Do You Need a Certificate of Insurance From Every Vendor?
Not every vendor needs a certificate of insurance — but "we trust them" isn't the test. A three-question framework for deciding, and what your lease might already require regardless.
The blanket rule almost every guide gives, and where it breaks down
Search this exact question and the advice converges fast: require a certificate of insurance from every vendor, no exceptions, because asking costs nothing. Insurance Canopy's own guidance backs that framing with a specific number — the average price of a certificate of insurance is $0, since it's the vendor's broker who issues it, not a service the vendor pays for out of pocket. That's true, and for an operation that already has a request-and-track process running, it's the safest default: build the habit once, apply it everywhere, never make an exception you'll regret later.
But that answer skips the actual decision a property manager, general contractor, or facilities lead is making in the moment — not "should our company have a policy," but "does this specific bookkeeper, this one-time handyman, this SaaS subscription in front of me right now need to go through the request-and-verify cycle." Treating every vendor identically regardless of what they actually do wastes effort on the ones that carry no meaningful exposure, and worse, it trains whoever's doing the collecting to see the requirement as bureaucratic box-checking rather than risk management — which is exactly when a genuinely high-risk vendor slips through because "we always just check the box anyway."
The real answer is: it depends on what the vendor does, not who they are, how long you've worked with them, or how small the invoice is. Here's the test that decides it.
The three-question test
Before deciding whether to request a certificate, run a vendor through three questions. A "yes" to any one of them means you need a certificate of insurance at minimum — general liability, and additional coverage depending on the answer.
- Do they, or anyone working for them, physically come onto your property, a tenant's unit, or a project site? Presence is exposure — a person on-site can fall, cause a fire, damage a fixture, or injure someone else, regardless of how routine the job is.
- Could the work plausibly cause bodily injury or property damage if something goes wrong? A landscaper's mower can throw a rock through a window. A cleaner's chemical can trigger an allergic reaction. A handyman's ladder can fall on a parked car. If a bad outcome is physically possible, general liability is the coverage that responds.
- Do they operate a vehicle or powered equipment as part of the job — a service van, a lift, a pressure washer, a delivery truck? Vehicles and equipment add an entire second category of exposure (commercial auto, equipment liability) that a desk-based vendor never triggers.
Applying the test to real vendors
Some categories are unambiguous. Others are genuine judgment calls, and the test doesn't remove judgment — it gives you three specific things to check instead of a gut feeling.
- Almost always yes: contractors, subcontractors, and trades who work on-site — plumbers, electricians, roofers, HVAC, landscaping, janitorial/cleaning crews, pest control, snow removal, security guards, movers. All three test questions come back yes.
- Almost always no: pure goods suppliers who ship via a common carrier and never enter your space (an office-supply vendor, a parts distributor), remote-only professional services (a bookkeeper, a virtual assistant, most software subscriptions), and one-off consultants who meet you off-site.
- Judgment call — delivery and light on-site work: a courier who drops a package at the front desk versus one who carries it into a server room; a photographer shooting an empty unit versus one directing furniture moves during a staged shoot. These usually turn on question one — do they cross the threshold into occupied or working space — more than on the nature of the business itself.
- Judgment call — low dollar, short duration: a $150 one-time handyman repair looks low-risk because of the invoice size, but the test doesn't ask about dollars — it asks whether a ladder, a power tool, or a ceiling job is involved. A single afternoon of work on a ladder is exactly the exposure a certificate exists to cover, regardless of what it cost.
Why "we've used them for years" isn't on the test
Trust and tenure answer a different question than risk does, and conflating them is a common reason a real gap gets discovered only after a claim. A landscaper you've used for eight years hasn't gotten less likely to have an accident — if anything, an aging mower or a newer, less experienced crew member raises the odds over time, not lowers them. What changes with tenure is your comfort level, not the vendor's exposure profile.
It's also the vendor's certificate that expires, not your trust in them — a policy that lapsed six weeks ago on a vendor you've worked with since 2019 protects you exactly as much as a lapsed policy on a vendor you met yesterday, which is to say not at all. The certificate of insurance requirements checklist exists specifically because "we know them" is not a line item any checklist should have — the same three-question test applies to your longest-standing vendor as to a new one.
The workers' comp question is separate from the general liability question
A vendor who clears all three general-liability questions might still legitimately not carry workers' compensation — and it's worth knowing the difference before treating a missing work comp line as a red flag. Workers' comp requirements attach to having employees, not to doing risky work. A true sole proprietor with no employees is generally exempt from carrying workers' comp under state law; New Jersey and New York, among others, exempt a solely-owned business with no employees from the requirement outright.
That exemption has real edge cases worth knowing rather than assuming away. California, for instance, has moved toward requiring workers' comp for certain licensed contractor classifications even without employees, though the broader version of that requirement has been reported as pushed back to January 1, 2028. State rules on this shift often enough that a vendor's exemption claim is worth confirming against your state's current rule rather than taking it on faith — this is exactly the kind of state-specific compliance question worth checking with your insurance broker or an attorney rather than treating any single article, including this one, as the final word.
In practice: if a vendor is a genuine one-person operation with no employees or subcontractors, a missing workers' comp certificate usually isn't a document they're withholding — it's a document that may not exist because the law doesn't require them to carry one. General liability is the piece that still applies regardless.
Check what you already signed before you apply your own judgment
The three-question test assumes you're free to set your own bar. Often you're not. Commercial leases commonly obligate the tenant to require insurance from "any contractor or vendor performing work in the premises," full stop, with no risk-based carve-out — because the landlord's own insurer wrote that language to protect the building, not to match your assessment of a specific painter's risk. Franchise agreements frequently do the same for any vendor touching a franchised location. HOA master policies and management agreements often name a required floor for "any vendor working on common areas" regardless of job size.
None of this shows up when you're reasoning from the vendor's side of the transaction — which is why the first real step, before running the three-question test on a borderline vendor, is checking whether your lease, franchise agreement, master insurance policy, or HOA governing documents already answer the question for you. If one of them says "every vendor," that clause controls, and the risk-based test becomes irrelevant for anything it covers. University risk-management offices — Wisconsin, Auburn, and CSUSB among others — formalize this exact structure for their own campuses: a standard floor that applies to essentially all vendors, with named higher tiers layered on top for specific higher-risk categories such as transportation, custodial and pest control, or IT and data-handling engagements. A property manager or GC without a risk office can borrow the same two-layer shape: one policy-driven floor set by whatever you've already signed, and judgment above it for everything the floor doesn't reach.
What skipping a COI on a low-risk vendor actually costs you if it goes wrong
For vendors that genuinely clear the low-risk bar, skipping the certificate doesn't leave you fully exposed — your own commercial general liability or business owner's policy responds to a claim regardless of whether the vendor had coverage. What you lose is the ability to push that claim, or the cost of defending it, onto the vendor's insurer instead of your own. That shows up as your deductible, your claims history, and potentially your renewal premium absorbing a loss that a vendor's certificate could have redirected, even for a vendor everyone agreed was low-risk going in.
It's worth being precise about what a certificate actually buys you here, because certificate holder status alone buys almost nothing: being listed as certificate holder only means you're notified the policy exists, not that you're covered by it. The protection that actually redirects a claim is additional insured status, which has to be requested and endorsed onto the vendor's policy specifically — a certificate without that endorsement is evidence a policy exists, not a shield. For what a genuinely uninsured or underinsured vendor can cost you when something does go wrong, see what happens if a subcontractor doesn't have insurance.
Remote and software vendors need a different kind of coverage, not none
A vendor who never sets foot on your property and never handles anything physical — a bookkeeper, a marketing consultant, most SaaS tools — genuinely doesn't need general liability, because there's no bodily-injury or property-damage exposure a GL policy responds to. That's not the same as saying they need nothing. Where their exposure lives is in the deliverable itself: bad advice, a coding error, a data breach, a missed deadline with financial consequences. That's what professional liability (errors & omissions) coverage and cyber liability coverage exist for — a different pairing of policies from the general-liability-plus-workers'-comp stack that covers on-site vendors.
If a remote vendor's mistake could genuinely cost you money — a consultant whose advice you'll act on, a developer building something customer-facing — it's reasonable to ask for evidence of that coverage instead of a general liability certificate that wouldn't apply to their actual risk anyway. Asking the wrong vendor for the wrong document is its own failure mode: it trains the requester to think "certificate of insurance" is a universal box to check rather than a specific answer to a specific exposure.
Turning this into a process instead of a case-by-case call every time
Running the three-question test in your head works for the vendor sitting in front of you today. It breaks down at the tenth vendor, and it breaks down completely for whoever inherits vendor onboarding after you've moved to a bigger portfolio and stopped doing it yourself. The fix is writing the test down once, as a short onboarding rule rather than a judgment call each time, so "does this vendor need a COI" has the same answer regardless of who's asking or how busy they are that week.
That's the same problem this site's certificate of insurance requirements checklist and how to track certificates of insurance are built to solve on the collection side — once you've decided a vendor needs a certificate, the harder problem is making sure the one you get back is actually compliant and stays that way through renewal. CoverSynx exists for that second half: it doesn't decide which vendors need a certificate — that judgment call is still yours — but once you've made it, it standardizes the request, checks what comes back against your requirements, and flags an expiring policy before it lapses rather than after. It assists verification; it doesn't certify coverage or replace a broker's advice on a specific policy. Property managers and HOAs run this exact judgment call across dozens of vendors a year — both mix true on-site contractor work with vendors who only ever show up in an inbox, which is where the test earns its keep.
Common mistakes
The patterns that turn vendor risk assessment into either wasted effort or a real gap.
- Applying the same requirement to every vendor regardless of risk, which either wastes effort chasing paperwork from a bookkeeper or, more commonly, trains staff to treat the whole exercise as bureaucratic, so a genuinely risky vendor slips through the same rubber stamp.
- Using invoice size or trust as a proxy for risk instead of the vendor's actual exposure — a $150 ladder job is not lower-risk than a $5,000 desk-based consulting engagement.
- Not checking whether a lease, franchise agreement, or master insurance policy already sets a blanket requirement that overrides your own risk judgment.
- Treating a missing workers' comp certificate from a true one-person vendor as a red flag rather than checking whether your state exempts them.
- Asking a remote or software vendor for a general liability certificate that doesn't cover their actual exposure, instead of professional liability or cyber coverage.
- Letting the decision reset every time a new person handles vendor onboarding, instead of writing the rule down once and applying it consistently, the way covered in insurance requirements for subcontractors.
FAQ
Do I need a certificate of insurance from a vendor who never comes onto my property?
Usually not for general liability purposes — if a vendor ships goods through a common carrier or does all their work remotely, there's no bodily-injury or property-damage exposure a GL certificate would be evidencing. Check your lease or master agreement first, though; some obligate you to collect a certificate from every vendor regardless of how they interact with your property.
Is it safe to skip a certificate for a low-risk, low-dollar vendor?
If the vendor genuinely clears all three risk questions — no on-site presence, no plausible bodily-injury or property-damage exposure, no vehicle or equipment use — skipping is defensible. Your own general liability policy still responds if something goes wrong, but you'll absorb the claim through your deductible and renewal rather than redirecting it to the vendor's insurer.
Does a vendor I've worked with for years still need a current certificate?
Yes. Tenure changes your comfort level, not the vendor's risk profile, and it has no effect on whether their policy has lapsed. A certificate from several years ago tells you nothing about coverage today — the same three-question test and the same renewal check apply to a ten-year vendor as to a new one.
What insurance should I ask a remote or software vendor for instead of a COI?
General liability doesn't cover a remote vendor's actual exposure. If their work involves advice you'll act on, code you'll rely on, or data they'll handle, ask about professional liability (errors & omissions) and cyber liability coverage instead — those respond to the kind of mistake a desk-based vendor could actually make.
Do all vendors need workers' compensation coverage too?
No. Workers' comp requirements attach to having employees, not to doing risky work. A true sole proprietor with no employees is exempt from carrying it in many states, though the exemption rules vary and are shifting in some — California has moved toward requiring it for certain contractor license classes. Confirm against your state's current rule rather than assuming a missing certificate means a vendor is uninsured.
Can my lease or franchise agreement require certificates from vendors I'd otherwise consider low-risk?
Yes, and it's common. Commercial leases and franchise agreements frequently require a certificate from any vendor performing work on the premises, with no risk-based exception. That clause overrides your own judgment for anything it covers, so check your governing documents before applying a risk-based test to a vendor working in a leased or franchised space.
What's the actual cost of asking a vendor for a certificate of insurance?
Nothing to the requester, and typically nothing to the vendor either — the certificate is issued directly by the vendor's insurance broker at no charge, since it's a standard service already included with a commercial policy. The cost isn't in asking; it's in tracking what comes back and catching it before it lapses.
About the author
Rehan Shah — Founder, CoverSynx
I build CoverSynx, software that helps property managers and contractors keep track of their vendors' certificates of insurance. I'm not an insurance broker or a lawyer. These guides summarise published industry guidance and cite their sources — for advice on your own situation, speak to your broker.
Stop tracking certificates in spreadsheets. CoverSynx collects vendor COIs, reads each one automatically, checks it against your requirements, and chases the vendor before a policy lapses.
Start free — no card required →