Insurance

How to Track Certificates of Insurance From Intake to Renewal

Track COIs with clear review states, contract requirements, policy-level renewal dates, and exception owners. Compare spreadsheets, software, and services.

In this guide

Track certificates of insurance by connecting each vendor and contract to its requirements, received documents, review status, renewal dates, and unresolved exceptions. Give every gap an owner and a next action. The result should show what evidence you hold and what still needs attention; a certificate on file does not guarantee that a particular claim will be covered.

This guide is for operations and risk teams managing vendor or subcontractor evidence. It covers collection through renewal, with a comparison of spreadsheets, software, and outsourced services. It does not determine the insurance requirements for a particular contract or replace review of the relevant policy.

Define what the tracker is allowed to say

A single green status is too ambiguous. It might mean a document arrived, someone reviewed the required limits, or a risk owner accepted an unresolved issue. Use labels that describe the actual checkpoint, and retain the evidence behind them.

Use the open scorecard to compare evidence, review ownership, and export capabilities.

The following status model is a proposed operating method. Adapt it to your contracts and review authority.

StatusMeaningNext owner
RequestedRequirements and a due date have been sent; evidence has not yet been receivedVendor coordinator follows up.
Received, awaiting reviewA file is stored and associated with the vendor and relevant contractReviewer checks identity, period, and the applicable requirements.
Gap identifiedA specific item is missing, inconsistent, or requires interpretationCoordinator obtains evidence; risk or insurance specialist resolves interpretation.
Reviewed against requirementsThe specified checks are complete for the recorded documents and requirements versionProgram owner monitors renewal and relevant changes.
Exception acceptedAn authorized person accepted a stated departure for a defined scope and periodApprover owns the decision and its expiry.
Renewal evidence outstandingThe current record does not yet contain reviewed evidence for the next policy periodCoordinator escalates under the agreed procedure.

Use a separate decision for permission to start or continue work. The project or procurement owner should see the unresolved issue and the authorized decision, rather than inferring permission from a document status. Record a time-limited exception separately from a requirement met.

Build the record around the contract and policy periods

Start with the active vendor list from procurement, project management, or accounts payable. Reconcile it with the tracker so newly engaged vendors do not remain invisible. One vendor can have several contracts with different requirements; one certificate can refer to several policies with different expiration dates.

At a minimum, record the vendor's legal identity, contract or project reference, type of work, responsible business owner, requirements version, document links, and vendor or agent contact. For each relevant policy, record the insurer, policy identifier, effective and expiration dates, and the fields your approved requirements ask you to check. Track required endorsement evidence separately from the certificate.

Store the original file, receipt date, reviewer, review date, and findings. Keep older versions according to your retention policy. A replacement document should not overwrite the evidence on which an earlier decision was made. Restrict access to information staff need for their role.

A certificate summarizes; the policy determines its terms

Do not ask a certificate to supply rights absent from the policy. For a concrete jurisdictional example, the Texas Department of Insurance's certificate FAQ explains that certificate wording cannot expand policy coverage, and cancellation-notice rights depend on the policy, endorsement, or applicable law. These are Texas-specific explanations; have the appropriate adviser check requirements in the jurisdictions involved.

The standard form says so itself. The ACORD 25 (2025/12) certificate of liability insurance, as posted by New York's Department of Financial Services, states that it is issued as a matter of information only, confers no rights upon the certificate holder, and does not amend, extend or alter the coverage afforded by the policies it lists. It adds that an additional insured needs additional insured provisions in the policy or an endorsement, and that a statement on the certificate does not confer rights in place of that endorsement.

Use your risk adviser to define which evidence is needed for each requirement and who can interpret it. A field showing an additional-insured indicator is a reason to examine the required supporting material, not a substitute for deciding whether the terms apply to your entity and work. Likewise, a future expiration date does not establish that a policy has remained unchanged since the document was issued.

Extraction software can help record fields and flag discrepancies. The operating question remains whether the team has enough reliable evidence for the decision it is making. When wording, authenticity, exclusions, or scope is uncertain, preserve the question and refer it to the authorized reviewer.

Work through a renewal without losing the unresolved issue

This fictional scenario illustrates the workflow, not a claim or client result. A facilities company requires a contractor's current insurance evidence before a new project begins. The contractor submits a certificate with dates covering the planned work, but an endorsement requested by the company's risk adviser is absent.

The coordinator records receipt and leaves the requirement open. A follow-up names the specific missing evidence and the project reference. If the project manager wants work to begin immediately, that becomes a decision for the designated risk approver; the coordinator does not change the review status to make the dashboard look complete.

Suppose the missing document later arrives and the reviewer accepts the record. When renewal approaches, the tracker requests evidence for the next term and repeats the applicable checks. It does not assume the earlier endorsement carries forward unchanged. If the renewed policy begins after the old policy expires, the gap is visible for review rather than silently joined into one continuous date range.

A useful history now answers four questions: what was requested, what was received, what was checked, and who approved the next action. That history supports later investigation; it does not predetermine how an insurer will respond to a claim.

Choose the tracking approach by the work it must support

A spreadsheet can be adequate when the program is stable, reminders are reliable, documents are linked, and an owner can review the workload. There is no universal vendor-count cutoff. A small set of complex projects can require more control than a larger set of uniform low-complexity relationships.

ApproachWhen to consider itWhat to demonstrate
Spreadsheet plus document storageRequirements and handoffs remain manageable with an assigned coordinatorPolicy-level dates, reminders, version links, access control, backup ownership, and an exception log
Tracking softwareRepeated collection, changing requirements, or multiple teams exceed the current processCorrect requirement assignment, usable vendor requests, supporting-document review, and reliable integration with the active vendor list
Outsourced tracking serviceThe business needs capacity for collection or a clearly defined review serviceContracted scope, reviewer qualifications, escalation times, evidence retention, and decisions retained by your risk owner

TrustLayer's product page describes document collection, requirement checking, and reminder workflows. Treat those as capabilities to test against your program, not proof of coverage or a reason to skip review of the service scope.

For any option, ask it to handle a vendor with two projects, three different policy expiration dates, an absent endorsement, and a temporary exception. Then export the record. If staff cannot reconstruct those relationships outside the dashboard, resolve that limitation before migrating the program.

Make renewal follow-up lead to a decision

Choose reminder intervals from the time your vendors and reviewers actually need, the contract, and the work schedule. For example, a program might propose reminders 45 and 15 days before expiration, but those intervals are illustrative, not a legal standard or a guarantee against a lapse. Assign an escalation date early enough for the business owner to act.

Track active relationships with missing evidence, overdue reviews, unresolved gaps, exceptions approaching expiry, and renewals not yet reviewed. Distinguish overdue evidence from verified cancellation or expiration; the tracker should not assert facts it has not established. Review the oldest unresolved items with the people who can make the decision.

The insurance operations guide provides related document and ownership context. A dependable COI program makes the next action clear at collection, review, and renewal, while keeping the limits of its evidence visible.

Quick answers

Does a certificate of insurance guarantee coverage?

No. A certificate summarizes policies at the time it was issued. The ACORD 25 form states that it confers no rights upon the certificate holder and does not amend, extend or alter the coverage afforded by the policies; the policy terms, endorsements and applicable law decide coverage.

What should a certificate of insurance tracker record?

The vendor's legal identity, contract or project, requirements version and business owner; for each policy, the insurer, policy number, effective and expiration dates and the fields your requirements check; required endorsement evidence; and the reviewer, review date, findings and any accepted exception.

How far ahead should we request renewal certificates?

Set the interval from how long your vendors and reviewers actually take and when the work is scheduled. Reminders at 45 and 15 days before expiration are one illustrative pattern, not a legal standard; add an escalation date early enough for the business owner to act.

Is a spreadsheet enough to track certificates of insurance?

It can be when requirements are stable, reminders are reliable, documents are linked and one owner can manage the workload. There is no universal vendor count that forces software; test any option on a vendor with several projects, policy dates and an open exception.

Sources

  1. Texas Department of Insurance's certificate FAQ · tdi.texas.gov
  2. The ACORD 25 (2025/12) certificate of liability insurance · dfs.ny.gov
  3. TrustLayer's product page · trustlayer.io

Revision note · September 24, 2026: Updated with the standard certificate form's own disclaimer and short answers on coverage, tracking fields, renewal timing and spreadsheets.

How we research and review these guides

AI transformation with Clairvance

Put the ideas to work in your business.

We provide AI consulting and implementation for insurance agencies and brokers. Bring us the process that is slowing your team down and the systems involved. We can assess the problem with you and discuss a practical implementation.

Discuss your project →

Still exploring? Explore the Workflow Opportunity Workbook →