Certificate of Insurance Requirements
What to ask for, by vendor type
Most teams collect certificates of insurance and very few read them properly. A certificate on file that does not actually cover the work is worse than no certificate, because it produces confidence rather than a question.
A certificate of insurance evidences that a vendor holds cover. What to require depends on what the vendor does: general liability applies broadly, workers compensation matters wherever people work on your premises, professional liability applies to advisory and design work, and cyber liability applies where a vendor handles your data. The certificate should be checked for named insured, cover limits, policy dates and any additional insured or waiver requirements you rely on.
What usually applies to whom
Requirements should follow what the vendor actually does rather than a single policy applied to everyone.
| Vendor type | Commonly required | Why |
|---|---|---|
| On-site contractors and trades | General liability and workers compensation | People are physically present, so both third party injury and employee injury are live exposures |
| Professional and advisory services | Professional liability, plus general liability | The exposure is advice and work product rather than physical damage |
| IT, software and data processors | Cyber liability, plus general and professional liability | The exposure is data and availability rather than premises |
| Goods suppliers and distributors | General liability, and product liability where relevant | Product defect exposure sits with what is supplied rather than how it is delivered |
| Transport and logistics | Auto liability and cargo cover, plus general liability | Vehicles and goods in transit are the specific exposures |
Five things, in about a minute
The named insured matches your vendor
A certificate in the name of a related company, a parent or a trading name is common and means the cover may not attach to the entity you contracted with.
Policy dates cover the work
A certificate valid today is not the same as cover for the whole engagement. The end date is the part that matters, and it is the part most often not recorded.
Limits meet your requirement
Both per occurrence and aggregate. An aggregate limit already partly consumed by other claims is a common gap.
Additional insured status where required
If your contract requires it, the certificate should evidence it rather than you assuming it follows automatically.
Cover types match the work
A general liability certificate from a professional services vendor evidences the wrong thing, and nobody notices because a certificate arrived.
The certificate is recent
A certificate issued two years ago for a policy that has since been renewed tells you about a policy that no longer exists. Check the issue date as well as the expiry.
It is always the same step
Every certificate tracking system in common use fails at one specific point.
| Step | What happens |
|---|---|
| The certificate arrives | Fine, usually by email or through a portal |
| Somebody opens it | Also fine, though it waits in a queue at volume |
| Somebody types the expiry into a tracker | This is the failure point. It is manual, it is boring, and it is the first thing to slip when the week gets busy |
| Nobody notices it was skipped | Because a missing row in a tracker looks identical to a vendor with no certificate requirement |
| The certificate expires | And is discovered at the moment somebody needs it |
Capture the date where it cannot be skipped
| Practice | Effect |
|---|---|
| Collect certificates inside the onboarding questionnaire | The document arrives with the submission rather than through a separate thread |
| Capture the expiry when the document is read | No manual typing step exists, so there is nothing to skip |
| Track per document rather than per vendor | A vendor with three policies has three dates, not one review date that misses two of them |
| Request only what expired at renewal | Vendors complete a single document request far more often than a full resubmission |
| Retain previous certificates | So you can evidence what cover was in place at any point, not just what is current |



