CoverSynx

How to Spot a Fake Certificate of Insurance (2026 Verification Guide)

By Rehan ShahFounder, CoverSynx12 min read

A forged COI takes five minutes to make and can leave you uninsured. Here are the red flags, the verification steps that actually confirm coverage, and what to do when a certificate doesn't hold up.

Why fake certificates of insurance exist

A certificate of insurance is the document you rely on to prove a vendor is covered. It is also, unhelpfully, one of the easiest business documents in the world to fake. The ACORD 25 form is publicly available, and anyone with a PDF editor can change a name, a limit, or an expiration date in a couple of minutes.

The motive is obvious. Commercial general liability and workers' compensation are expensive, and a contractor who cannot afford coverage — or who let it lapse last month — still wants the job. Handing over a doctored PDF is the path of least resistance, and most of the time nobody checks.

The consequence lands on you, not on them. If an uninsured vendor causes injury or property damage on your site, the claim looks for the nearest solvent party. That is usually the business that hired them, which is the same exposure covered in our guide to the real cost of a lapsed vendor policy.

One honest note before the tactics: you will see confident-sounding statistics about what share of certificates are forged. We have not found a credible source for that number, so we are not going to invent one. What is well documented is the scale of insurance fraud overall — the Coalition Against Insurance Fraud puts the total cost at roughly $308 billion a year in the United States, and the FBI estimates non-health insurance fraud alone exceeds $40 billion annually. Certificate fraud is a small, poorly-measured slice of that, but it is a slice that lands directly on the business that accepted the document.

The two failure modes: forged, and real but useless

Most articles on this topic only address forgery. In practice, the second failure mode is far more common and costs businesses more money, because it passes every visual inspection.

A forged certificate is a document that was altered or fabricated. A real-but-useless certificate is entirely genuine — issued by a licensed producer, accurate on the day it was written — and still fails to protect you. It expired six weeks ago. It names a different legal entity. It lists your company as certificate holder but never added you as an additional insured, so you have proof that someone else is covered.

Both leave you uninsured. Only one of them involves anybody lying. If you build a verification process that only hunts for fraud, you will catch the rare forgery and wave through the common failure — so check for both, every time.

  • Forged: altered limits, edited dates, fabricated producer details, or a self-issued document.
  • Expired: genuine when issued, out of force now. By far the most frequent problem.
  • Wrong entity: the named insured is a related company, a trading name, or an individual rather than the contracting entity.
  • Missing endorsements: no additional insured, no waiver of subrogation, no primary and non-contributory wording.
  • Insufficient limits: real coverage, below what your contract requires.

Red flags on the document itself

Start with the certificate in front of you. None of these is proof of fraud on its own, but each is a reason to verify before accepting.

The single most telling signal is who sent it. A certificate of insurance is issued by a licensed producer — an agent or broker — on behalf of the carrier. A vendor cannot legally issue their own. If the PDF arrived attached to the vendor's email with no producer involved anywhere, that alone justifies a call to the agency named on the form.

  • No ACORD form identifier. A genuine US liability certificate is an ACORD 25; the form number appears in the bottom corner. See our ACORD 25 glossary entry for what the form contains.
  • Missing producer block. The agency name, address, and contact should be filled in and should be a real, findable firm.
  • Blank or vague insurer. Carriers are named in the 'Insurer(s) Affording Coverage' rows along with NAIC numbers. Blank NAIC codes are a red flag.
  • Typography that changes mid-document. Mismatched fonts, misaligned rows, or a number that sits slightly off the baseline are classic signs of PDF editing.
  • Flattened or photographed image. A certificate re-scanned or photographed for no obvious reason may be hiding edit artifacts.
  • Round-number limits that exactly match your contract. Convenient precision is worth a second look — genuine policies rarely match a requirement to the dollar by coincidence.
  • Your company misspelled in the certificate holder box. Real producers copy the holder details from a request; sloppiness here often means the document was edited by hand.
  • Dates that don't hang together — an issue date after the effective date, or a policy period that happens to end exactly at project completion.

The verification workflow that actually confirms coverage

Reading the document tells you whether it looks right. Only these steps tell you whether the coverage exists. Work through them in order; each one is cheap, and you can stop as soon as something fails.

  • 1. Require source-only submission. Ask the vendor to have their broker send the certificate directly to you. This single policy change eliminates most forgery, because the document never passes through the vendor's hands.
  • 2. Confirm the producer is licensed. Look up the agency or agent in your state's Department of Insurance database, or the National Insurance Producer Registry. An unlicensed or non-existent producer is decisive.
  • 3. Call the producer using a number you looked up yourself. Never use the phone number printed on the certificate — on a forged document, that number reaches the forger. Find the agency independently and call that.
  • 4. Ask the producer to confirm four things: the named insured, the policy number, the policy period, and whether the endorsements you require are actually attached.
  • 5. Verify the endorsements by form number, not by checkbox. A tick in the 'additional insured' column is a claim, not evidence. Ask for the endorsement itself.
  • 6. Diarize the expiration date and re-verify at renewal. A certificate is a snapshot of one day. Coverage can be cancelled mid-term without anyone telling you.

Where fakes and gaps hide: the endorsements

If someone is going to alter a certificate, the endorsement boxes are the easiest place to do it and the hardest place for you to catch it. Ticking a box takes one keystroke; the underlying endorsement either exists on the policy or it does not.

This is also where honest certificates fail. A producer may accurately record that no additional insured endorsement was requested, and the certificate is completely truthful — it just doesn't give you the protection you assumed you had.

The distinction between being a certificate holder and being an additional insured is the one that catches most people out, and it is worth understanding properly. We cover it in detail in additional insured vs. certificate holder.

  • Additional insured — commonly ISO forms CG 20 10 (ongoing operations) and CG 20 37 (completed operations). Ask which form is attached; 'yes' is not an answer. See additional insured.
  • Waiver of subrogation — stops the vendor's insurer pursuing you after paying a claim. See waiver of subrogation.
  • Primary and non-contributory — decides whose policy pays first. Without it, your own insurer may end up sharing the loss. See primary and non-contributory.
  • Being listed as certificate holder only means a copy was sent to you. It confers no coverage whatsoever.

What to do when a certificate doesn't hold up

Separate the two cases before you act, because the right response is very different.

If the certificate is simply out of date or missing an endorsement, this is an administrative problem. Tell the vendor precisely what is missing, ask their broker to issue a corrected certificate, and hold the work until it arrives. Most vendors fix it the same day.

If you believe the document was deliberately altered, treat it as a contractual and legal matter. Stop the vendor working immediately — every hour they remain on site is uninsured exposure sitting on your balance sheet. Preserve the original file and the email it arrived in. Notify your own broker or risk manager, and check what your contract permits regarding suspension or termination.

Forging a certificate of insurance is a criminal offense in most US states, frequently charged as felony forgery or insurance fraud, though the specific classification varies by state. You do not need to decide the legal question yourself. Document what you have, escalate it, and take advice.

Doing this across sixty vendors without a full-time person

Everything above is straightforward for one certificate. The difficulty is that a mid-sized property manager or general contractor is holding dozens or hundreds of them, each expiring on its own date, each needing the same checks again at renewal.

This is where manual processes quietly fail. Not because anyone is careless, but because the work is unbounded and invisible until something goes wrong. A spreadsheet records what you typed into it; it cannot tell you that a policy was cancelled in March, and it will not chase anybody. We look at where that breaks down in COI tracking in spreadsheets.

What scales is separating the two halves of the job. Extraction and expiry monitoring are mechanical and should be automated. Authenticity judgment — the producer call, the endorsement request, the decision to stop a vendor working — is human work that benefits from being surfaced early rather than discovered late.

Software should tell you which certificates need a human look and chase the routine renewals on its own. That is deliberately how CoverSynx is built: it reads each certificate, checks it against your requirements, flags what is missing, and emails the vendor before a policy lapses. It assists verification; it does not certify coverage, and it is not a substitute for the producer call on anything that looks wrong.

Common mistakes

These are the errors that show up again and again in real compliance files.

  • Calling the phone number printed on the certificate. On a forged document it reaches the person who forged it.
  • Accepting the certificate from the vendor rather than the broker.
  • Treating certificate holder status as coverage. It is a mailing label, not protection.
  • Filing the certificate and never looking at it again until a claim.
  • Checking limits but not endorsements — the limits are usually the honest part.
  • Accepting a certificate whose named insured is 'close enough' to the contracting entity.
  • Letting work start on the promise that the certificate is coming.
  • Assuming a broker-issued certificate guarantees the policy is still in force today. Mid-term cancellation happens.

A practical policy you can adopt this week

You do not need a risk department to close most of this gap. Three rules do the bulk of the work, and they cost nothing to implement.

First, certificates come from brokers, never from vendors. Put it in the contract and in the onboarding email. Second, no certificate, no site access — and no exceptions for people you have worked with for years, because familiarity is exactly how lapses persist unnoticed. Third, every certificate gets a diarized expiry date and is re-verified at renewal, not merely re-filed.

If you want the full adequacy check to run alongside the authenticity check, our vendor COI requirements checklist covers what to confirm on every certificate, and how to track certificates of insurance covers the collection and renewal process end to end.

FAQ

Can a vendor issue their own certificate of insurance?

No. A certificate of insurance is issued by a licensed producer — an agent or broker — on behalf of the insurer. A document a vendor produced themselves has no standing, and creating one is a criminal offense in most states. If a certificate did not come from a producer, treat it as unverified until you have confirmed it directly with the agency.

How can I check if a certificate of insurance is real?

Call the producer named on the certificate using a phone number you looked up independently — never the number printed on the document — and ask them to confirm the named insured, policy number, policy period, and attached endorsements. You can also confirm the producer holds a valid license through your state's Department of Insurance or the National Insurance Producer Registry.

What is the most common problem with vendor certificates?

Expiration, not forgery. Most certificates that fail to protect a business were completely genuine when issued and simply lapsed without anyone noticing. The second most common problem is a missing additional insured endorsement, which leaves you holding proof that somebody else is covered.

Does being listed as certificate holder mean I'm insured?

No. Certificate holder status only means a copy of the certificate was sent to you. Coverage comes from being named as an additional insured via an endorsement on the policy itself, such as ISO form CG 20 10. Many businesses discover this distinction only when they file a claim.

Is it enough to check the certificate once at onboarding?

No. A certificate reflects the position on the day it was issued. Policies expire, and they can be cancelled mid-term without the certificate holder being notified. Re-verify at every renewal and monitor expiration dates continuously.

What should I do if I think a certificate has been forged?

Stop the vendor working immediately, since any time on site is uninsured exposure. Preserve the original file and the email it arrived in, notify your broker or risk manager, and review what your contract allows regarding suspension or termination. Forging a certificate is generally a criminal matter, but you should take advice rather than make that determination yourself.

About the author

Rehan ShahFounder, CoverSynx

I build CoverSynx, software that helps property managers and contractors keep track of their vendors' certificates of insurance. I'm not an insurance broker or a lawyer. These guides summarise published industry guidance and cite their sources — for advice on your own situation, speak to your broker.

Stop tracking certificates in spreadsheets. CoverSynx collects vendor COIs, reads each one automatically, checks it against your requirements, and chases the vendor before a policy lapses.

Start free — no card required →