Operations workflow

Top 10 vendor compliance mistakes GCs make with subcontractor COIs

By Policyhold Team, Compliance operationsPublished Updated 6 min readSources & references
  • vendor compliance mistakes
  • general contractors
  • coi tracking
  • mobilization
Share

Policyhold Team, Compliance operations. Practical guidance for GC compliance and mobilization operations.

Most general contractor compliance programs do not fail because teams are careless. They fail because email, spreadsheets, and shared drives become the system of record by default, and nobody owns daily updates, expiration logic, or field visibility.

This guide is for GC compliance coordinators, risk managers, and operations leaders who manage subcontractor insurance across active job sites. You will see the ten workflow gaps that appear most often in vendor COI programs, what each one costs in daily operations, and what strong programs do differently.

Publish trade-specific limit floors before you send COI requests. Use the subcontractor insurance requirements generator to build a printable spec by trade.

Free tool

Generate a subcontractor insurance requirements spec

Answer six questions about project type, state, trade, and value tier. Get printable GL limits, workers comp, auto, umbrella, and endorsement language.

Open generator

What are the most common vendor compliance mistakes GCs make?

These ten gaps show up across programs of every size. Most are fixable without new software, but only if someone names the failure mode and assigns an owner.

1. Treating "COI on file" as cleared for site

A certificate collected at contract award is not proof of coverage on mobilization day. Policies renew, endorsements change, and legal entities shift. Programs that never re-verify before site access mobilize on stale files.

Operational cost: Superintendents schedule work against an onboarding COI while the policy expired three weeks ago.

See the mobilization compliance checklist for a pre-site verification sequence.

2. Using email as the system of record

Email has no status model, no expiration alerts, and no project-level clearance view. Requests get forwarded, attachments duplicate, and field teams cannot tell whether a sub is cleared without asking the compliance coordinator.

Operational cost: Five PDFs named COI_final_v3.pdf with no link to which version is current.

Programs that rely on inbox tracking eventually add a spreadsheet, then calendar reminders, then a shared drive, and still break on renewals. See how to reduce vendor compliance email chaos.

3. Approving certificates from checkboxes, not endorsements

A COI can state additional insured status while the underlying CG 20 10 / CG 20 37 endorsement is missing or expired. Reviewers who trust the certificate without the endorsement PDF approve gaps that surface at audit.

Operational cost: Re-review loops, mobilization holds, and owner audit findings.

Review what is an additional insured endorsement before accepting renewal certificates line by line.

Free tool

Run a COI review before mobilization

Confirm the subcontractor certificate passes initial review and document the mobilization decision.

Open COI approval checker

4. Running expiration dates through a static spreadsheet

Spreadsheets can list COIs. They cannot sustain renewal monitoring across a growing vendor roster. Dates go stale, renewal certificates arrive in inboxes, and nobody updates the master sheet before supers mobilize.

Operational cost: Renewal drift, the earliest and most common failure mode in active programs.

Compare when spreadsheet programs break down in spreadsheet vs compliance software for vendor COIs.

5. Letting project managers be the intake front door

When subs can send COIs to any PM email address, you never have one current file. Attachments scatter across inboxes, and compliance chases threads instead of reviewing a queue.

Operational cost: Duplicate files, wrong versions, and unclear ownership when the coordinator is out.

Route intake through one tracked path. See reduce vendor compliance email chaos for a standard request workflow.

6. Showing one clearance status across multiple projects

A sub cleared on Job A may be blocked on Job B: different requirements, different owner rules, different mobilization dates. A single "cleared" flag in a spreadsheet or shared drive hides project-level truth.

Operational cost: Wrong mobilization decisions and rework when the gap surfaces mid-schedule.

Status drift: When a cleared column outlives the policy or project context, field teams schedule work against outdated status. See what happens when a COI expires mid-project.

7. Verifying once at onboarding, never at renewal

Mid-project policy renewals are where additional insured endorsements disappear, limits drop, and named insured entities change. Programs without a 60 / 30 / 0-day renewal workflow treat verbal broker confirmation as sufficient.

Operational cost: Work continues after coverage lapses until an incident or owner audit exposes the gap.

Follow the renewal cadence in COI renewal monitoring.

8. Storing documents without decision history

An audit-ready file includes what was verified, when, and by whom, not just PDFs in a folder. Reviewers who cannot reconstruct clearance decisions from email threads fail owner and insurer reviews.

Operational cost: Days rebuilding files from forwarded attachments when audit requests arrive with 48-hour notice.

Structure files for owner handoff in building audit-ready vendor compliance files.

9. Sending COI requests without a standard requirements spec

"Can you send your COI?" with no named insured rules, limit floors, endorsement form list, or due date produces wrong limits, missing additional insured parties, and endless back-and-forth.

Operational cost: Coordinators spend more time chasing corrections than reviewing certificates.

Match every request to a written program baseline. See subcontractor insurance requirements for a standard review checklist.

10. Keeping clearance status invisible to field teams

Superintendents and PMs should not live in the compliance inbox. When site access decisions depend on "email the coordinator and wait," mobilization week becomes a bottleneck and compliance absorbs heroic manual work on every schedule change.

Operational cost: Group chats asking "do we have their COI?" instead of checking a blocked / cleared / pending status.

Mobilization clearance: The operational state where a subcontractor has met documented requirements for a specific project and is approved for site access. Field teams need that status in one place. See the mobilization compliance checklist.

What do strong GC programs do differently?

Effective programs share five habits, whether they run on spreadsheets today or centralized software tomorrow:

  1. One tracked intake path. Email notifies; it does not store. Subs submit to a known destination tied to a vendor record.
  2. Project-level clearance. Blocked, cleared, and pending status per vendor per job, not one company-wide flag.
  3. 60 / 30 / 0-day renewal workflow. Request at 60 days, escalate at 30, block clearance on expiration if no valid certificate is on file.
  4. Verification on every receipt. Check limits, policy dates, named insured, and endorsements every time a COI arrives, not only at onboarding.
  5. Decision log with actor and timestamp. Record who cleared whom, when, and on which document version.

You do not need enterprise software on day one. You do need a written owner, update SLA, and a standard requirements spec before the spreadsheet outgrows your team.

A spreadsheet-first program can still work when you manage fewer than roughly 25 to 40 active subcontractors, one compliance owner updates the sheet daily, and field teams know to ask that person for clearance. Document when you have crossed that threshold, usually when renewal volume and multi-project overlap exceed what one coordinator can update manually.

MistakeFirst symptomFix
COI on file = clearedRe-mobilization without re-checkMobilization gate per project
Email as databaseDuplicate PDFs, no statusOne front door + tracked requests
Checkbox approvalsAdditional insured endorsement missing at auditCOI + endorsement PDF review
Static spreadsheetExpiration column not updated after renewal60 / 30 / 0-day alerts and outreach
Field status invisiblePMs and supers ask compliance ad hocBlocked / cleared / pending per vendor per job

Vendor compliance mistakes are workflow gaps, not character flaws. Name the failure mode, assign an owner, and connect expiration dates to mobilization decisions before crews step on site. For programs evaluating centralized tracking and gate controls, request a demo to walk through COI enforcement, mobilization clearance, and audit-ready records with our team.

Sources

Reference starting points for GC compliance teams. Verify requirements with counsel and your owner contract.

Frequently asked questions

Quick answers to common questions from GC compliance teams.

Static spreadsheets and email folders lack expiration alerts and project-level clearance status. Renewal certificates arrive in inboxes while field teams mobilize subs based on onboarding files that were never re-checked before the policy expired.

Related resources

See how Policyhold fits your vendor compliance workflow

Walk through COI enforcement, mobilization clearance, and audit-ready records with our team.

Request a demo