Insurance operations
Certificate of insurance tracking, explained
What a certificate actually attests, why the spreadsheet always misses a lapse, what tracking software really does, and what to check before you buy or build any of it.
Every vendor relationship starts with the same one-page promise. The work is remembering when it expires.
If you run a commercial account, manage property, or hire subcontractors, you have a stack of certificates of insurance somewhere. The stack grows every month. And the question that decides whether the stack is protection or theater is simple: when a certificate expires, who notices, and how fast
This guide covers what a certificate of insurance is, what tracking actually involves, why the usual spreadsheet fails, what COI tracking tools do, and what to verify before paying for one. It is written from the operations side, for people who answer the phone when something lapses.
What a certificate of insurance actually is
A certificate of insurance, almost always the ACORD 25 form, is a one-page summary of someone else's policy. It lists the carrier, the policy numbers, the coverage lines, the limits, and the effective dates. General contractors collect them from subcontractors. Property managers collect them from tenants. Agencies issue them for clients, daily.
The part most people get wrong: a certificate attests coverage, it does not create or change it. It is a snapshot taken on the day it was issued. If the underlying policy cancels next week, the certificate in your drawer still says everything was fine. That is why tracking exists at all. The paper is not the protection. Knowing the paper is still current is the protection.
Two endorsements get checked more than anything else, because they are the ones contracts actually fight over:
- Additional insured: the other party's policy extends to cover your interest in their work. A certificate without the endorsement is a certificate that misses the point.
- Waiver of subrogation: their carrier agrees not to come after you after paying a claim that was arguably your fault.
Both live on the policy as endorsements, not on the certificate. A serious tracking process checks for them specifically. A filename that says "COI" does not.
What COI tracking actually involves
Tracking is four jobs wearing one name:
- Collecting: getting the certificate from every vendor, tenant, or counterparty before work starts, in the right form, with the right endorsements.
- Verifying: reading the limits and endorsements against what the contract requires, and flagging the gaps.
- Renewing: knowing every expiration date and requesting the renewal before it passes, not after. Most policies renew annually, which means every vendor in the book needs a touch every year, forever.
- Archiving: keeping the historical certificates so that when a claim or dispute surfaces three years later, the proof of coverage on that date exists.
None of these jobs is hard. The failure mode is that they are all invisible until they matter. A tracked book is quiet. An untracked book is also quiet, right up until an uninsured subcontractor has an incident on your site and the certificate on file expired fourteen months ago.
The exposure is not theoretical. Certificates are the first document requested after an incident, and the first one examined in an errors and omissions claim against the account manager who let one lapse.
Why the spreadsheet always misses one
Most tracking starts as a spreadsheet, and for a book of twenty certificates run by one careful person, a spreadsheet is genuinely fine. It fails on schedule, not on day one:
- Contact data decays by roughly a third each year. The vendor's office manager who answered renewal emails moves on. The request lands in a dead inbox, and the row quietly goes stale.
- Renewals cluster. When forty certificates expire in the same quarter, the chase competes with the actual job, and the chase loses.
- A spreadsheet records what someone typed into it. If the renewal certificate arrives with the additional insured endorsement missing, the spreadsheet does not know. It shows green because someone marked it green.
- Nothing escalates. A dead row in a spreadsheet is indistinguishable from a current one until someone audits the whole file.
The consistent pattern we see in agency and operations books: the spreadsheet is accurate for the accounts the owner personally touches, and fiction for the rest.
What COI tracking software actually does
The category is mature. Dedicated tools include myCOI, Jones, TrustLayer, and bcs, and most agency management systems now carry a certificate module of some kind. Under the branding, a real COI tracking system does five things:
- Stores each certificate against the account, contract, and requirement set.
- Reads the coverage and expiration data off the document, so nobody retypes it.
- Compares what arrived against what the contract requires, and flags the gap rather than trusting the filer.
- Requests renewals automatically on a schedule, escalates the non-responders, and keeps the full send-and-receive trail.
- Archives every version, so the proof for any past date is one query instead of an email archaeology project.
That list is also the buying checklist. A tool that stores PDFs but does not escalate non-responses is a shared drive with a subscription. A tool that reads dates but does not check endorsements is half the job. Ask the vendor for a live run with one of your messiest accounts, not a demo account.
What to check before you buy, or build
Whether you are evaluating a vendor or building the pipeline internally, the same questions decide it:
- Who receives the renewal request, and what happens when they ignore the first two?
- Are requirements stored per account and per contract, or one global rule that fits nobody?
- Does the system verify endorsements, or only limits and dates?
- Where does the audit trail live, and can you export it when a carrier or attorney asks?
- How does it connect to what you already run? For agencies, that means the AMS: Applied Epic, AMS360, HawkSoft, EZLynx. For everyone else, it means email, your document store, and whatever dashboard your team actually opens.
- What does it cost per tracked certificate, and what happens to price at double the volume?
The agency side: producing certificates fast
Everything above is the consuming side of certificates. If you are a broker, you live on the producing side, and your tracking problem is speed. The most common certificate-related call an agency gets is some version of "can I get a certificate of insurance today": a contractor who won a job yesterday and cannot mobilize until the COI is in the general contractor's inbox.
That call is not hard. It is just interrupt-driven, arrives in bursts, and burns the same capable people every time. The agencies that handle it well treat certificate issuance as a pipeline, not a favor: the request comes in through a channel that captures job details, the issuance happens against current policy data, and the confirmation goes out without a human shepherding each step. The ones that handle it badly lose the account the next time a faster shop answers first, because the contractor with a mobilization date does not wait.
Both sides of the certificate problem, producing and tracking, are the same shape: recurring, interrupt-heavy work that a system does better than a busy person with a good memory. We build those pipelines for agencies, and we start by measuring what the current process costs. See what that looks like.
Frequently asked questions
What is a certificate of insurance? +
A one-page summary of a policyholder's coverage, almost always on the ACORD 25 form. It lists the carrier, policy numbers, limits, and effective dates. It is informational: it proves coverage existed on the day it was issued and does not change the policy itself.
Who is responsible for tracking certificates of insurance? +
Whoever bears the risk if coverage lapses. For a general contractor or property manager, that means tracking every vendor and tenant COI against contract requirements. For an agency, it means producing certificates quickly and, on commercial accounts, often tracking vendor COIs on the client's behalf. In practice the job lands on whoever answers when a certificate expires, usually an account manager or CSR.
How long should you keep certificates of insurance on file? +
At minimum, as long as the contract that required the certificate. Most shops archive for the same period as the underlying records, commonly three to seven years, because the certificate is the proof of coverage if a claim or dispute surfaces later. The system should archive automatically rather than depend on someone saving the PDF.
What does COI tracking software do? +
It stores each certificate, reads the coverage and expiration dates off it, flags gaps against the requirements you set, sends renewal requests automatically before expiration, escalates the ones that go unanswered, and keeps an audit trail of who sent what and when. The point is that no lapse depends on a human remembering to check a spreadsheet.
Can you track certificates of insurance in a spreadsheet? +
You can start one, and most shops do. It fails as the count grows: contact data decays by roughly a third each year, renewals land in one busy season, and a missed row is a silently uninsured vendor. If the spreadsheet is current and someone owns it, it works. That combination rarely survives two renewal cycles.