Most COI reviews stop at three things: is there a certificate, does it say general liability, and has it expired. That catches the obvious failures and misses every expensive one. Here is the full list, in the order it is fastest to work through.
The 12 points
- Insured name matches the entity you contracted with — exactly, including LLC/Inc and any DBA.
- Certificate holder is your exact legal entity, at the right address, spelled correctly.
- Every coverage line your contract requires is present: general liability, auto, workers' compensation, umbrella, and any trade-specific line such as pollution or professional.
- Each limit meets or beats your requirement — each occurrence, general aggregate, products-completed operations aggregate, auto combined single limit, employers liability.
- Policy effective dates start on or before the work starts.
- Policy expiration dates run past the end of the work, or you have a plan to re-verify mid-job.
- Additional insured status for ongoing operations, evidenced by the endorsement, not the checkbox.
- Additional insured status for completed operations, which is a separate endorsement and the one most often missing.
- Primary and non-contributory wording, backed by an endorsement rather than a sentence in the description box.
- Waiver of subrogation on general liability and on workers' compensation.
- Carrier is admitted in the state and financially rated; the NAIC number is present and resolves to a real carrier.
- Endorsement pages are physically attached — a certificate that claims four endorsements and attaches none is one document, not five.
Want the checklist applied to your own certificates instead?
Get a free 3-certificate auditThe four traps that catch experienced reviewers
1. The aggregate is shared
A $2M general aggregate is not $2M for your project. It is $2M across everything that vendor does all policy year, and it can already be half gone. If a vendor works for twenty owners, you are all sharing one limit. For meaningful work, a per-project aggregate endorsement is the fix, and it is a separate thing to require and verify.
2. The certificate is fresh but the policy is not
Certificates get reissued. A document dated last week can describe a policy that expires next week. Always read the policy expiration column rather than the issue date at the top of the form — it is a surprisingly common substitution when people are moving fast.
3. Workers' compensation with an owner exclusion
Small trade businesses often carry a workers' compensation policy that excludes the owner-officers. The certificate looks compliant. If the person who falls off your roof is the owner, there is no comp coverage behind them, and the claim comes to you. The exclusion generally shows in the description box or on the policy, not in the limits grid.
4. The umbrella that does not follow form
An umbrella limit only helps if the umbrella sits above the policies you care about and extends the same additional insured status. A vendor can carry a $5M umbrella that does not follow the additional insured grant of the underlying general liability. If the umbrella is doing real work in your requirement, ask whether it follows form and whether additional insureds are included.
Fraud signals worth a second look
- Producer contact details that go to a free email domain rather than an agency domain.
- A NAIC number that does not match the carrier named beside it.
- Fonts or alignment that change mid-document, or numbers that sit slightly off the field baseline.
- Limits that are unusually round and identical across every line.
- A certificate emailed by the vendor rather than issued by the agency, when everything else about the relationship is high-value.
Doing this at scale
Twelve checks across four coverage lines is roughly forty comparisons per certificate. It is entirely doable for five vendors and completely unrealistic for two hundred — which is how the check quietly degrades into "is there a PDF in the folder". If you are past the point where a careful person can hold the whole list, the answer is either fewer requirements or a system that applies the whole list every time.
CertShield runs every one of these checks on upload, and routes anything unclear to a person before you see a verdict.
See how it works