A warehouse contractor may operate equipment or work around employees and inventory.

Insurance requirements can help transfer or manage certain risks associated with these activities.

A company may therefore require evidence of insurance before allowing a vendor to begin work.


Common COI Requirements

There is no universal COI requirement that applies to every vendor.

Requirements depend on:

  • Vendor activity
  • Industry
  • Contract scope
  • Location
  • Risk level
  • Company policy
  • Customer requirements
  • Applicable law

Common requirements can include the following.

1. Commercial General Liability

Commercial General Liability coverage may be relevant when a vendor’s activities could create third-party bodily injury or property damage exposure.

For example, contractors working at a manufacturing facility or warehouse may need liability coverage appropriate to their activities.

The required limit should be determined by the applicable contract and risk assessment rather than using a universal amount.


2. Employee Compensation / Workers’ Compensation

Employee-related insurance requirements can apply when vendors have employees performing work.

The exact terminology and legal requirements vary by jurisdiction.

Organizations should determine the appropriate requirement based on applicable law, the vendor’s workforce, and contract terms.


3. Employers’ Liability

Employers’ liability coverage may be relevant to vendors with employees, depending on jurisdiction and applicable insurance arrangements.

Procurement teams should verify the requirement against the contract and applicable local requirements.


4. Commercial Auto Liability

Commercial auto coverage may be relevant when a vendor uses vehicles as part of the contracted service.

Examples include:

  • Logistics providers
  • Transport companies
  • Delivery providers
  • Fleet operators
  • Contractors using commercial vehicles

It should not automatically be required for every vendor.

For example, a typical office-based IT service provider may have no contract-related vehicle exposure.


5. Professional Indemnity / Errors & Omissions

Professional Indemnity or Errors & Omissions coverage may be relevant when a supplier provides professional advice, design, consulting, technology, engineering, or other professional services.

Examples include:

  • IT services
  • Consultants
  • Engineering firms
  • Professional service providers
  • Technology vendors

The appropriate requirement depends on the nature and risk of the services.


6. Umbrella / Excess Liability

Umbrella or excess liability coverage can provide additional limits above underlying liability policies.

It may be appropriate for:

  • High-risk contractors
  • Large contracts
  • High-value projects
  • Activities with significant third-party exposure

However, it should generally be treated as contract-dependent rather than automatically required for every vendor.


Additional COI Requirements and Endorsements

Insurance coverage is only one part of the review.

Contracts may also specify particular endorsements or certificate wording.

Additional Insured

A contract may require the customer or another party to be named as an Additional Insured under applicable policies.

The exact requirement should be verified against the contract and applicable policy documentation.

A certificate alone may not establish the legal status of an Additional Insured.


Waiver of Subrogation

A contract may require a waiver of subrogation where appropriate.

This can affect the insurer’s rights after a covered loss.

The requirement should be reviewed against the actual contract and policy terms.


Primary and Non-Contributory

Some contracts require a vendor’s applicable insurance to respond on a primary and non-contributory basis.

This is a contract-specific requirement and should not be assumed for every vendor.


Certificate Holder

The COI may identify the organization or party designated as the certificate holder.

Procurement teams should verify that the certificate contains the expected certificate holder information.


What Should You Check on a COI?

A practical review can include:

  • Vendor or insured name
  • Insurance carrier
  • Policy type
  • Policy number
  • Effective date
  • Expiration date
  • Coverage limits
  • Certificate holder
  • Required endorsements
  • Relevant remarks
  • Contract-specific requirements

The review should compare the information on the certificate against the organization’s actual requirements.


COI Review Example

Suppose a manufacturing company hires a contractor to perform equipment maintenance at its facility.

The procurement team may need to determine:

  • What liability coverage is required?
  • Is employee-related coverage required?
  • Does the contractor use vehicles?
  • Is additional insured status required?
  • Is waiver of subrogation required?
  • Is umbrella or excess coverage appropriate?
  • When does the policy expire?

The exact requirements should be established before the contractor begins work.

The COI can then be reviewed against those requirements.


COI Requirements by Vendor Type

Different vendors can require very different insurance considerations.

Construction Contractors

Potential areas include:

  • General liability
  • Employee-related coverage
  • Commercial auto where vehicles are used
  • Umbrella / excess for higher-risk work
  • Contract-specific endorsements

Construction work can create significant physical and third-party exposure, so requirements should reflect the project scope.


Logistics and Transportation Providers

Potential areas include:

  • Commercial auto
  • General liability
  • Employee-related coverage
  • Cargo-related requirements where applicable
  • Contract-specific insurance requirements

Requirements should reflect the type of transportation service and the assets or goods involved.


IT and Technology Providers

Potential areas include:

  • General liability
  • Professional indemnity / E&O
  • Cyber-related coverage where contractually required
  • Contract-specific endorsements

Commercial auto generally should not be treated as a default requirement for ordinary IT services unless vehicle-related activities are part of the engagement.


Warehouse Contractors

Warehouse vendors can include:

  • Security providers
  • Housekeeping contractors
  • Maintenance companies
  • Pest control providers
  • Material handling contractors
  • Transport providers

Insurance requirements should reflect the specific work performed and the risks created by that activity.


COI Requirements Should Be Risk-Based

A common mistake is applying exactly the same insurance checklist to every vendor.

A better approach considers:

Vendor Type

What does the vendor actually do?

Industry

What environment will the vendor work in?

Risk Level

What could happen if something goes wrong?

Contract Scope

What activities are included?

Jurisdiction

What requirements apply where the work is performed?

Company Policy

What minimum requirements has the organization established?

This produces more practical requirements than a one-size-fits-all checklist.


Common COI Review Mistakes

Assuming Every Vendor Needs the Same Coverage

An IT consultant and a construction contractor do not have the same risk profile.

Using Generic Insurance Limits

Coverage limits should be based on contract requirements, risk exposure, applicable law, and company policy.

Avoid assuming that a single limit is appropriate for every vendor.

Checking Only the Expiration Date

A current policy can still fail to meet the required coverage or endorsement requirements.

Review the certificate against the actual requirements.

Treating the COI as the Policy

A COI summarizes insurance information. It may not contain all policy terms and conditions.

When important coverage questions arise, the underlying policy and applicable endorsements may need to be reviewed by appropriate professionals.

Forgetting Renewals

Insurance documentation can expire.

A vendor that was compliant at onboarding may become non-compliant later if the required certificate is not renewed.


COI Management Is an Ongoing Process

Collecting a COI during onboarding is only one part of vendor compliance.

A practical lifecycle looks like:

Define Requirements

→ Identify required insurance

Collect COI

→ Review coverage and dates

Approve Vendor

→ Monitor expiration

→ Request renewal

→ Review updated certificate

→ Maintain audit evidence

This is why COI management should be connected to the broader vendor compliance process.


Use Our Free Vendor & Contractor COI Requirement Checker

Determining insurance requirements manually can be difficult when an organization works with many types of vendors.

Our Vendor & Contractor COI Requirement Checker provides a simple starting point.

You can select:

  • Vendor or contractor type
  • Industry
  • Risk level

The tool then generates common COI requirements and explains why each requirement may matter.

It also distinguishes between required and recommended or contract-dependent requirements where appropriate.

The tool is intended for general guidance. Insurance requirements should always be reviewed against the applicable contract, company policy, jurisdiction, and professional advice where appropriate.


From COI Requirements to Vendor Compliance

A COI is one document in a much larger vendor compliance lifecycle.

Depending on the supplier and industry, organizations may also need to manage:

  • GST registration
  • PAN
  • Business registration
  • Licenses
  • Quality certificates
  • Safety documents
  • Labour compliance documents
  • Insurance policies
  • Other regulatory evidence

These documents can have different expiry dates and renewal requirements.

VendorCompliancePro helps organizations centralize vendor documents, approvals, expiry dates, audit evidence, and compliance workflows.

Instead of keeping certificates and renewal dates across spreadsheets and email threads, teams can manage vendor compliance through a centralized workflow.


COI Management in Manufacturing

Manufacturing organizations may work with:

  • Maintenance contractors
  • Equipment suppliers
  • Logistics providers
  • Labour contractors
  • Security vendors
  • Facility management providers

The appropriate insurance requirements depend on the work performed and the risks associated with the facility and contract.

Manufacturing companies can combine COI requirements with broader vendor qualification and compliance processes.


COI Management in Logistics

Logistics organizations often work with:

  • Carriers
  • Transport providers
  • Fleet operators
  • Warehousing partners
  • Maintenance vendors
  • Third-party logistics providers

Insurance requirements can be particularly important where vehicles, cargo, employees, or customer property are involved.

Requirements should reflect the actual transportation and logistics activities.


COI Management in Warehousing

Warehouse operations may use vendors for:

  • Security
  • Housekeeping
  • Pest control
  • Equipment maintenance
  • Material handling
  • Transportation
  • Facility services

Each vendor type can create different risks.

A risk-based COI process helps warehouse teams avoid both under-insurance requirements and unnecessary requirements.


Frequently Asked Questions

What is a COI?

A Certificate of Insurance is a document that summarizes certain insurance information for an insured party, including policy types, dates, limits, and other relevant details.


Is a COI the same as an insurance policy?

No. A COI generally provides a summary of insurance information and does not necessarily contain all the terms and conditions of the underlying policy.


What should a company check on a COI?

Common checks include the insured name, insurer, policy type, policy dates, coverage limits, certificate holder, and contract-specific requirements or endorsements.


Does every contractor need the same insurance?

No. Requirements should depend on the contractor’s activities, risk, contract scope, jurisdiction, and company policy.


Should IT vendors have commercial auto insurance?

Not automatically. Commercial auto may be relevant when the IT vendor performs vehicle-related activities, but it generally should not be a default requirement for ordinary office-based IT services.


How often should COIs be reviewed?

COIs should be reviewed during onboarding and whenever requirements change. Expiration dates should also be monitored so renewed certificates can be collected before existing coverage evidence expires.


Can a COI prove that a vendor is fully compliant?

Not by itself. A COI is one piece of evidence. Organizations should compare it against their actual insurance requirements and consider other vendor compliance requirements as well.


Conclusion

Certificate of Insurance requirements are an important part of vendor and contractor risk management.

The key is not to apply the same insurance requirements to every supplier.

Instead, organizations should consider the vendor’s activities, industry, risk level, contract scope, jurisdiction, and internal requirements.

A good COI process should define requirements, collect evidence, review the information, monitor expiration dates, and maintain an audit trail.

For procurement and vendor management teams, COI management should also be part of the broader supplier compliance lifecycle.

Use our Vendor & Contractor COI Requirement Checker to create a practical starting point for COI requirements, then use VendorCompliancePro to manage vendor documents, approvals, expiry dates, and ongoing compliance.


Related Articles

Vendor Compliance

Vendor Management

Chandradev Prasad
About the Author

Chandradev Prasad

Founder of VendorCompliancePro | AI-Powered Vendor Compliance

Chandradev Prasad is the founder of VendorCompliancePro and a software engineer with over 20 years of experience building enterprise applications using Microsoft technologies. He writes about vendor compliance, procurement technology, AI-powered document validation, and supplier risk management to help procurement teams automate compliance processes and stay audit-ready.

Vendor ComplianceProcurementArtificial IntelligenceMicrosoft .NET
Contact VendorCompliancePro on WhatsApp