Practical guide
Certificate of Insurance (COI) Tracking: A Vendor COI Expiration Checklist
A certificate of insurance shows coverage as of the day it was issued. Use this checklist to record each vendor coverage line, assign an owner, and catch expirations before they become a problem — dates and ownership, not coverage review.
October 7, 2026 · 6 minute read
Why COI expirations slip
A certificate of insurance (COI) shows that a vendor had certain coverage as of the day it was issued. You collect it at onboarding, file it, and move on. Months later the policy renews, or doesn't, and nobody on your side notices.
The usual reasons:
- The certificate lives in an email attachment or a shared folder, not on a list with dates
- One vendor has several policies that expire on different days
- Nobody owns the follow-up, so the request for a new certificate never goes out
- The vendor keeps working because nothing tells anyone to pause
This checklist is for ops, facilities, admin, and finance teams who collect vendor COIs and want to catch expirations before they become a problem. It covers dates and ownership. It is not legal or insurance advice. Questions about what coverage you require, or whether a certificate meets your contract, belong with your broker or legal counsel.
What to record for each certificate
Track one row per coverage line, not one row per vendor. A vendor's general liability can be current while their auto or workers' compensation policy has lapsed.
- Vendor: legal name as it appears on the certificate
- Coverage line: for example general liability, auto, workers' compensation, professional, umbrella
- Policy effective date and policy expiration date
- Certificate received date: when you got this copy
- Insurer and broker contact: who to ask for a fresh certificate
- Vendor contact: the person who will actually send the renewal certificate
- Internal owner: the named person on your side who chases it
- Status: current, renewal requested, received, lapsed, or vendor inactive
- Source link: where the certificate file is stored
- Notes: anything your contract requires that you check on each renewal (keep the requirement itself with legal or your contract, not reinvented here)
If you already keep a general expiration tracker, COIs can live in the same list with a clear category. See how to track expiration and renewal dates without missing one for the core columns.
Set reminders before each policy expires
Anchor reminders to the policy expiration date on each coverage line. A sequence works better than a single ping because vendors and brokers take time to respond.
A practical starting ladder:
- 60 days before: confirm the vendor contact is still right and let them know a renewal certificate will be needed
- 30 days before: request the renewal certificate from the vendor or their broker
- 14 days before: follow up if nothing has arrived and loop in whoever manages the vendor relationship
- 7 days before: escalate internally and decide what happens if coverage is not confirmed by the expiration date
Adjust the ladder to your risk. Vendors who work on site or touch customer locations deserve the longer runway. For why a sequence beats one reminder, see the 90/60/30-day renewal reminder schedule.
When the new certificate arrives
- Save it as a new record; do not overwrite the old one
- Enter the new effective and expiration dates for each coverage line
- Check that the new effective date picks up where the old expiration left off, and note any gap
- Route anything that looks different from what your contract requires to the person who owns insurance requirements (often legal, finance, or your broker)
- Update status and set the next round of reminders
- Keep the superseded certificate on file
Keeping old certificates matters. If someone later asks whether a vendor had coverage on a specific past date, you want the certificate that was in effect then, not just the latest one.
Decide in advance what happens on a lapse
The worst time to invent a policy is the morning a certificate expires. Agree on it now, in writing, with whoever owns vendor risk:
- Who gets notified when a coverage line lapses
- Whether work pauses, payment holds, or both, until a current certificate arrives
- Who can approve an exception, and for how long
- How the vendor is told
Keep this short. A one-paragraph rule that people follow beats a long policy nobody reads.
Weekly and quarterly rhythm
Weekly (10 to 15 minutes): Scan coverage lines expiring in the next 30 days. Confirm each has an owner and a renewal request out. Chase anything with no response.
Quarterly: Look for vendors marked inactive who still have site access or open purchase orders. Check that vendor contacts and broker contacts are still valid. Archive vendors you no longer use, but keep their certificate history.
Spreadsheet version
A spreadsheet can carry this for a modest number of vendors. Use one row per coverage line, a computed "days until expiration" column, and conditional formatting for anything inside 30 days. Freeze the header row and keep one master copy.
When the sheet starts to drift (owners left blank, reminders living in one person's calendar, nobody sure which certificate is current) see how to move renewal tracking out of spreadsheets.
FAQ
How often should we ask for a new certificate?
At least at every policy renewal, which for many commercial policies is annual. Because each coverage line can renew on a different date, track each line separately.
Is a certificate proof that coverage is active today?
A certificate reflects coverage as of the date it was issued. If you need to confirm current status, ask the vendor's broker. Your broker or legal counsel can advise on what your contracts require.
Who should own COI follow-up?
One named person on your side, usually whoever manages the vendor relationship or vendor onboarding, with a backup. A shared inbox can receive the certificates, but a person should own the chase.
Should COIs live in the same tracker as software and contract renewals?
They can, if the same team runs the reminders. Label the category and the date meaning clearly, since a policy expiration is a different clock from a software cancel-by date.
Does this replace a review by our broker or legal team?
No. This checklist keeps dates and follow-ups from slipping. Coverage requirements and whether a certificate satisfies a contract are questions for your broker or counsel.