COI Compliance Checklist for Property Managers & HOAs
The CertifiKit team
Certificate-of-insurance desk
Vendor COI compliance for a property manager or HOA comes down to four habits: set written requirements per vendor type, verify every certificate before work starts, re-verify at every renewal, and keep the trail. Here's the whole program as a checklist you can hand to whoever opens the mail.
Step 1 — Set requirements per vendor type (once)
Don't negotiate per vendor; publish a standard. A sensible baseline for property/HOA vendors:
| Vendor type | GL | Workers' comp | Extras |
|---|---|---|---|
| Landscaping, cleaning, general maintenance | $1M / $2M | Statutory + $500K | Additional insured |
| Trades (plumbing, electrical, HVAC) | $1M / $2M | Statutory + $1M | Additional insured + waiver of subrogation |
| Roofing, tree work, anything at height | $2M / $4M (or umbrella) | Statutory + $1M | Both endorsements + primary & non-contributory |
Put the requirement in the vendor agreement as a condition of payment. (The full reasoning behind each line is in our subcontractor requirements guide — the logic is the same for property vendors.)
Step 2 — Verify before the first job (every vendor)
For each certificate received, check:
- Named insured exactly matches the vendor entity you contracted
- Certificate holder is your association / management entity, correct address
- GL limits meet the table above; aggregate isn't shared across someone else's projects
- Workers' comp line is present — uninsured crew injuries become premises claims
- All policy dates current, none expiring within 30 days of scheduled work
- Additional insured endorsement referenced by form number, not just a checkbox
- Certificate is the current ACORD 25 (our field-by-field guide shows where each item lives)
A vendor's certificate failing isn't a crisis — it's an email to their agent with the specific gaps. Specific is the key: "WC employers' liability shows $500K, we require $1M" gets fixed in a day; "please send updated COI" starts a three-week thread.
Step 3 — Re-verify on a calendar (forever)
This is where programs die. Policies renew annually, scattered across the year:
- Log every expiration date the day a certificate arrives
- Request renewals 30 days out; escalate at 14 and 7
- Treat an expired certificate as a stop-work condition — communicated in advance, enforced without drama
- Spot-check one certificate a month against the actual requirements (drift is real)
Step 4 — Keep the trail
Boards change, managers change, claims arrive years later (completed-operations claims especially). Keep:
- Every certificate version, datestamped
- What was checked and the result
- The fix-request emails and what came back
When counsel asks "did the association verify the roofer's coverage in 2024?", a folder of dated verdicts is the difference between a nuisance and a problem.
The honest-effort math
Forty vendors ≈ a renewal every nine days, each with verification, a chase thread, and filing. Done by hand it's a real part-time job — which is why it usually degrades into "we have a COI on file" without anyone knowing if it's any good.
Two ways to make it sustainable: run the program on a disciplined spreadsheet if your vendor count is small — or let CertifiKit do steps 2–4 automatically: certificates verified in 60 seconds, fix lists emailed to agents, expirations chased at 30/14/7 days, audit trail kept. Test it with one vendor's certificate in the free checker — no account, takes a minute.