Vendor Insurance Tracking: How to Stop Letting Expired COIs Onto Your Jobsite
The practical system for vendor insurance compliance is a document record per vendor, expiration dates tracked against those records, automatic 30-day renewal notices so chasing certificates is nobody's job, and an admin dashboard that surfaces non-compliance before it ends up on your jobsite — not after.
Most home builders have a spreadsheet. There is a column for the expiration date, someone updates it when they remember to, and the discovery that a certificate lapsed happens one of two ways: a random audit, or an incident. Neither is a good discovery mechanism for something that determines who is liable when a framer falls off a roof.
Why is COI tracking a risk problem, not a paperwork problem?
A certificate of insurance is proof that the subcontractor carries their own coverage. When that coverage lapses and the vendor is still on your lot, the liability transfer breaks down — and depending on jurisdiction and contract language, you can find yourself exposed for an injury that should have been the sub's carrier's problem. The paperwork is the mechanism of risk transfer, not an administrative nicety.
This is why the tracking system has to be proactive. A 30-day warning is enough lead time for a vendor to get a renewal issued and uploaded. A same-day discovery that the COI expired three months ago is not — the work has already happened, and the exposure has already run.
What documents does a working compliance system actually track?
Vendor compliance document types
General Liability COI
Coverage dates tracked, 30-day expiration notice sent automatically
Workers Comp Certificate
Per-trade requirements configurable — toggle on or off per account
W-9 / 1099 documentation
Collected at onboarding so year-end 1099 prep doesn't become an emergency
Signed Scope of Work
Uploaded by the vendor through the no-login portal before work begins
Requirements are configurable per account. A landscaping vendor may not need a separate Workers Comp certificate in your state; a framing crew absolutely does. Forcing a uniform checklist onto every trade creates compliance friction that doesn't actually improve coverage — it just generates pushback from the vendors who get asked for documents that don't apply to them.
How to collect documents at vendor onboarding (before the work starts)
The right time to collect compliance documents is at onboarding — before a vendor is ever assigned to a lot. A vendor registration form collects the GL COI, Workers Comp, W-9, and signed scope of work in one submission through the vendor portal — no Cornerstone login required for the vendor, just a link. That pattern — outside parties accessing a function without needing an account — is how the rest of Cornerstone handles vendor interactions too. Subs submit bids the same way and check in on lots the same way.
Collecting at onboarding means the documents arrive before the trade does, not after an incident surfaces that nobody has a record of the coverage period.
How to set up automated COI expiration tracking
Collect documents at vendor onboarding
Send the vendor registration form before their first assignment. The vendor uploads GL COI, WC certificate, W-9, and signed SOW through the no-login portal.
Configure required document types per account
Toggle SOW, W-9, General Liability, and Workers Comp requirements on or off. Requirements that don't apply to a trade type don't add friction.
Record expiration dates against each vendor
Store the COI expiration date in the vendor record. The dashboard surfaces expiring and expired vendors automatically from there — no manual checking needed.
30-day automated notifications go out to vendors
Cornerstone sends expiration notices to the vendor 30 days before the certificate lapses. The vendor clicks the link in the email and uploads the renewal through the portal — same no-login flow.
Admin dashboard flags expiring and expired vendors
Warning banners and KPI cards show how many vendors are expiring within 30 days and how many have already lapsed. Overdue tasks and expiring insurance surface in the same view.
Don't assign non-compliant vendors to active schedules
Check the compliance status before scheduling a vendor. A lapsed COI is a hold flag — the vendor should not be on an active lot until documentation is current.
What does the admin dashboard actually show?
Vendor compliance dashboard — KPI summary
3
Expiring within 30 days
1
Currently expired
14
COIs current
Expiring and expired vendors surface in the same view as overdue tasks — so compliance and scheduling stay in one picture.
The point of the dashboard is that it gives you the compliance picture before you make scheduling decisions, not after. When a vendor flagged as expiring shows up in the same view as their upcoming task assignments, the connection between non-compliance and active work is explicit rather than buried in a separate spreadsheet.
Why automated renewal notices matter more than reminders to your team
The failure mode for spreadsheet-based COI tracking is always the same: someone is responsible for checking the sheet, and that person is also managing a schedule, approving POs, and answering vendor calls. The sheet check gets deprioritized until it doesn't happen.
Automated 30-day notices shift that responsibility to the vendor — who has far more motivation to keep their own coverage current than any builder's office manager does. The vendor gets an email, clicks the link, and uploads the renewed certificate. Your admin sees the update in the dashboard. Nobody on your team made a phone call.
This connects to a broader pattern in how production home builder software should handle outside parties: minimize friction for people who don't have accounts in your system. Vendors submit bids without logging in, check in on lots with a QR code, and upload compliance documents through a link. The burden of maintaining compliance lands on the party who owns the compliance obligation, not the party doing the administrative coordination.
Does this connect to the rest of the build pipeline?
Vendor compliance in Cornerstone is not a standalone module bolted on from the outside. The vendor record that holds the COI expiration date is the same record that drives bid awards, PO generation, and task assignments. When a trade's coverage is flagged as non-compliant, that signal is visible in the same vendor profile you use to award bids and assign work — not in a separate compliance system that nobody opens.
The same vendor portal where subs upload renewal certificates is where they submit bids, view POs, and access scope of work documents. That means your vendors already have the muscle memory for using the portal, because they interact with it in the normal course of the job — not just when a renewal notice arrives.
Compliance that runs itself — no spreadsheet, no chase.
Cornerstone tracks COI expiration dates, sends 30-day renewal notices to vendors automatically, and surfaces non-compliant trades in the admin dashboard before they're assigned to a lot.
Request Early Access