July 2, 2026

Understanding Vendor Credentialing: Why It Matters for Contractors and Property Managers

Share this post
A person sitting at a desk writing something on a piece of paper

Every time a vendor steps onto your property, whether it's an HVAC technician repairing a chiller or a landscaper trimming trees, they bring risk with them. If a contractor punctures a water line or a cleaning vendor causes a slip-and-fall in your lobby, who pays for the damage?

Without a verified Certificate of Insurance (COI) on file, that financial liability lands squarely on your property’s master policy, driving up premiums and threatening your bottom line. As a property manager, requiring and verifying COIs isn't just paperwork, it’s a critical fiduciary duty to protect owners, residents, and asset value.

The Critical Checklist: What to Look for on an ACORD 25

A COI is a one-page snapshot of a vendor’s active insurance policy issued by their broker. It does not amend coverage, but it acts as vital proof of protection. When reviewing a standard ACORD 25 form, you must verify five critical elements:

  • Legal Entity Name: Ensure the "Insured" name matches the vendor's legal business name exactly as stated on your contract.
  • Carrier Rating: Confirm the insurance companies listed are admitted in your state and hold strong financial ratings, such as an A.M. Best rating of A- or better.
  • Policy Effective Dates: Verify the policy is active and covers the entire duration of the project.
  • Policy Limits: Ensure coverage meets your contract minimums, which typically require $1 million per occurrence and $2 million aggregate for general liability.
  • Core Coverage Lines: Look for General Liability, Commercial Auto, Workers' Compensation (which is mandatory if they have employees), and Umbrella or Excess Liability for high-risk jobs.

The "Additional Insured" Trap: Mistaking Status for Coverage

One of the most common—and expensive—mistakes property managers make is confusing a Certificate Holder with an Additional Insured. Simply being listed as a "Certificate Holder" at the bottom of the page only guarantees you will receive a notice if the policy is canceled. It offers zero liability protection.

To actually shield your asset, your contract must require the vendor to name your property management company and the ownership entity as Additional Insureds. This must be backed up by a specific endorsement (like ISO form CG 2010) noted in the Description of Operations. This extension forces the vendor's insurance to defend you in court if their work triggers a lawsuit.

A person working with power tools and wood

Red Flags: Spotting Fraud and Lapsed Coverage

As insurance premiums rise, so does COI fraud. Accepting an edited or fraudulent document leaves your portfolio completely exposed. Watch out for these immediate red flags:

  • Inconsistent Formatting: Look for different fonts, misaligned text, or white-out marks indicating altered policy numbers or dates.
  • Suspiciously Identical Dates: Be wary of multiple policy lines showing the exact same renewal dates across entirely different coverage types.
  • The "Silent Lapse": Keep in mind that up to 31% of COI gaps occur because a vendor simply fails to submit a renewal certificate after their policy expires mid-project.

Our pragmatic advice is to never accept a COI edited or generated by the vendor themselves. It must come directly from their licensed insurance broker. If something feels off, call the issuing agent listed on the top of the form to verify coverage.

Stop Tracking Insurance on Spreadsheets

Manual COI tracking consumes an average of 8 to 10 hours per week per portfolio. It’s an administrative bottleneck prone to human error, missed expirations, and unverified endorsements.

VendorAccess turns manual risk management into a seamless, automated workflow. First, you can set different insurance thresholds automatically based on vendor type, ensuring higher limits for roofers and standard limits for painters. Second, the platform proactively prompts vendors to upload renewed COIs before their current policies lapse, locking out non-compliant contractors automatically. Finally, our workflows scan for critical additional insured language and carrier validity, ensuring your assets are protected before work ever begins.

Protect your portfolio without sacrificing your team's time. Let VendorAccess handle the compliance so you can focus on operations.

Quick-Fire FAQs

  • Do we need a COI from low-risk vendors? Yes. Anyone performing physical work on-site should provide a COI with basic General Liability. For purely off-site or delivery-only vendors, you can customize lower-risk thresholds within VendorAccess to keep onboarding fast but secure.
  • Is a COI a legal guarantee of coverage? No. A COI is a summary of coverage as of the day it was issued. In a legal dispute, courts look at the actual insurance policy and its specific endorsements, which is why verifying the "Additional Insured" endorsement wording on the COI is so vital.
  • What should we do if a vendor's policy expires mid-project? Stop the work. Issue a clear policy that states no active COI means no property access. VendorAccess automatically flags upcoming expirations weeks in advance so you can avoid project delays.