COI vs Endorsements: What Proves Coverage (and What Doesn’t)

A certificate of insurance sitting in your filing cabinet might be the most dangerous document in your business. Not because of what it says, but because of what it doesn't say. Every year, companies discover after a loss that the COI they relied on was little more than a snapshot: a moment-in-time summary that carried zero contractual weight. The real proof of coverage lives somewhere else entirely, buried in endorsement pages most people never bother to request. Understanding what actually proves coverage versus what merely describes it is the difference between being protected and holding an expensive illusion. If you manage risk for your organization, or if you're responsible for vetting vendors and subcontractors, this distinction should keep you up at night.
The Fundamental Difference Between a COI and an Endorsement
Think of it this way: a COI is a photograph of a house. An endorsement is the deed. One tells you what the house looks like on a given day. The other defines who owns it, what rights they have, and what restrictions apply. Both relate to the same property, but only one holds up in court.
The confusion between these two documents costs businesses real money. A 2025 survey from the Insurance Information Institute found that nearly 40% of claims disputes between contracting parties involved disagreements about what a COI actually guaranteed. The answer, in almost every case, was nothing. The gap between what people believe a COI promises and what it legally delivers is one of the most persistent blind spots in commercial risk management.
COI: The Informational Snapshot
A certificate of insurance is a standardized form, most commonly the ACORD 25, that summarizes key details about an insurance policy. It lists the insured party, the insurer, policy numbers, effective dates, coverage types, and limits. A broker or agent generates it and provides it to a third party, usually because a contract requires proof of insurance.
Here's the critical part: a COI is informational only. It does not amend, extend, or alter the coverage described in the actual policy. If the policy changes the day after the certificate is issued, the COI becomes instantly outdated, and nobody is obligated to tell you. The certificate holder has no contractual relationship with the insurer based on the COI alone.
Endorsement: The Binding Policy Amendment
An endorsement is a formal modification to an insurance policy. The insurance carrier issues it, attaches it to the policy, and it changes the terms of coverage. When a contract requires a vendor to name you as an additional insured, that requirement isn't fulfilled by a line on a COI. It's fulfilled by an actual additional insured endorsement attached to the vendor's policy.
Endorsements carry legal weight because they are part of the policy contract. If a dispute arises and you need to prove you were covered as an additional insured, the endorsement is what matters. At best, the COI is evidence that someone intended to provide that coverage. Intention and execution are very different things in insurance law.
Why a Certificate of Insurance Isn't a Legal Guarantee
This is where organizations get burned. A COI feels official. It has policy numbers, carrier names, and a certificate holder box with your company's name neatly typed in. It looks like proof. But courts across the country have consistently ruled that certificates of insurance do not create, modify, or guarantee coverage.
The 'For Information Only' Disclaimer
Look at the top of any standard ACORD certificate form. You'll find language stating the certificate is issued "as a matter of information only and confers no rights upon the certificate holder." That's not fine print buried on page twelve. It's right there at the top, in plain language, and it means exactly what it says.
This disclaimer exists because the certificate is not a contract between you and the insurer. The insurer may not even know the certificate was issued. In many cases, brokers generate COIs without carrier involvement. The carrier's obligation runs to its policyholder, not to whoever happens to be listed as a certificate holder. If you're relying on a COI as your safety net, you're standing on air.
Common Discrepancies Between COIs and Actual Policy Terms
The gap between what a COI states and what the underlying policy actually provides can be startling. Here are the most frequent discrepancies risk managers encounter:
- Coverage limits listed on the COI may reflect aggregate limits already partially eroded by prior claims during the policy period.
- The COI may indicate "additional insured" status, but the actual policy contains no corresponding endorsement, or the endorsement uses restrictive language that limits coverage to specific operations.
- Policy exclusions that would apply to your specific project or contract aren't visible on the certificate. A general liability policy might exclude pollution, professional services, or work at certain heights, and you'd never know from the COI alone.
- Cancellation notice provisions on the certificate often state the insurer will "endeavor to" provide 30 days' notice, but that language creates no binding obligation. The carrier can cancel the policy without ever notifying the certificate holder.
These aren't edge cases. They're routine. And they only surface when something goes wrong, and someone files a claim.
Critical Endorsements Every Risk Manager Should Verify
If the COI is the photograph, endorsements are the structural inspection report. You need to see the actual documents to know what you're dealing with. Three endorsements in particular should be on every risk manager's verification checklist.
Additional Insured Status
Being named as an additional insured on a vendor's or subcontractor's policy gives you direct rights under that policy. If the vendor causes damage or injury related to their work for you, you can tender the claim to their insurer rather than filing against your own policy. This preserves your loss history and protects your premiums.
But dozens of additional insured endorsement forms exist, and they vary wildly in scope. The CG 20 10 (ongoing operations) and CG 20 37 (completed operations) are the most commonly requested, but older or more restrictive forms may limit coverage to claims arising only from the named insured's sole negligence. Some forms only apply to work performed at a specific location. If the endorsement language doesn't match what your contract requires, you have a gap, and a COI won't fill it.
Waiver of Subrogation
Subrogation is an insurer's right to recover claim payments from a responsible third party. A waiver of subrogation endorsement prevents the vendor's insurer from coming after you to recoup losses, even if you were partially at fault. This is standard in most construction contracts and increasingly common in service agreements.
Without the actual endorsement on file, you're trusting that the waiver exists based on a checkbox on the COI. That's a bet, not a risk management strategy. If the vendor's carrier pays a $500,000 claim and then discovers no waiver was ever added to the policy, they'll come after your company.
Primary and Non-Contributory Language
This endorsement ensures the vendor's policy responds first in a claim, before your own insurance is called upon to contribute. Without it, both policies might share the loss, which means your policy takes a hit even though the vendor caused the problem.
Primary and non-contributory language is especially important in situations involving multiple layers of contractors and subcontractors. On a large construction project, for example, the general contractor needs each sub's policy to respond as primary. If even one subcontractor's policy lacks this endorsement, the GC's insurer may pay a share of the loss, and that cost flows directly back to the GC's bottom line.
Best Practices for Proving Comprehensive Coverage
Knowing the difference between certificates and endorsements is step one. Most organizations struggle to build a process that consistently verifies actual coverage. Shifting from collecting COIs to verifying endorsements requires both a mindset change and a workflow change.
Moving Beyond the ACORD 25 Form
The ACORD 25 was designed as a convenience, a quick summary for parties that need to confirm a policy exists. It was never intended to replace policy review. Yet most organizations treat COI collection as the entirety of their insurance verification process. That's like checking that a car has an engine without confirming it has wheels.
A stronger approach starts with your contracts. Specify exactly which endorsements are required, referencing specific form numbers where possible. Then require copies of the actual endorsement pages, not just the certificate. This means asking for the CG 20 10, the waiver of subrogation endorsement, and the primary and non-contributory endorsement as separate documents. Yes, it's more work. But it's the only way to confirm that what the COI claims is actually reflected in the policy.
Risk managers should also build renewal tracking into their process. Policies renew annually, and endorsements from last year's policy don't automatically carry over. A vendor who was properly endorsed in 2025 might have a completely different policy structure in 2026. If you're not re-verifying at renewal, you're running on stale information.
Automating the Collection of Endorsement Pages
Manual endorsement verification is brutal. For an organization managing hundreds or thousands of vendor relationships, tracking down endorsement pages, comparing them against contract requirements, and flagging gaps is a full-time job for multiple people. And it's the kind of repetitive, detail-heavy work where human error thrives.
This is where technology becomes essential. Automated compliance tracking platforms can request, collect, and store endorsement documents alongside COIs, flagging discrepancies between contract requirements and actual policy terms. The goal is to move from periodic, fire-drill audits to continuous awareness: knowing at any moment which vendors are fully compliant and which have gaps.
Organizations that do this well tend to follow a governance model in which the central risk team sets standards and maintains oversight. At the same time, project leads or site managers handle day-to-day collection. This prevents bottlenecks without sacrificing visibility. Without that structure, you end up with fragmented data spread across email inboxes and shared drives, and coverage gaps stay hidden until a claim forces them into the open.
Mastering Your Risk Mitigation Strategy
The question of what proves coverage versus what merely suggests it isn't academic. It has direct financial consequences every time a claim is filed, a lawsuit is served, or an audit reveals gaps. COIs serve as quick-reference documents, but they are not proof of coverage in any legally meaningful sense. Endorsements are.
Building a verification process that goes beyond certificates requires effort. Still, the alternative is worse: discovering after a seven-figure loss that the coverage you assumed existed was never actually in place. The organizations that get this right treat endorsement verification as a core business function, not an administrative afterthought. They invest in systems, train their teams on what to look for, and hold vendors accountable for providing actual documentation, not just summaries.
Explore More TrustLayer Insurance Insights
If you're rethinking how your organization handles insurance verification, TrustLayer publishes regular insights on compliance tracking, vendor risk management, and the practical mechanics of building a modern risk program. Their content is worth exploring, especially if you're in the early stages of moving from manual processes to something more sustainable.
Book a Consultation with Our Insurance Experts
Risk management shouldn't mean chasing paper and hoping for the best. TrustLayer helps organizations automate the collection, storage, and verification of compliance documents like COIs and endorsements, replacing the phone calls, spreadsheets, and guesswork that slow teams down. If you're ready to stop treating certificates as proof and start verifying what actually matters, set up a time to talk with our team and see how a purpose-built platform can close the gaps in your current process.











