2026-08-27 · Aervik Labs
Why manual certificate-of-insurance review misses things
A certificate of insurance has to be checked against several separate details at once. Here's what a real ACORD 25 review requires, and why doing it by hand at volume is error-prone.
Every general contractor, property manager, and franchisor deals with the same recurring document: a subcontractor, vendor, or tenant submits a Certificate of Liability Insurance — almost always on the industry-standard ACORD 25 form — and someone has to check it against what the actual contract requires before granting site access, signing off on a vendor, or renewing a lease.
What actually has to be checked
A single ACORD 25 packs several independent facts onto one page, and a real compliance check has to verify all of them, not just glance at whether a certificate exists:
- Named insured — does the certificate actually name the correct party (the vendor or subcontractor you’re contracting with, not a parent company or an unrelated entity)?
- Coverage limits — does each relevant coverage section (general liability, workers’ comp, auto, umbrella/excess) meet or exceed the minimum your contract specifies, per occurrence and in aggregate?
- Additional-insured status — is the certificate holder (you) actually listed as an additional insured on the policy, not merely the party the certificate was sent to? These are not the same thing, and it’s a common point of confusion.
- Waiver of subrogation — has the insurer waived its right to pursue your organization after paying a claim, if your contract requires it?
- Policy effective and expiration dates — is the certificate current as of today, and does it stay current through the duration of the work or lease term?
Any one of these being wrong or missing can mean an uninsured loss lands on the general contractor or property owner instead of the vendor who was supposed to be covered.
A detail printed on every real ACORD 25
It’s worth knowing that a real ACORD 25 form itself carries a standard disclaimer stating the certificate “is issued as a matter of information only and confers no rights upon the certificate holder” and “does not affirmatively or negatively amend, extend or alter the coverage afforded” by the underlying policies. In plain terms: the certificate is a summary, not the policy itself, and additional-insured status or a subrogation waiver only actually applies if the underlying policy or its endorsements say so — the certificate is evidence of that, not the source of it. A reviewer who only reads the certificate’s box for “additional insured: yes/no” without understanding this distinction can miss that the actual endorsement isn’t attached or doesn’t match.
Why this is error-prone at volume, done by hand
Checking a single certificate against a set of requirements this way typically takes somewhere in the range of 15 to 45 minutes when done manually — cross-referencing several coverage sections, limits, dates, and endorsement details against a separate requirements document. That’s manageable for one certificate. It stops being manageable for a general contractor running dozens of active subcontractors, or a property manager or franchisor tracking hundreds of vendor or tenant certificates that each need to be re-verified at renewal. The failure mode isn’t usually a reviewer who doesn’t know what to check — it’s volume and repetition wearing down a manual process until something gets missed: an expired policy that renews after the certificate was last checked, a limit that’s technically below the contract’s minimum, an additional-insured box left unchecked.
How Aervik Labs’ COI Verification API handles this
The COI / ACORD 25 Verification API separates the two steps deliberately: extraction reads the document (named insured, insurers, every coverage section’s limits and dates, additional-insured and subrogation-waived flags) and returns a confidence score, since reading a scanned, faxed, or photographed document is never perfect. The compliant/deficient verdict itself runs through a fixed, deterministic rules engine over those extracted fields — never an AI judgment call — so the same requirements and the same extracted data always produce the same verdict, with an itemized list of exactly what’s missing rather than a bare pass/fail.
This is advisory only, not a substitute for professional review. A “compliant” result is not a guarantee that the underlying policy is valid, in force, or will respond to a real claim — always check the confidence score, and treat a low-confidence extraction as a signal to review the original document directly.
