Insurance & COI

What to Check on a Subcontractor's COI (Beyond the Limits)

The limits are the easy part. The endorsements are where coverage quietly fails.

Most certificate reviews start and end with the limits: the sub was supposed to carry a million per occurrence, the certificate shows a million per occurrence, done. Limits are the easy part. The claims that surprise general contractors usually trace back to the parts of the submission that a quick review skips—the endorsements, the wording, and the gap between what a certificate says and what a policy actually does. This article covers what a thorough COI review looks at, in roughly the order the problems occur. It is general education, not coverage or legal advice; requirements vary by contract and by insurance program, and your risk manager and broker should have the final word on yours.

The standard form is the ACORD 25 certificate of liability insurance, and the first checks are mechanical. The named insured should match the entity you contracted with, not an affiliate or a similarly named company. The certificate holder should be your correct legal entity. The producer block tells you which broker to contact when something needs correcting, which you will need later. Policy numbers and policy periods should be present for each line, and the policy periods should cover your project's schedule—a certificate that expires two months into a ten-month job is a reminder on a calendar, not evidence of coverage for the work.

Then the coverage lines, checked against the specific minimums in your subcontract rather than a generic standard. Commercial general liability carries separate figures worth distinguishing: the each-occurrence limit, the general aggregate, and the products/completed-operations aggregate, and your requirements may also specify that the aggregate apply per project. Automobile liability typically requires a combined single limit and should indicate coverage for owned, hired, and non-owned autos where your contract calls for it. Workers' compensation shows statutory limits alongside employer's liability limits, which are stated separately and are the ones your contract sets minimums for. If umbrella or excess coverage is required, confirm the limit and, where your program requires it, that it sits over the underlying lines you care about.

Everything above is visible on the certificate's face. The failures that matter mostly live one layer down.

Additional insured status, in two parts. Construction contracts routinely require the sub's CGL policy to name the GC (and often the owner) as an additional insured. What a quick review misses is that ongoing and completed operations are separate grants. The common ISO endorsement for ongoing operations, CG 20 10 in its recent editions, covers you while the sub's work is in progress and stops there. Coverage for claims that surface after the work is done—which describes most construction-defect claims—requires a completed-operations endorsement such as CG 20 37. A file containing only the first endorsement looks compliant on the day it's reviewed and fails years later, precisely when a claim arrives. Carriers also issue proprietary endorsement forms whose wording differs from the ISO standards, which is exactly the kind of variation a checkbox review cannot catch.

Primary and noncontributory wording. Many contracts require that the sub's coverage respond first, without seeking contribution from your own program. That protection comes from policy wording or an endorsement, not from a typed note in the certificate's description box. If your contract requires it, the review has to confirm it in the actual endorsement language.

Waiver of subrogation. Where required, the sub's carrier waives its right to recover against you after paying a claim. The same rule applies: the waiver exists if an endorsement says so.

The ACORD 25 states its own limitation plainly: it is issued as a matter of information only and confers no rights on the certificate holder, and it does not amend or alter the coverage of the policies it lists. The form itself notes that additional insured status requires the policy to be endorsed and that a statement on the certificate does not substitute for the endorsement. (The current form is a public document; New York's Department of Financial Services publishes it here.) In practical terms: the certificate is a broker's snapshot, the policy and its endorsements are the contract, and when the two disagree, the policy wins. A review that never sees the endorsements is a review of the snapshot.

This is why a complete submission is a packet—certificate, endorsements, and sometimes policy forms—and why the review is genuinely time-consuming when done properly. Each document has to be read, matched against the requirement it's meant to satisfy, and checked for wording that narrows the grant.

Reading a multi-document submission against a specific set of requirements is the work Bex Insurance was built for. Your requirements—limits, endorsements, wording—are configured in plain English, per project or program. When a sub submits, Bex reads the certificate, the endorsements, and any policy documents as one packet and returns an assessment stating which requirements are satisfied, which are not, and which are ambiguous. When something is missing, Bex writes to the sub and names the exact gap, then follows the correspondence through to a complete file. Unusual policy structures and conflicting endorsements are not silently scored; they're escalated to your team with Bex's analysis attached, because the judgment calls belong to people, not the machine.

A checklist is a good start, and if this article becomes your team's checklist it has done its job. If you'd rather the checklist ran itself against every packet, on every project, we can show you what that looks like with your own requirements—the contact link is below.