COI Expiration Tracking: How to Catch a Lapse Before It Becomes a Claim
A certificate isn't a static file — it has a shelf life, and no one is obligated to tell you when it runs out. How to build expiration tracking that actually catches a lapse.
Expiration tracking isn't the admin part of compliance — it's the whole program
Most advice on vendor certificates centers on collection and verification: get the document, check the limits, confirm the endorsements. Expiration tracking gets treated as what happens after the real work — a calendar reminder, a spreadsheet column with a date in it. That framing has it backwards. For the entire life of a vendor relationship, the expiration date is the only thing standing between "verified" and "unknown." Everything else you confirmed on the certificate — the limits, the additional insured endorsement, the named entity — was true on the day it was issued. None of it comes with a guarantee that it's still true today.
That makes expiration tracking the load-bearing piece of the entire process, not the cleanup step at the end of it. A perfectly verified certificate of insurance that nobody re-checks at renewal degrades into exactly the same risk as never having verified it at all — it just takes longer to notice, and by the time it's discovered you're looking at the kind of exposure covered in the real cost of a lapsed vendor policy. The broader collection-and-verification workflow is covered in how to track certificates of insurance; this guide is about the piece that workflow depends on to keep working over time: knowing, reliably, when a certificate stops being current.
Why you can't count on being told
The instinct most people have is that someone will flag it — the insurer will send a cancellation notice, the vendor will mention it, the broker will follow up. Structurally, none of that is guaranteed, and the reasons are worth knowing because they're the actual justification for building tracking instead of trusting the system to self-report.
Start with the certificate itself. The ACORD 25 form carries its own cancellation clause, and the current version's wording is explicit about what it does and doesn't promise: should a listed policy be cancelled before its expiration date, the issuing insurer "will endeavor to mail" a set number of days' written notice to the certificate holder — but failure to do so "shall impose no obligation or liability of any kind upon the insurer, its agents or representatives." ACORD tightened this language in the 2009 revision specifically to remove any implication that the certificate holder has an enforceable right to notice. "Will endeavor" is a best-effort statement, not a commitment, and the form says so in the same sentence.
State insurance law doesn't fill that gap the way people assume it does. Most states do require insurers to give written cancellation notice — commonly around 10 to 15 days for non-payment and 30 to 60 days for other underwriting reasons — but that notice obligation almost always runs to the named insured (the vendor) and, in some states, to the vendor's broker. It is not, in the general case, a right extended to a third-party certificate holder like you. New York's own regulator has issued opinions on exactly this point, confirming that a certificate holder's entitlement to cancellation notice depends on what the certificate itself promises, not on a separate statutory right of its own.
Put together, that means the two parties best positioned to warn you — the insurer and the vendor — are each under no enforceable obligation to. The insurer has a courtesy clause it can decline to honor without consequence, and the vendor whose coverage just lapsed has no incentive to volunteer that fact mid-contract. Expiration tracking isn't one option among several for catching a lapse. For most vendor relationships, it's the only mechanism that exists.
Two different problems hide under "expired," and most tracking only catches one
The obvious failure is the certificate's own expiration date passing with nobody noticing. That's real, but it's the easier of the two problems, because the date is sitting right there on the document — a system that just watches that field will catch it eventually.
The harder problem is the one a plain expiration-date tracker misses entirely: a certificate that hasn't reached its stated expiration date yet no longer reflects current coverage, because the underlying policy was cancelled mid-term. A vendor's insurer can cancel for non-payment, for a claims history the underwriter didn't like, or simply by choosing not to renew — and none of that shows up on the certificate you already have on file, because that document was accurate the day it was issued and was never designed to update itself. A certificate dated to expire next March tells you nothing about whether the policy behind it is still in force this Tuesday.
The inverse case trips people up too, in the other direction: a certificate can show an expiration date that's already passed while the underlying policy actually renewed on time — the vendor's broker was simply slow to issue the updated paperwork. Reflexively treating every certificate past its printed date as a live compliance gap, without a quick check, wastes chase effort on vendors who are actually fine. Both directions point to the same conclusion: the certificate's expiration date is a useful trigger for re-verification, not a substitute for it.
Building a reminder cadence that survives broker lag
A single reminder sent on the expiration date itself is really a notice that you're already out of compliance — there's no time left to fix anything. A cadence that actually prevents a gap has to start well before the deadline and repeat, because a renewal request has several points where it can stall that have nothing to do with anyone being careless.
The vendor has to notice the request and forward it to their broker. The broker has to process the renewal, which competes with everything else in their queue. If the certificate needs an endorsement the current policy doesn't already carry, that endorsement has to be added to the policy before it can appear on a certificate — a step that can add days on its own. None of that is unusual or a sign anything's wrong; it's just how long the pipeline normally takes, and a reminder schedule has to be built around it rather than assuming a renewal happens instantly. How to request a certificate of insurance from a vendor has copy-paste wording for the renewal ask itself; this section is about the schedule that triggers it.
- 90 days out — first notice, framed as a heads-up rather than urgent. Gives the broker pipeline room to work without pressure.
- 60 days out — repeat the request if nothing's arrived. Still comfortably ahead of the deadline.
- 30 days out — this is where a plain reminder becomes a follow-up with a deadline attached, and where it's worth confirming the vendor has actually contacted their broker rather than just acknowledging the email.
- 14 days out — treat as at-risk. Escalate past whoever has been unresponsive to a manager or account contact.
- 7 days and expiration day — final notice, tied explicitly to the consequence: work pauses, access is suspended, or payment holds, whichever your contract specifies.
Not every vendor needs the same cadence
A blanket 90-day cadence applied identically to every vendor is administratively simple and functionally wasteful — it spends the same chasing effort on a low-risk supplier as on a roofing crew working three stories up. Tiering the cadence to risk, the same way you'd tier the coverage requirements themselves (covered in insurance requirements for subcontractors), concentrates the follow-up where a lapse would actually hurt.
Vendors doing high-risk or on-site physical work — general contractors, roofers, anyone operating heavy equipment — justify the full laddered cadence starting at 90 days, because the cost of a gap is highest there. Lower-risk vendors, such as a supplier who never sets foot on your property, can run on a lighter two-step cadence at 30 and 7 days without meaningfully increasing your exposure. Property managers juggling a mixed vendor list — landscapers alongside elevator contractors — are the clearest case for tiering rather than one blanket schedule. The point isn't to track less — it's to spend the finite attention of whoever is doing the chasing on the renewals where a missed one actually matters.
What actually happens when day zero arrives and nothing showed up
A reminder schedule is only half the system. The other half is deciding, in advance, what happens when the schedule runs out and the certificate still hasn't arrived — because that's the moment tracking either holds or quietly becomes theater.
The consequence that works is the one that doesn't require a judgment call under pressure: no current certificate, no continued site access, decided and written into the contract ahead of time rather than negotiated in the moment a job is already underway. Payment holds are a real lever too, but they bite too late to prevent the exposure — the uninsured work has already happened by the time an invoice is due. The uncomfortable version of this rule is that it has to apply to vendors you've worked with for years just as much as to a new one; familiarity is exactly the condition under which a lapse persists unnoticed, because nobody wants to be the one who stops a trusted vendor's crew over paperwork. Whatever arrives before the deadline still has to pass the same checks as the original — run it against the COI requirements checklist rather than treating "a certificate arrived" as the finish line.
Where a spreadsheet specifically fails at this — not at collection, at watching
A spreadsheet can hold an expiration date perfectly well. What it cannot do is notice, on its own, that today is 30 days before that date and act on it. Every reminder in a spreadsheet-based system depends on a person opening the file, scanning a column of dates, and remembering to do that on a regular cadence across every vendor's individually staggered renewal — a task that degrades the moment that person is on vacation, changes roles, or simply has a busier week than usual. Where manual tracking in a spreadsheet breaks down covers this in more detail; the specific failure relevant here is that a spreadsheet is a record, not a watcher, and expiration tracking is fundamentally a watching problem.
This is also the piece that changes hands badly. Who is responsible for tracking certificates of insurance covers the ownership question directly, but the expiration-tracking angle on it is specific: a system built entirely on one person's habit of checking a spreadsheet weekly doesn't survive that person's absence. Every certificate that was current on their last day in the role stays frozen in that state — not because anyone stopped caring, but because nothing was left watching once they were gone.
Common mistakes
The patterns that turn expiration tracking from a safeguard into a false sense of security.
- Setting a single reminder on the expiration date itself, leaving no runway to actually fix a lapse before it becomes one.
- Assuming an insurer's cancellation notice will reach you directly — the ACORD 25's own "will endeavor to mail" clause explicitly disclaims that obligation.
- Treating the certificate's printed expiration date as proof coverage is still active, rather than as a trigger to re-verify it.
- Applying the same reminder cadence to every vendor regardless of risk, which spreads limited follow-up effort too thin on the vendors where a gap matters most.
- Having no written consequence for a missed renewal, so the decision gets improvised — and usually skipped — the day it's actually needed.
- Building the entire system around one person's calendar discipline instead of a process that survives them changing roles.
What software changes, and what it doesn't
Automating the watching half of this is mechanical: track each vendor's expiration date, fire a laddered sequence of reminders to the vendor and to whoever owns the relationship internally, and surface anything that's gone quiet past the point where a broker delay stops being a plausible explanation. That's the part a spreadsheet structurally can't do on its own, and it's the part worth automating first regardless of what else you automate — see choosing COI tracking software as a small business for what else is worth looking for beyond this one feature.
It doesn't decide the escalation for you. When a vendor goes silent past day 14, or a certificate comes back with a downgraded limit, a person still has to decide whether to hold the start date, escalate to a manager, or make an exception — and own that call. CoverSynx is built around that split: it reads each certificate against your requirements, tracks the expiration date, and emails the vendor before the policy lapses, so the renewal conversation starts at 60 or 90 days out instead of after the fact. It assists verification and removes the person-dependent part of watching the calendar; it doesn't certify coverage, and the decision to pause a vendor's access is still yours to make.
FAQ
Will an insurer notify me if a vendor's policy is cancelled?
Not reliably. The ACORD 25's cancellation clause says the insurer "will endeavor to mail" notice to the certificate holder but explicitly disclaims any liability for failing to do so. State cancellation-notice laws generally protect the named insured, not a third-party certificate holder, so you shouldn't rely on outside notification.
How far in advance should I start tracking a certificate's expiration?
A common laddered approach starts at 90 days out with a light heads-up, repeats at 60 and 30 days, and escalates at 14 and 7 days if nothing's arrived. The early lead time accounts for how long a broker can take to process a renewal, especially if an endorsement needs to be added first.
Can a certificate be expired on paper but the coverage still active?
Yes. A broker can simply be slow to issue the updated certificate even though the underlying policy renewed on time. Treat a certificate past its printed date as a reason to re-verify with the vendor or broker, not as automatic proof the vendor is currently uninsured.
Can a policy lapse before the certificate's expiration date?
Yes, and this is the harder failure mode to catch. A policy can be cancelled mid-term for non-payment or underwriting reasons, and the certificate you already have on file — accurate the day it was issued — won't reflect that. The stated expiration date is not a guarantee coverage lasts until then.
Should every vendor get the same expiration reminder schedule?
No. Tiering the cadence to risk — a full 90-day ladder for vendors doing physical or on-site work, a lighter schedule for low-risk suppliers — concentrates follow-up effort where a lapse would actually be costly, rather than spreading it evenly regardless of exposure.
What should happen automatically when a certificate isn't renewed in time?
Decide the consequence in advance and put it in the contract, rather than deciding under pressure. The clearest and most enforceable rule is no current certificate, no continued site access — applied consistently, including to long-standing vendors, since familiarity is exactly how lapses go unnoticed.
Why can't a spreadsheet handle expiration tracking well?
A spreadsheet stores a date; it doesn't act on it. Every reminder depends on a person opening the file and checking it on schedule across every vendor's separately staggered renewal date, which degrades the moment that person is away, changes roles, or falls behind — with no system left watching in the meantime.
About the author
Rehan Shah — Founder, CoverSynx
I build CoverSynx, software that helps property managers and contractors keep track of their vendors' certificates of insurance. I'm not an insurance broker or a lawyer. These guides summarise published industry guidance and cite their sources — for advice on your own situation, speak to your broker.
Stop tracking certificates in spreadsheets. CoverSynx collects vendor COIs, reads each one automatically, checks it against your requirements, and chases the vendor before a policy lapses.
Start free — no card required →