Written and maintained by CASRAI Editorial Board
Last updated
A certificate of insurance (COI) is the document a vendor’s insurance broker issues to prove the vendor carries active coverage — it is not the policy itself, and it does not by itself guarantee that coverage stays in force or applies to your purchase. Requesting one is standard practice before onboarding a new medical-supply vendor, but a COI only protects you if someone actually reads what it says. This guide covers what the document shows, the specific gaps and red flags to check for a medical-supply vendor, and how it fits into a broader vendor-onboarding process.
What a Certificate of Insurance Actually Shows
Most COIs in the United States are issued on a standard industry form — ACORD 25, published by ACORD (a nonprofit standards body for the insurance industry) — which is why certificates from different vendors and different brokers tend to look similar. The form is a snapshot, prepared by the broker or agent at a point in time, summarizing what the named insured’s policies cover. It is evidence that a policy existed when the certificate was issued, not a warranty that it will still be in force when you actually need it, and not itself a contract between you and the insurer.
A COI for a vendor typically lists several distinct coverage lines, each with its own limits:
- Commercial general liability (CGL). Covers third-party bodily injury and property damage arising from the vendor’s operations — for example, a delivery driver damaging your loading dock. Shown as an “each occurrence” limit and a separate, higher “general aggregate” limit that caps total payouts across the policy period.
- Products & completed operations. This is the line that actually matters for a supplier of physical medical products, and it is easy to miss because it is sometimes folded into the CGL aggregate and sometimes broken out as its own sub-limit. It responds to injury or damage caused by a product after it has left the vendor’s control — the scenario you actually care about with a supply vendor, as distinct from the vendor’s own premises or operations exposure that base CGL is built around.
- Automobile liability. Relevant if the vendor delivers product with its own vehicles rather than a third-party carrier.
- Umbrella or excess liability. Additional limits sitting on top of the underlying CGL/auto policies once those are exhausted.
- Workers’ compensation and employer’s liability. Protects against claims if the vendor’s own employee is injured while on your premises for delivery, installation, or service.
The certificate also names a certificate holder (the entity requesting the document — you) and, separately, may or may not name your institution as an additional insured. These are not the same thing, and the difference is one of the most consequential things to check.
Certificate Holder vs. Additional Insured
Being listed as certificate holder means the vendor’s broker will send you a copy of the certificate. It does not extend any of the vendor’s coverage to you. Being named as an additional insured is a substantive endorsement to the vendor’s actual policy that extends liability protection to your institution for claims arising out of the vendor’s work or products — meaning if a claim names both the vendor and your institution, the vendor’s insurer has a duty to defend and potentially indemnify you too, not just the vendor.
If your contract or your institution’s procurement policy requires additional-insured status, the certificate needs to show that explicitly — usually as a checked box plus a reference to an attached endorsement form (commonly CG 20 10, CG 20 26, or a similar ISO endorsement number for CGL policies). A certificate that lists your institution only as certificate holder, with no additional-insured endorsement referenced, does not satisfy that requirement even though it looks similar at a glance.
Red Flags to Check Before You Accept a Certificate
| What to check | Why it matters |
|---|---|
| Policy expiration dates | A COI is only proof of coverage through its listed expiration date. An expired or soon-to-expire policy period means you have no evidence of coverage going forward — request a renewed certificate before the old one lapses, not after. |
| Coverage limits below your institution’s requirement | Compare the “each occurrence” and “aggregate” figures against whatever minimum your procurement or risk-management policy sets, not against a generic industry figure. A commonly seen baseline in commercial contracts is $1,000,000 per occurrence / $2,000,000 aggregate for general liability, but that is a convention, not a rule — your institution’s actual requirement is the only number that matters, and it may be higher for a vendor supplying products used directly in patient care. |
| Missing or unclear products & completed operations coverage | A vendor can carry a fully compliant-looking CGL policy that excludes or sub-limits products/completed operations. For a company supplying physical medical products, this is the coverage that responds if the product itself causes harm after delivery — confirm it’s present and ask what its limit is, since it is sometimes lower than the base CGL limit rather than identical to it. |
| Additional insured requested but not shown | See above — certificate holder and additional insured are not interchangeable. If your contract requires the latter, look for the endorsement reference, not just your institution’s name in the certificate-holder box. |
| No real cancellation notice to you | Older certificate language sometimes led buyers to assume they would automatically get 30 days’ notice before a vendor’s policy was cancelled. Current ACORD 25 language does not guarantee that — it commits only to notice “in accordance with the policy provisions.” Don’t rely on the certificate itself to warn you of a lapse; build a renewal check into your own vendor-file review cadence instead. |
| Certificate you can’t independently verify | Certificates are sometimes altered or issued by an agent without authority to bind the stated coverage. For a new or higher-risk vendor, it’s reasonable to call the broker or insurer using contact information you look up independently — not a phone number printed only on the certificate itself — to confirm the policy is active as described. |
| Wrong legal entity named | Confirm both that the named insured on the certificate matches the vendor entity you’re actually contracting with (not an affiliate or subsidiary with a similar name) and that your own institution’s legal name is correct in the certificate-holder and additional-insured fields. |
Where This Fits in Vendor Onboarding
A certificate of insurance is one document in a larger onboarding packet, not a standalone gate. It sits alongside the broader set of documentation purchasing and materials-management staff typically collect before a new vendor goes live in the accounting system — see Vendor Onboarding for Medical Supply Purchases: What Documentation to Request for the full checklist and why each item exists. Insurance verification addresses a specific risk in that checklist (uninsured liability), distinct from what trade references verify (payment reliability and account behavior — see Trade References in Vendor Qualification) or what quality-system credentials like ISO 13485 verify (manufacturing/distribution quality controls, not financial protection if something goes wrong).
Practically, the certificate is worth re-checking at renewal, not just at onboarding. Set a reminder tied to the policy expiration date on file so a vendor doesn’t quietly lapse into uninsured status a year into the relationship.
Frequently Asked Questions
Is a certificate of insurance legally binding?
No. Most ACORD 25 certificates include disclaimer language stating explicitly that the certificate confers no rights on the certificate holder and does not amend, extend, or alter the coverage the listed policies actually provide. It is evidence of coverage at the time of issuance, not a contract.
How often should we request an updated certificate?
At minimum, before the listed policy period expires, since a certificate is only proof of coverage through its stated expiration date. Many institutions build this into an annual vendor-file review rather than tracking each vendor’s renewal date individually.
Does general liability coverage automatically include product liability?
Not necessarily, and this is the single most common gap for a product supplier specifically. Confirm the products & completed operations line is present and check its limit separately — it can be lower than, or excluded from, the base general liability limit depending on the policy.
What’s the difference between being a certificate holder and an additional insured?
Certificate holder means you’re on the mailing list for the document. Additional insured is an actual endorsement to the vendor’s policy that extends liability protection to your institution. If your contract requires the latter, confirm the endorsement is referenced on the certificate, not just your institution’s name in the certificate-holder field.








