What to Do When a Vendor's COI Is Non-Compliant: A Step-by-Step Process
A working escalation process for non-compliant vendor COIs — diagnose the gap precisely, route the fix to the right party, escalate on a cadence, and decide the hard call: can they keep working?
Travis
Diamond Flooring Starts Next Week
2 coverage gaps—we've reached out and resolved this before work begins.
- Emailed Vendor
- Verified with Insurance Broker
- Updated new COI in system
Diamond Flooring starts next week. Travis finds that the general liability limit needs an increase and the additional insured is not listed, emails the vendor, verifies coverage with the insurance broker, and updates the new COI in the system before work begins.
A non-compliant COI puts you in an awkward spot: the paperwork says your risk transfer has a hole in it, but the vendor is mid-contract, possibly mid-job, and "stop everything" has real operational cost. The way through is a process that's precise about the gap, fast on the first move, and honest about the decision most teams avoid making explicitly: what happens while it's being fixed?
Step 1: Diagnose precisely — the gap determines everything
"Non-compliant" covers failures with very different risk profiles and very different fixes:
- Expired or cancelled coverage — the emergency tier. There may be no coverage behind the vendor right now. Fastest to confirm, slowest to forgive.
- Missing endorsements (additional insured form not attached, no completed-ops, no waiver, no P&N) — coverage exists; your access to it doesn't. The most common tier, and fixable through the agent — though endorsement changes route through underwriting, so think weeks, not days.
- Insufficient limits — real coverage, smaller than the contract requires. Fix is a policy change or (sometimes) a documented exception if the requirement was miscalibrated for the vendor's actual risk.
- Wrong entity / clerical mismatches — sometimes a five-minute cert reissue, sometimes a sign the policy names the wrong entity, which is the serious version. Diagnose which before relaxing.
Write the finding specifically — "CG 20 37 not attached; description box references AI status" — because a precise finding becomes a one-round fix, and a vague one ("cert doesn't meet requirements") becomes a month of ping-pong.
Step 2: Route the request to the party who can fix it
Certificate and endorsement corrections come from the vendor's insurance agent, not the vendor. Send the correction request to the agent directly, vendor cc'd, naming the exact forms needed and a date — templates here. The vendor's job is one thing only: telling their agent to prioritize it. Coverage changes (higher limits, new endorsement purchases) need the vendor's authorization, so those requests lead with the vendor and copy the agent.
Step 3: Escalate on a cadence, not on memory
The pattern that kills compliance programs isn't the missed finding — it's the found gap that ages silently in a tracker. Fixed cadence, written down: correction request day 0 → follow-up day 5 → phone call day 10 → vendor's owner/PM + your leverage day 15. Leverage means the mechanisms your contract gives you: hold the next payment, pause new work orders, condition the next job. Payment holds resolve endorsement gaps with remarkable speed — not because anyone's being punished, but because the agent suddenly gets a prioritized phone call from their client.
Document each round. If a claim arrives mid-gap, the file showing you found it, requested it, and escalated it is the difference between a diligence story and a negligence story.
Step 4: Make the working-status call explicitly
The question teams dodge: does the vendor keep working while non-compliant? Dodge it and the default answer is "yes, indefinitely." Make it a rule instead, tiered by the gap:
- Expired/cancelled coverage: stop work until a current cert arrives. No exceptions without an executive signature — this is the uninsured tier.
- Missing endorsements or limits: time-boxed written exception (e.g., 15 business days) with the correction in progress, payment held as backstop. High-hazard trades get a shorter box.
- Clerical mismatches: work continues, fix tracked to the same cadence.
For repeat offenders, move the enforcement upstream: compliance verified before the next engagement, not chased during it — the pre-work gate is the only version of this process that runs itself.
Step 5: Close the loop — verify the fix
The corrected certificate gets the same three-layer review as a new one; a surprising share of "corrections" fix the named gap and introduce another, and a description-box sentence is not a fix at all. Then log the resolution date. Gaps-found-to-gaps-closed is the metric that tells you whether you have a compliance program or a finding generator.
This whole pipeline — precise diagnosis, agent-direct requests, cadence-based escalation, verification of the fix — is what Tightrope's agent Travis runs automatically on every gap it finds, by email, phone, and text, until the compliant cert is on file. Your team makes the working-status calls; Travis does the rounds.
FAQ
Can I legally let a vendor work with non-compliant insurance? Usually yes (absent statutory requirements like workers' comp) — it's your risk to accept, not a legal bar. The point of the process is making that acceptance explicit, time-boxed, and documented instead of accidental and permanent.
How long should a vendor get to fix a COI gap? Cert reissues: days. Endorsement additions: 2–3 weeks (underwriting). Coverage changes: up to 30 days. Set the deadline by fix type, and hold payment — not work, necessarily — as the default backstop.
What if the vendor refuses? Then you've learned the vendor's price includes uninsured risk transfer, and the contract's remedies — termination, replacement, back-charging force-placed coverage where drafted — are the honest comparison. Most refusals are really agent inertia; the phone call upstream resolves them.
Finding gaps is the easy half. Travis closes them — diagnosis, agent chase, verified fix — on Tightrope's free plan. Bring your most stubborn open item.