← All Posts

Guides

Vendor Insurance Compliance: Tracking COIs and Certificate Expirations at Scale

A certificate of insurance is not proof of coverage. It is a producer's description of what coverage looked like the day it was issued, and it confers nothing. Here is what has to be checked instead, and why expiration dates are the easiest part.

By HarperAugust 5, 20266 min read

Vendor Insurance Compliance: Tracking COIs and Certificate Expirations at Scale

Every vendor file has a certificate of insurance in it. Almost none of them prove what the person who filed them thinks they prove.

A certificate is a producer's snapshot of policies as they stood the day it was issued. The current ACORD 25 form states its own limits in the header: issued "AS A MATTER OF INFORMATION ONLY," conferring "NO RIGHTS UPON THE CERTIFICATE HOLDER." Older forms went further and disclaimed any duty to tell you about a cancellation; the 2016 form instead defers to the policy, which means notice reaches you only if the policy was endorsed to send it. A vendor can hand you a clean certificate in January, stop paying premiums in March, and the document in your file will look exactly as reassuring in October.

So "we have a current COI on file" answers a much smaller question than it sounds like.

Expiration dates are the easy failure

They are the only field most tracking systems check, and they are the one thing a vendor tends to fix on their own, because their broker sends the renewal automatically.

The failures that cost money are the ones a date field cannot see.

Limits that do not meet the requirement. The contract says $5 million per occurrence. The certificate shows $2 million primary with no umbrella line, or an umbrella that sits over the auto and employers liability policies but not the one that matters. Or it shows $5 million aggregate against $1 million per occurrence, which is a different promise. Nobody compares the number on the certificate to the number in the clause, because the clause is on page 42 of a document that stays closed.

Additional insured status that does not exist. The checkbox on the certificate confers nothing, and the form says so itself:

"IMPORTANT: If the certificate holder is an ADDITIONAL INSURED, the policy(ies) must have ADDITIONAL INSURED provisions or be endorsed."

You need either an endorsement scheduling your entity, or a blanket endorsement that picks you up because a written contract required it. Blanket forms carry conditions of their own, including, on CG 20 33, that you contracted directly with the named insured rather than through a tier above.

The named insured is a different entity. The contract was signed by a subsidiary and the certificate names the parent. Sometimes the parent's policy schedules that subsidiary and you are fine. The certificate will not tell you, and the default answer under a CGL is that a separate entity is a separate entity.

Missing waiver of subrogation or primary and noncontributory wording. Negotiated hard, then not evidenced. The form is explicit that a certificate cannot carry either one:

"If SUBROGATION IS WAIVED, subject to the terms and conditions of the policy, certain policies may require an endorsement. A statement on this certificate does not confer rights to the certificate holder in lieu of such endorsement(s)."

Coverage types that do not match the risk. General liability where the contract required professional liability or cyber. Common with technology and clinical vendors, where the exposure and the policy have drifted apart.

An aggregate already spent. The form warns about this itself - "LIMITS SHOWN MAY HAVE BEEN REDUCED BY PAID CLAIMS" - so the $5 million aggregate you are relying on may be half consumed by claims you will never see.

And policies that renew mid-relationship at worse terms. The date on file is current, so the tracking system stays satisfied while the limit drops by half.

Each of those is a real gap that a green "current" status in a vendor portal will happily conceal.

Why this scales badly

The requirement is not one requirement. It lives in the insurance clause of each agreement, and that clause was negotiated separately for each vendor - sometimes for each amendment. Different limits, different coverage types, different additional-insured wording, different notice requirements.

So verification is not "check the certificate." It is "check the certificate against this specific vendor's specific clause," several hundred times, on several hundred different renewal schedules.

That is why insurance verification is so often automated in name only. Plenty of systems store certificates and email reminders. Storing and reminding is not verifying. The moment verification requires reading a clause and comparing it to a document, the work goes back to a person, and the person has three hundred of them.

What real verification looks like

Start from the contract, not the certificate. The obligation is defined by the clause: what coverage, what limits, whose name on it, what wording, what notice. Extract that once, per agreement, and you have a specification.

Then every incoming certificate gets checked against its own specification rather than a generic template. Limits compared to the negotiated numbers. Named insured matched against the entity that signed. Additional insured, waiver, and primary and noncontributory confirmed by endorsement when the clause requires them. Dates checked, last, because they are the least interesting field.

Then it runs continuously. Renewals get requested before expiry rather than chased after it. Changes get compared against what was on file, so a limit that drops at renewal surfaces as a change rather than passing as a fresh valid certificate. And when a certificate is ambiguous, the follow-up goes back through the vendor, or to the broker they point you to, and the answer is attached to the record.

Harper does this from the documents the vendor and its broker provide. It reads the insurance clause out of the executed agreement, reads the certificate, compares them field by field, chases what is missing, and flags what does not line up - with the clause and the document shown side by side, so the conclusion is checkable rather than asserted. It does not query insurers or insurance data infrastructure; coverage status comes from what the counterparty makes available.

Two things make that work at scale. Harper integrates directly with your vendors, so the certificate arrives from the party who actually holds it rather than through a chain of forwarded email - evidence collected at the source is evidence you can stand behind. And every check leaves an audit trail: what was requested, when, from whom, what came back, which clause it was tested against, and what Harper concluded. When an auditor or a plaintiff's counsel asks how you knew a vendor was covered in the third quarter of last year, you retrieve the answer instead of reconstructing it.

The same loop runs across every obligation in the agreement, not just insurance. A certificate is one piece of evidence among the exclusion screenings, the signed flow-downs, the attestations and the retention duties that the same contract created - and they are all worth exactly as much as your ability to prove them.

The part nobody budgets for

Insurance obligations do not stop at your direct vendor.

If a contract requires subcontractors to carry equivalent coverage - standard in construction subcontracts, common but negotiated in healthcare vendor agreements - then the obligation propagates, the same way federal requirements flow down to delegated entities. Your vendor has to collect and verify certificates from entities you have no relationship with. And where your own agreement gives you audit rights over that verification, you are the one who has to produce it.

Few can. The usual evidence is an attestation from the vendor saying they handled it. That is worth roughly what any unverified attestation is worth, which is why it holds up until the first claim that reaches past your direct counterparty.

A quick diagnostic

Take ten vendor files at random and answer three questions for each without calling anyone.

Does the certificate on file meet the limits in that vendor's own insurance clause, or in the template you assume applies?

Is your correct legal entity named as additional insured?

If that vendor uses subcontractors, can you produce evidence they carry the coverage the contract requires of them?

In our experience most teams get through question one. Question three is where a program's real coverage shows up, because it is the one nobody has a system for.

Request a Demo

Frequently asked questions

What is COI tracking?
Monitoring the certificates of insurance your vendors provide to confirm each one still satisfies the coverage its contract requires. Real tracking checks more than the expiration date: coverage types, per-occurrence and aggregate limits, additional insured status, waiver of subrogation, primary and noncontributory wording, and whether the named insured matches the entity that signed.
Why is a certificate of insurance not proof of coverage?
A COI is a producer's snapshot of policies as they stood on the issue date. The current ACORD 25 form says it plainly: the certificate "IS ISSUED AS A MATTER OF INFORMATION ONLY AND CONFERS NO RIGHTS UPON THE CERTIFICATE HOLDER." On cancellation it commits to nothing of its own - notice "WILL BE DELIVERED IN ACCORDANCE WITH THE POLICY PROVISIONS," which means whether you hear about a lapse depends on whether the policy carries a notice endorsement naming you, not on the paper in your file. A policy can lapse the week after issuance and the certificate will look unchanged.
What should be checked on a vendor COI?
That the coverage types match what the contract requires, that per-occurrence and aggregate limits meet or exceed the negotiated minimums, that your entity is named as additional insured where required, that waiver of subrogation and primary and noncontributory language appears when the contract calls for it, that the named insured matches the entity that signed the agreement, and that policy dates are current. Each of those is a separate failure mode.
Does Harper contact insurers directly to verify coverage?
No. Harper reads coverage status from the documents, certificates and declarations that the vendor or its broker makes available, and it can follow up with the vendor or producer to confirm what a certificate shows. It does not retrieve data from insurers or insurance data infrastructure.

Sources

  1. ACORD 25 (2016/03) certificate of liability insurance - current form language
  2. IRMI - Additional Insured Status: Automatic or Wet Blanket?
  3. IRMI - Primary and Noncontributory
  4. U.S. HHS - HIPAA for Professionals (business associate requirements)
  5. HHS Office of Inspector General - Exclusions Program (LEIE)

Other Posts

August 10, 2026 · Insights

Inside 540 Obligations Across Real Healthcare Contracts

Health plans and their vendors file real contracts with the SEC - including Omada's agreement with Cigna. We counted every binding clause in seven of them: 540 obligations across 49,892 words, and a CMS contract form that does not match the regulation it cites.

July 21, 2026 · Insights

You Already Have a CLM. Why Do You Need Harper?

A contract lifecycle manager tells you what you agreed to. It cannot tell you whether it is still true. That gap, between the signed contract and the live obligation, is the job Harper does, and the reason the two belong together.

July 14, 2026 · Insights

The Unexplored Frontier of Contract Compliance

The cost of building software has collapsed, and the number of vendors every organization must trust is about to reorder. Compliance is the bottleneck, and continuous contract enforcement is the frontier no one has claimed yet.

June 16, 2026 · Insights

What Vendor Contract Management Looks Like in a World With AI

For decades a contract has been a document you sign and file. With AI, it becomes a live system that knows its own obligations and whether they are being met - and the work inverts from reading everything to reviewing the exceptions.

May 5, 2026 · Product

Meet Harper

Vendor compliance is mostly reading contracts and chasing paper. Harper does both, so the person who owns it can stop keeping plates spinning.

February 4, 2026 · Insights

The Illusion of Certificates

SOC 2, HIPAA, and HITRUST are NOT vendor contract compliance. Many vendors incorrectly believe this, exposing their enterprise customers to massive hidden risk.

February 2, 2026 · Insights

The Problem With Looming Audits

It's not a matter of if you'll get audited, but a matter of when. The problem lies at the very beginning: vendors lack proper tooling to organize compliance efforts.

January 28, 2026 · Company

Announcing Harper

We're excited to publicly announce Harper: a new way for health plans and systems to oversee, analyze, and boost vendor contract compliance.