I'm an electrical contractor, and the scariest gap in most contracting businesses isn't on the job — it's in a filing cabinet. It's the subcontractor certificate of insurance that quietly expired three months ago while the sub kept showing up and working. Nothing happens... until something happens. Then you find out, in the worst possible way, whose policy is on the hook.
What a COI is, and why expiry is the whole game
A certificate of insurance (COI) is the sub's proof that they carry coverage — typically general liability, workers' comp, and auto. When a sub is properly insured and something goes wrong on their scope, their policy responds. When their coverage has lapsed, the claim goes looking for the next policy up the chain — and that's yours. An uninsured sub doesn't just expose the sub. It quietly converts their risk into your risk, and your premiums (or your bank account) wear it.
An expired COI doesn't fail loudly. It sits there looking fine until a claim turns it into your problem.
The spreadsheet trap
Almost everyone tracks this the same way: a spreadsheet with sub names and expiry dates that somebody is supposed to check. The problem is the word "supposed to." That spreadsheet is current the day it's made and stale a month later. Nobody owns it, nobody's reminded by it, and the one time it matters, the date that needed flagging was buried on row 34 between two jobs and a vacation. Manual tracking doesn't fail because people are careless. It fails because it relies on a human remembering to look at the exact right moment, every time, forever.
What you actually need to track
For every sub you put on a job, at minimum:
- Expiry dates for each policy (GL, workers' comp, auto) — they don't all expire on the same day.
- Coverage limits — that they meet what your contract and the GC require.
- Additional insured status — that you're actually named where you're supposed to be.
- The certificate itself — the PDF, on file, so you can produce it when the GC or your own carrier asks.
Automate the warning, not just the storage
Storing the COI is table stakes. The thing that actually protects you is the warning — the system flagging "this sub's GL expires in 30 days" and "this sub's coverage lapsed, do not let them on site" without anyone having to go look. When the expiry date lives next to the subcontractor's record and the system surfaces it on its own, the lapse stops being something you discover after a claim and becomes something you handle on a Tuesday with a quick email: "Hey, send me your renewed cert before Thursday."
The one-minute version
- An expired sub COI pushes their risk onto your policy — silently, until a claim.
- Spreadsheets go stale because they rely on someone remembering to look.
- Track expiry dates, limits, additional-insured status, and the cert itself.
- Automate the warning so a lapse is a Tuesday email, not a courtroom.