What Is COI Compliance? A Plain Definition for Businesses

Jul 19, 2026 Last updated July 2026

Read any certificate of insurance free. Upload an ACORD 25 and let AI pull the data in seconds.

PDF, JPG, PNG, BMP, HEIC, TIFF

Upload your certificates of insurance

Last updated July 2026.

COI compliance means that every vendor, subcontractor or tenant you work with carries the insurance your contract requires, that the coverage has been verified against your specific limits and endorsements, and that it is current rather than expired. A vendor is COI compliant when its certificate of insurance is on file, meets your requirements, and has not lapsed. It is non-compliant the moment any one of those three things fails.

The phrase gets used loosely, so it helps to be precise. Collecting a certificate is not compliance. Filing it is not compliance. Compliance is the ongoing state where the coverage you required is actually in force for every party who could create a liability for you, and where you can prove it on the day someone asks.

What does COI compliance mean?

COI stands for certificate of insurance, the one-page ACORD form a vendor's insurance agent issues to summarize their coverage. COI compliance is the discipline of making sure those certificates exist, meet your standards, and stay valid across your whole vendor base. It has three parts, and all three have to be true at once: the certificate is collected, the coverage meets your requirements, and the policy has not expired.

Miss any one and the vendor is out of compliance even if the other two look fine. A certificate on file with limits below your contract is non-compliant. A perfect certificate that expired last month is non-compliant. Compliance is the intersection, not any single box ticked.

What makes a vendor COI compliant or non-compliant?

A vendor is compliant when its certificate clears every requirement you set. In practice that means a short checklist per certificate:

Compliance checkCompliantNon-compliant
Certificate on fileCurrent COI collectedMissing or never requested
Coverage typesAll required lines presentA required line, such as auto or umbrella, is absent
LimitsMeet or exceed your minimumsGeneral liability under your required amount
EndorsementsAdditional insured, waiver of subrogation as requiredNamed as certificate holder only, no endorsement
Policy datesActive todayExpired or not yet effective

The endorsement row is where most quiet failures live. Being listed as the certificate holder does not make you an additional insured. The document that grants that protection is the endorsement, not the certificate face, a distinction covered in additional insured vs certificate holder. A certificate can look complete and still leave you unprotected.

Why does COI compliance matter?

Because an uninsured third party's loss looks for the nearest solvent party, and that is usually you. If a vendor without adequate coverage causes injury or damage while working for you, the claim can land on your own policy, which never priced for that risk. In a workers compensation audit, an uninsured subcontractor's payroll can be reclassified as yours, producing a premium bill months after the job is done. COI compliance is the control that keeps other people's risk off your balance sheet.

There is a contractual side too. Leases, master service agreements and client contracts often require you to enforce insurance on the parties below you. When a client or insurer asks you to demonstrate that enforcement, compliance is the difference between pulling one clean report and spending a week reconstructing it from email.

Who is responsible for COI compliance?

Whoever required the insurance owns the compliance. That sounds obvious and is constantly ignored. The requirement comes from a contract, so the accountable party is the business that signed it, not the vendor and not the vendor's agent. Inside a company the work usually lands on risk management, but in smaller organizations it falls to whoever owns the vendor relationship: a property manager, a project manager, or the accounts payable team that already holds the vendor file. The full breakdown by organization type is in who is responsible for tracking certificates of insurance.

The failure mode is diffusion. When compliance is nobody's named job, certificates get collected at onboarding and never checked again, and the program silently decays as policies renew and lapse without anyone watching.

What is a COI compliance rate?

A COI compliance rate is the share of your active vendors whose certificates are on file, meet your requirements, and are currently valid. If 180 of your 200 vendors clear every check, your compliance rate is 90 percent. It is the single number that tells you how exposed you are, and it moves every day as policies expire, so a rate measured once a quarter is close to meaningless. The point of tracking it continuously is that the 10 percent gap is exactly where an uncovered claim will come from.

How do you achieve and maintain COI compliance?

Compliance is not a project you finish. It is a state you hold against constant decay, because every certificate you collect starts expiring the day it arrives. Four things keep it current:

First, write requirements by vendor type and put them in the contract, so a landscaper and a roofing contractor are held to the right standard rather than the same one. Second, collect a certificate before any work begins, never after. Third, verify each certificate against the requirement for that vendor, checking limits and endorsements rather than just filing the PDF. Fourth, track expiration dates and chase renewals before they lapse, because the vendor has no incentive to tell you their policy ended.

That last step is why spreadsheets fail. A spreadsheet stores what you type and emails no one. It cannot read a certificate, cannot check a limit, and cannot notice an expiration. Past a couple dozen vendors the manual version breaks, which is where COI compliance software takes over: it reads each certificate, checks it against your rules, flags anything short, and chases renewals automatically so your compliance rate stays high without anyone babysitting a calendar.

What is the difference between COI compliance and COI tracking?

COI tracking is the activity of monitoring certificates and their expiration dates. COI compliance is the outcome tracking is meant to produce: a verified, current state where every required party carries the coverage your contract demands. You track in order to be compliant. A team can track diligently and still be non-compliant if it never checks the coverage against requirements, which is why verification, not just collection, is the part that matters.

Is COI compliance a legal requirement?

It depends on the source of the requirement. There is rarely a general law forcing you to track vendor COIs, but the obligation is usually contractual and just as binding. Your lease, your client agreement, or your own insurance policy conditions can all require you to collect and enforce coverage from third parties, and failing to do so can breach a contract or void part of your own coverage. In regulated industries, insurance verification also feeds into broader regulatory compliance obligations that carry their own audit and reporting duties. Treat COI compliance as mandatory whenever a contract you signed says it is, which is most of the time.

The short version

COI compliance is proof, held continuously, that the people you work with are insured the way your contracts require. It has three moving parts, collected, verified and current, and it fails the moment any one slips. The organization that required the coverage owns the outcome, the work is enforcement rather than filing, and the whole thing decays on its own unless a system holds it in place. Start by writing your requirements down, then decide who owns the number, then automate the reading and chasing before the vendor count outruns the spreadsheet.