Vendor Compliance

Vendor & Contractor COI Requirements: Complete Guide + Free COI Checker

Learn what Certificate of Insurance (COI) requirements vendors and contractors may need, what to check on a COI, common insurance coverage types, and how to use our free Vendor & Contractor COI Requirement Checker.

Vendor & Contractor COI Requirements: Complete Guide + Free COI Checker

Vendor & Contractor COI Requirements: Complete Guide + Free COI Checker

When businesses work with vendors, contractors, suppliers, and service providers, insurance requirements are often an important part of the vendor approval process.

A Certificate of Insurance (COI) provides evidence of insurance coverage maintained by a vendor or contractor. Procurement, risk, compliance, facilities, and operations teams may need to review COIs before allowing a third party to begin work or access a site.

The challenge is that COI requirements are not always the same for every vendor.

A contractor working on a construction site may require different insurance coverage from a software provider, transport company, security agency, or maintenance contractor.

This guide explains vendor and contractor COI requirements, common types of insurance coverage, what organizations should review, and how to identify requirements based on the vendor or contractor’s situation.

You can also use our free Vendor & Contractor COI Requirement Checker to get general guidance on commonly required insurance coverage.


What Is a Certificate of Insurance (COI)?

A Certificate of Insurance (COI) is a document that provides evidence of insurance coverage maintained by an insured party.

A COI may summarize information such as:

  • Name of the insured
  • Insurance company
  • Policy type
  • Policy number
  • Effective date
  • Expiration date
  • Coverage limits
  • Additional information about the policy

A COI is generally used as evidence of insurance rather than as the insurance policy itself.

For vendor management teams, the COI can provide a convenient way to review whether a vendor has provided evidence of the insurance coverage required by the organization.


Why Do Businesses Require COIs From Vendors and Contractors?

Organizations may require insurance documentation to help manage risks associated with third parties.

Depending on the relationship, a vendor or contractor may:

  • Work at company facilities
  • Interact with employees or customers
  • Operate vehicles
  • Perform maintenance
  • Handle equipment
  • Provide security services
  • Perform construction or installation work
  • Provide specialized professional services

Insurance requirements can help organizations establish minimum coverage expectations before a vendor begins work.

A structured COI process can also make vendor onboarding and ongoing compliance reviews easier.


Are COI Requirements the Same for Every Vendor?

No.

COI requirements can vary based on factors such as:

  • Type of vendor or contractor
  • Nature of work
  • Industry
  • Risk level
  • Contract requirements
  • Location or jurisdiction
  • Work performed at the company’s premises
  • Company insurance policy
  • Customer requirements

For example, a contractor performing physical work at a manufacturing facility may have different insurance requirements from a software company providing a cloud-based service.

Therefore, organizations should avoid applying one identical COI checklist to every vendor.


Common Types of Insurance Coverage for Vendors and Contractors

The coverage required depends on the vendor’s activities and the organization’s requirements.

Common types of coverage that organizations may encounter include:

General Liability Insurance

General liability coverage may help address certain third-party claims involving bodily injury or property damage, subject to the policy terms and conditions.

It is commonly considered for vendors and contractors performing work that could create third-party liability exposure.


Workers’ Compensation Insurance

Workers’ compensation coverage may be relevant when a contractor has employees performing work.

Requirements vary by jurisdiction and employment arrangement.

Organizations working with labour-intensive contractors may therefore request evidence of applicable workers’ compensation coverage.


Commercial Auto Insurance

Commercial auto coverage may be relevant when vendors use vehicles as part of their business activities.

Examples include:

  • Transport companies
  • Delivery vendors
  • Logistics providers
  • Field service companies

The required limits and coverage depend on the nature of the work and applicable requirements.


Professional Liability Insurance

Professional liability coverage may be relevant to vendors providing professional or advisory services.

Examples may include:

  • Consultants
  • Engineers
  • Technology professionals
  • Professional service providers

The appropriate requirements depend on the services provided and contractual risk.


Product Liability Insurance

Product liability coverage may be relevant to suppliers or manufacturers whose products could create liability exposure.

This can be particularly important when vendors supply products, components, equipment, or materials used by the organization.


Cyber Liability Insurance

Cyber insurance may be considered when a vendor handles sensitive information, operates technology systems, or has access to company data.

It may be relevant to:

  • Software providers
  • IT service providers
  • SaaS vendors
  • Data-processing vendors

The appropriate requirements depend on the organization’s risk assessment and contractual requirements.


Vendor COI Requirements vs Contractor COI Requirements

Although the terms are sometimes used interchangeably, the risk profile can be different.

Vendor

A vendor may primarily supply:

  • Products
  • Materials
  • Equipment
  • Software
  • Professional services

Contractor

A contractor may perform:

  • Construction work
  • Maintenance
  • Installation
  • Security services
  • Housekeeping
  • Labour-intensive services
  • Work at company facilities

Because the activities and risks differ, insurance requirements should be based on the actual work being performed rather than simply whether an organization labels the third party a “vendor” or “contractor.”


What Should You Check on a Vendor COI?

When reviewing a COI, organizations commonly check whether the submitted evidence appears consistent with their defined requirements.

Important information may include:

1. Insured Name

Check that the named insured corresponds to the vendor or contractor being onboarded.

2. Policy Type

Confirm that the COI identifies the coverage types required by the organization.

3. Policy Dates

Check the effective and expiration dates.

An expired certificate should be escalated for updated documentation.

4. Coverage Limits

Compare the stated limits with the organization’s contractual or internal requirements.

5. Policy Number

Record the policy number where required for internal tracking.

6. Insurance Carrier

Capture the insurer information shown on the certificate.

7. Additional Requirements

Some contracts may require additional insured status, waivers, endorsements, or other specific provisions.

These requirements should be reviewed against the applicable contract and insurance requirements.


COI Compliance Checklist

A practical vendor COI review can include:

  • Vendor or contractor name verified
  • Required insurance types identified
  • Policy number recorded
  • Insurance carrier recorded
  • Effective date checked
  • Expiration date checked
  • Coverage limits reviewed
  • Required endorsements reviewed, where applicable
  • Contract requirements checked
  • Certificate stored in the vendor record
  • Renewal date tracked
  • Exceptions documented

This checklist can be adapted to your organization’s requirements.


Common Vendor COI Problems

Procurement and compliance teams frequently encounter issues such as:

Expired COIs

A certificate may have passed its expiration date.

Missing COIs

A vendor may be approved without providing the required insurance evidence.

Incorrect Vendor Name

The certificate may not correspond to the legal entity being onboarded.

Insufficient Coverage

The stated limits may not meet the organization’s requirements.

Missing Required Coverage

A required policy type may not appear on the certificate.

Scattered Records

COIs may be stored across email inboxes, shared folders, and spreadsheets.

No Renewal Tracking

Teams may have no reliable process for monitoring certificate expiration.


How to Determine COI Requirements for a Vendor

Before requesting a COI, organizations can evaluate:

1. What does the vendor do?

Understand the actual products or services provided.

2. Where will the vendor work?

Working at a company site may create additional risks compared with remote services.

3. Does the vendor interact with people, property, vehicles, or data?

These activities can influence the organization’s risk assessment.

4. What does the contract require?

Contractual insurance requirements should be reviewed carefully.

5. What is the vendor’s risk level?

Higher-risk activities may require stronger insurance requirements.

6. Are there customer or regulatory requirements?

Additional requirements may apply depending on the business relationship and jurisdiction.


Use Our Free Vendor & Contractor COI Requirement Checker

Not sure what insurance requirements may apply to a particular vendor or contractor?

Use our free Vendor & Contractor COI Requirement Checker.

The tool provides general guidance based on information about the vendor or contractor and can help you identify commonly considered COI requirements.

The checker can help you:

  • Identify potentially relevant insurance coverage
  • Understand common COI requirements
  • Create a starting point for vendor insurance discussions
  • Prepare for vendor onboarding
  • Build a preliminary insurance checklist

Check Vendor & Contractor COI Requirements — Free Tool

Important: The checker provides general guidance and is not legal or insurance advice. Actual requirements can vary based on contracts, jurisdiction, vendor activities, company policies, and other circumstances.


Example: Using the COI Requirement Checker

Imagine a manufacturing company is onboarding a contractor that will perform maintenance work at its facility.

The procurement team needs to determine what insurance coverage should be considered before the contractor begins work.

The team can use the checker to:

  1. Identify the contractor type.
  2. Describe the nature of the work.
  3. Consider where the work will take place.
  4. Review the suggested insurance requirements.
  5. Compare those requirements with the company’s contract and internal policies.
  6. Request the appropriate documentation from the contractor.

The tool provides a starting point for the review. The organization’s final requirements should come from its applicable contracts, policies, risk assessment, and professional advice where appropriate.


COI Requirements During Vendor Onboarding

COI collection should ideally be part of the vendor onboarding process rather than an afterthought.

A typical workflow can be:

Vendor Registration

Vendor Risk Assessment

Define Insurance Requirements

Request COI

Vendor Uploads COI

Review Coverage and Dates

Approve or Request Changes

Store COI

Track Expiration

Request Renewal

This approach creates a repeatable process for managing vendor insurance documentation.

For a broader onboarding workflow, see Vendor Onboarding Process.


How to Manage COI Expiration Dates

COIs and underlying insurance policies may have expiration dates that require ongoing monitoring.

Organizations can track:

  • Policy expiration date
  • Renewal status
  • Outstanding requests
  • Updated certificates
  • Approval status
  • Exceptions

Automated reminders can help teams request updated certificates before existing coverage documentation expires.

This is especially useful when managing hundreds of vendors and contractors.

See Vendor Document Expiry Reminder.


Manual COI Tracking vs Automated Tracking

Manual Tracking Automated Tracking
Excel spreadsheets Centralized vendor records
Email reminders Automated notifications
Scattered COIs Central document repository
Manual expiry checks Automated expiry tracking
Difficult reporting Compliance dashboards
Manual follow-ups Workflow-based reminders
Limited history Audit trails

Automation can reduce repetitive administrative work and make it easier to identify certificates that require attention.


Best Practices for Vendor COI Management

Define Requirements Before Onboarding

Determine the insurance requirements appropriate for each vendor category and risk profile.

Standardize Your COI Review

Use a consistent checklist so reviewers do not overlook important information.

Track Expiration Dates

Record certificate and policy dates and establish a renewal process.

Centralize COIs

Keep insurance documentation connected to the appropriate vendor record.

Document Exceptions

Record approved exceptions and outstanding requirements.

Review High-Risk Vendors More Frequently

Risk-based monitoring can help focus attention on vendors with greater potential impact.

Maintain an Audit Trail

Keep appropriate records of submissions, reviews, approvals, and renewals.


How VendorCompliancePro Can Help

VendorCompliancePro helps organizations manage vendor compliance from a centralized platform.

Depending on the workflow, organizations can use the platform to:

  • Collect vendor documents
  • Maintain centralized vendor records
  • Track document expiration
  • Send automated reminders
  • Manage approval workflows
  • Monitor compliance status
  • Maintain audit trails
  • Generate compliance reports
  • Validate documents using AI-assisted workflows

For organizations managing large numbers of vendors and contractors, centralizing insurance and other compliance records can reduce manual follow-up and improve visibility.


Frequently Asked Questions

What is a COI?

A Certificate of Insurance is a document that provides evidence of insurance coverage maintained by an insured party.

What does a vendor COI show?

A COI may show the insured name, insurer, policy types, policy numbers, coverage dates, and coverage limits, depending on the certificate.

What insurance should vendors have?

There is no single insurance requirement that applies to every vendor. Requirements depend on the vendor’s activities, risk, contract, jurisdiction, and company policies.

What insurance should contractors have?

Contractor insurance requirements vary based on the work being performed, location, risk exposure, contract terms, and applicable requirements.

Does every vendor need a COI?

Not necessarily. Organizations should determine whether a COI is appropriate based on the vendor relationship, risk, contract, and internal requirements.

How often should vendor COIs be reviewed?

COIs should be reviewed during onboarding and whenever updated coverage is required. Expiration dates should also be monitored so renewals are requested in time.

Can I use a free COI requirements checker?

Yes. The Vendor & Contractor COI Requirement Checker can provide general guidance on commonly considered insurance requirements.

Does the COI checker validate an uploaded insurance certificate?

No. The checker is designed to provide general requirements guidance. It does not replace professional insurance review or validate the contents of an uploaded COI.


Conclusion

Vendor and contractor insurance requirements are an important part of third-party risk and compliance management.

However, there is no universal COI checklist that applies to every vendor. Requirements can vary based on the vendor’s activities, risk level, contract, jurisdiction, and organizational policies.

A structured process helps organizations define requirements, collect COIs, review key information, track expiration dates, and request renewals before coverage documentation becomes outdated.

If you are unsure where to start, try our free Vendor & Contractor COI Requirement Checker for general guidance.


Related Articles

Chandradev Prasad
About the Author

Chandradev Prasad

Founder of VendorCompliancePro | AI-Powered Vendor Compliance

Chandradev Prasad is the founder of VendorCompliancePro and a software engineer with over 20 years of experience building enterprise applications using Microsoft technologies. He writes about vendor compliance, procurement technology, AI-powered document validation, and supplier risk management to help procurement teams automate compliance processes and stay audit-ready.

Vendor ComplianceProcurementArtificial IntelligenceMicrosoft .NET
Contact VendorCompliancePro on WhatsApp