OnComply

We use cookies to improve your experience and analyze site usage. Privacy Policy

Back to Blog
Risk Management·4 min read

Certificate of Insurance Requirements by Industry

Minimum COI requirements are not universal. Here is how to set appropriate coverage requirements for vendors in different industries.

By
OnComply
Published
Updated

One of the most common vendor compliance mistakes is applying the same COI requirements to every vendor regardless of what they do. A software consultant and a commercial cleaning company present fundamentally different risk profiles. Your insurance requirements should reflect that. (New to COI handling? Start with our guide to collecting and tracking COIs.)

This guide covers how to identify relevant coverage by vendor type. It deliberately does not publish universal minimum limits because appropriate limits require facts about the work, contract, loss scenarios, policy terms, and jurisdiction.

Why Coverage Minimums Matter

A COI satisfies your process only when the policy information and required endorsements match requirements that were set through a defensible risk and insurance review.

If you require $1M general liability and a vendor provides a COI showing $500K, that COI does not satisfy your requirement, regardless of the expiration date or the insured name. Your requirements need to be specific about coverage type and limit. Automated COI validation enforces exactly this kind of rule.

Coverage Questions by Vendor Type

General Business Service Vendors

(Consultants, advisors, marketing agencies, technology contractors; no physical presence at your site)

Consider commercial general liability and, where negligent professional services could cause loss, professional liability. Ask an insurance professional how contractual liability, exclusions, defense costs, and claims-made terms affect the protection.

On-Site Service Vendors

(Facilities management, cleaning services, maintenance, catering, security)

Consider general liability, workers' compensation or permitted alternatives under applicable state law, employer's liability, auto exposure, property in the vendor's care, and whether the contract calls for additional-insured coverage.

Construction and Trades

(General contractors, subcontractors, electricians, plumbers, HVAC, structural work)

Construction programs may address general liability, completed operations, workers' compensation, employer's liability, commercial auto, builders risk, professional liability for design responsibilities, pollution, and umbrella or excess coverage. Additional-insured, waiver-of-subrogation, and primary/noncontributory requirements must come from the contract and actual endorsements, not the certificate alone.

General contractors managing dozens of subcontractor COIs should also read our subcontractor compliance guide, or see how OnComply for construction automates the workflow.

Technology Vendors with Data Access

(SaaS vendors, data processors, cloud infrastructure, managed security providers)

Consider technology errors and omissions, cyber/privacy coverage, general liability, crime/social-engineering coverage, and exclusions or sublimits relevant to the service and data. Insurance complements rather than replaces security due diligence and contract controls.

Healthcare Vendors

(Staffing agencies, medical equipment providers, clinical service providers)

Consider general liability, professional or medical malpractice coverage, workers' compensation, employer's liability, auto, cyber/privacy, and any coverage mandated by licensing, facility, payer, or contract requirements.

Financial Services Vendors

(Payroll processors, accounting firms, financial consultants, lenders)

Consider professional liability, cyber/privacy, crime or fidelity coverage, general liability, and any bond or insurance required by the vendor's regulator or license.

Customizing Requirements for Your Risk Profile

The relevant coverage types are prompts, not mandates. Your actual requirements should be calibrated to:

Plausible loss scenarios. Contract value alone may not measure the potential bodily injury, property, privacy, professional, or business-interruption loss.

The vendor's exposure on your premises. A vendor doing one day of work in your lobby needs less coverage than a vendor doing six months of construction on your building.

Your industry's norms. Some industries have established insurance requirements that carry weight; construction is heavily standardized, for example. Align with your industry where standards exist.

Your insurance program and contract. Coordinate requirements with your broker, insurer, and counsel so they align with your own policies and contractual allocation of risk.

What to Do When a Vendor Cannot Meet Your Requirements

Some vendors, particularly smaller sole proprietors and very small businesses, may be unable to obtain coverage at your required limits. You have several options:

Require the vendor to obtain a certificate of insurance that meets your requirements. This is the right answer for significant vendor relationships. If they cannot get the coverage, that is relevant information about their size and risk profile.

Adjust requirements proportionally for smaller vendors. If the engagement is low-risk and low-value, accepting lower limits is a risk decision you can make explicitly rather than by accident.

Document the exception. If you accept a vendor with coverage below your stated requirements, document that you made this decision intentionally, the reason for the exception, and the compensating controls in place.

Review risk allocation. Counsel can evaluate indemnification and other remedies. Contract terms do not replace insurance or guarantee collectability.

For the communication side of enforcing requirements, see how to handle non-compliant vendors.

Authoritative references


All posts
W-9 CollectionCOI TrackingACH AuthorizationDocument Fill & SignAutomated ValidationRenewal RemindersCan-Work / Can-Pay ControlsVendor PortalCompliance DashboardWebhook IntegrationsEligibility APIAudit-Ready ExportsLicense TrackingGrace Period ManagementCustom FormsW-9 CollectionCOI TrackingACH AuthorizationDocument Fill & SignAutomated ValidationRenewal RemindersCan-Work / Can-Pay ControlsVendor PortalCompliance DashboardWebhook IntegrationsEligibility APIAudit-Ready ExportsLicense TrackingGrace Period ManagementCustom Forms