Last updated

How to Spot a Fake or Expired Certificate of Insurance

A certificate of insurance (COI) is only as good as the coverage behind it. Every day, general contractors collect COIs from subcontractors and file them away as proof that the risk has been handled. But a certificate is a summary document, not the policy itself — and a subcontractor who wants to win your job has every incentive to make that summary look better than reality. Some alter numbers. Some send a certificate for a policy that lapsed months ago. A few forge the whole thing.

When a claim hits and the coverage isn't there, the exposure can land on you. Knowing how to spot a fake or expired certificate of insurance is one of the highest-leverage habits a GC can build.

Why Bad Certificates Slip Through

Most fraudulent or expired COIs don't get caught because nobody is really reading them. A certificate arrives by email attached to a dozen other onboarding documents, someone glances at it, confirms it exists, and moves the sub onto the site. The document did its job as a checkbox, not as verification.

Expired certificates are the most common problem, and usually the least malicious. A sub had valid coverage when they first bid the job, the policy renewed (or didn't), and nobody circled back to collect an updated certificate. Coverage that was real in March can be gone by September, but the PDF in your files still shows the old dates. If you're only checking that a certificate exists rather than tracking when each one expires, gaps are inevitable.

Forgeries are less common but more dangerous. Because a COI is generated on a standard industry form, the layout is easy to imitate. Someone with basic PDF editing skills can change a coverage limit, extend an expiration date, or paste in an additional insured endorsement that was never actually issued. The document looks legitimate at a glance because the format is legitimate — only the contents are false.

Red Flags on the Certificate Itself

Before you verify anything externally, read the document closely. Several warning signs are visible on the face of the certificate:

  • Mismatched or inconsistent fonts. Altered fields often use a slightly different typeface, size, or alignment than the surrounding text. Dates and dollar amounts are the most commonly edited fields — look there first.
  • The policy dates are expired or oddly narrow. Check that the effective and expiration dates actually cover your project timeline. A certificate that expires next week, or one issued for an unusually short term, deserves a second look.
  • No producer or agent contact information. A legitimate certificate is issued by an insurance agency (the "producer") and lists their name, phone, and address. A missing or vague producer is a serious red flag.
  • Blank or generic certificate holder. If the "certificate holder" box is blank, addressed "To Whom It May Concern," or names a different company, the sub may be recycling one certificate across every job.
  • Missing additional insured or waiver of subrogation language. If your contract requires you to be named as an additional insured, confirm the certificate says so — and remember that the box being checked is not the same as the endorsement being issued.
  • Signs of digital editing. Fuzzy text, misaligned rows, faint outlines around numbers, or a scanned-then-flattened image that hides edits can all indicate tampering.
  • Coverage limits that look too clean. Round numbers aren't proof of anything, but limits that exactly match your requirements down to the dollar — on a sub whose size doesn't fit that coverage — are worth confirming.

Reading the certificate carefully catches sloppy fakes and obvious expirations. It will not catch a well-made forgery. For that, you have to go past the paper.

Verify Authenticity With the Carrier

The single most reliable way to confirm a certificate is real is to contact the source — not the subcontractor, and not the phone number printed on the certificate, which a forger could have altered. Independently confirm coverage through the issuing agent or carrier.

Follow these steps:

  1. Identify the producer independently. Note the agency named on the certificate, then look up their contact information separately rather than trusting the number on the document.
  2. Call the issuing agent or carrier directly. Ask them to confirm the policy is active, the effective and expiration dates, and the limits shown on your copy.
  3. Confirm the specific endorsements. If you require additional insured or waiver of subrogation status, ask whether those endorsements were actually issued for your project. Request copies of the endorsement forms, not just verbal confirmation.
  4. Match the details to your contract. Compare coverage types and limits against what your subcontract agreement requires. A real certificate with insufficient coverage is still a problem.
  5. Document the verification. Record who you spoke with, the date, and what they confirmed. If a dispute arises later, a paper trail matters.
  6. Re-verify at renewal. Coverage confirmed today can lapse tomorrow. Set a reminder tied to the expiration date so you collect an updated certificate before the current one runs out.

This is general information, not legal or insurance advice. Your contracts, state, and insurance requirements determine what you actually need — when in doubt, involve your broker or attorney.

Build a Repeatable Verification Routine

Catching one fake certificate is luck. Catching them consistently is a system. The GCs who avoid coverage gaps treat COIs as living records, not one-time paperwork:

  • Track every expiration date, not just whether a certificate exists. The moment a policy lapses, the sub should be flagged and blocked from new work until an updated certificate arrives.
  • Standardize your requirements so every sub is measured against the same coverage types, limits, and endorsements. Consistency makes outliers easy to spot.
  • Keep the endorsement documents, not just the certificate. The certificate summarizes; the endorsement is the actual grant of coverage.
  • Automate the follow-up. Manual tracking across spreadsheets is where expirations hide. Purpose-built COI tracking software can store each certificate, flag approaching expirations, and keep the verification trail in one place — so a lapsed policy surfaces before the sub is back on your site.

The goal isn't to treat every subcontractor as a suspect. It's to make verification routine enough that a forged limit or a quietly expired policy can't slip past you unnoticed. A few minutes of scrutiny — reading the certificate, confirming with the carrier, and tracking the dates — protects you from exposure that can dwarf the cost of the diligence.

If you'd like an easier way to keep certificates current and expirations from slipping through, you can try TradeGuard free for 14 days at trade-guard.pro/signup. It handles the tracking so you can focus on the build.

Let TradeGuard track it for you

Every subcontractor's COI, license, and OSHA docs, tracked automatically, with alerts before anything expires. Free 14-day trial, no credit card.

See how COI tracking works

More guides