To automate COI collection from tenants and vendors, write the requirement per lease and per vendor tier first, trigger requests from four events rather than a calendar alone, send every request to the broker with the exact requirement, read each certificate against the requirement on arrival, and chase deficiencies on an escalating cadence with a day-zero action. No new portal is needed.
Every portal you add is a login someone will forget. Tenants already have a rent portal. Vendors already have a work order app, an invoicing platform, and three other landlords with three other systems. So when the plan for automating certificate of insurance collection begins with "we'll roll out a portal," you have already lost the people you most need to comply: the small HVAC contractor, the restaurant tenant with a part-time bookkeeper, the broker who handles two hundred accounts.
Automation that works meets those people where they already are. Email, mostly. Sometimes a phone call. The system runs underneath; the human on the other end never has to learn it.
Here is the workflow we would set up for a commercial or retail portfolio, in order.
Step 1: Write down the requirement before you request anything
Most collection failures start upstream of collection. A request goes out that says "please send your COI," the vendor sends whatever their broker sent last year, and someone on your team has to decide whether it is acceptable. It is not acceptable, usually, and now the chase begins with the vendor confused about what changed.
Instead, extract the actual requirement for each relationship first:
- Tenants: the insurance clause in the lease. Limits for general liability, property, business interruption if required; additional insured wording; waiver of subrogation; notice of cancellation. Amendments override, so read those too.
- Vendors: the master service agreement or the building's vendor requirements, by trade. A window washer and an electrician do not carry the same coverage.
- Entities: which legal entity must be named as additional insured and certificate holder. Portfolios with a dozen ownership LLCs get this wrong constantly.
Put the requirement in structured form (a checklist per relationship, not a PDF of the lease). Every later step compares against it.
Step 2: When should a certificate be requested?
A calendar reminder 30 days before expiry is the obvious trigger. It is also only one of four moments when a certificate is needed.
- Onboarding. A new tenant signs; a new vendor is approved. Request before the first day on site.
- Expiry. Policy renewal, usually annual. Start 60 days out for tenants, 45 for vendors.
- Change. Lease amendment, scope change on a contract, a new entity in the ownership structure. Re-request with the new requirement.
- Incident. A claim or a near miss. Verify coverage is in force today, not on the last certificate you filed.
Wire each trigger to the request. The change and incident triggers are the ones a spreadsheet never fires, and they are the ones that matter in a dispute.
| Trigger | When the request goes out | Who is asked |
|---|---|---|
| Onboarding | Before the first day on site or the lease commencement | Broker, with the tenant or vendor copied |
| Expiry | 60 days out for tenants, 45 for vendors; reminders converge on 60, 30, and 7 days in most vendor compliance tools | Broker |
| Change | On any amendment, scope change, or new ownership entity | Broker, with the new requirement attached |
| Incident | Same day as a claim or near miss | Broker, for confirmation of coverage in force |
Step 3: Send the request to the broker, with the requirement attached
The tenant does not produce the certificate; their insurance broker does. Ask the tenant once for the broker's contact, store it, and send every subsequent request to the broker with the tenant copied. Include the exact requirement in the request, in the broker's language: limits, endorsement forms, the precise additional insured name, the certificate holder address.
Brokers respond quickly to specific requests and slowly to vague ones. This single change shortens the loop more than any software feature.
Step 4: Read the certificate against the requirement, automatically
When the certificate arrives, a person should not be the first reader. Optical character recognition plus a rules check can confirm the dates, the limits, the named insured, the certificate holder, and the presence of the required endorsements in seconds. AI models are now good at reading the messy ones, including the broker cover letter stapled in front and the handwritten box.
The output is a verdict: compliant, deficient (with the specific gap), or unreadable. Only deficient and unreadable go to a human, and they go with the gap already identified.
Turnaround is where the tools differ most. Jones reports that its COI reviews typically complete in under 24 hours, while vendor comparisons of portal tools cite processing delays of two days to two weeks. A vendor due on site Monday cannot wait for the second kind.
Step 5: Chase deficiencies with a cadence that escalates
A deficient certificate is the normal case, not the exception. The broker named the wrong entity, the umbrella is missing, the waiver endorsement was not attached. The response has to name the gap precisely and go back to the broker within the hour, because brokers work in queues and a same-day reply stays on top of the pile.
Then a cadence: a second message at day 3, a phone call at day 7 for anyone due on site, a message to the tenant's or vendor's principal at day 10, and a hard stop at day 14 for vendors (no compliant certificate, no work order dispatched). We go deeper on the tactics in how property managers actually chase expiring certificates.
Rule of thumb: if a certificate has been "pending" for more than 14 days, the problem is no longer the paperwork. Someone needs to make a decision: grant a documented exception, or stop the relationship until it is fixed. Automation cannot make that call, but it should force it onto someone's desk.
Step 6: store the trail, not only the certificate. Filing the compliant certificate is the last step people think of and the one that pays off years later. What you need in the file is the whole exchange: requirement, request date, every reply, every deficiency notice, the final certificate, and the name of whoever approved any exception. When a claim arrives, the question is never "do you have a certificate." It is "what did you know, and when."
Where does COI automation stall?
Three places, in our experience.
Non-standard leases. Negotiated insurance clauses that no template captures. The fix is Step 1 done properly, lease by lease, once.
The vendor who never replies. Automation can escalate, but at some point a human has to pick up the phone or tell the property manager the vendor is off the approved list. Decide in advance who that human is.
Ownership of the queue. If deficient certificates land in a shared inbox that "someone" watches, they are not watched. The queue needs a name on it, and that name needs a target: median days from deficiency to compliant.
This is also where the question of who runs the process comes in. The workflow above is the same whether your coordinator runs it with software or a managed operator runs it under your policies. Premise runs it as one of its five operations, with AI doing the reading and drafting and its own people making the judgment calls and the phone calls, under an SLA your team reviews. Either way, the design is the same: requirement first, broker-directed requests, automated reading, an escalating chase, and a trail. If you are still choosing tooling, our comparison of COI tracking software covers what to test in a demo.
Start with one building and one trigger. Onboarding is the easiest, because the gate is obvious: nobody gets a key until the certificate is compliant.
Frequently asked questions
Do I need a tenant portal to automate COI collection?
No. Every portal is a login someone forgets. Automation that works meets tenants and brokers where they already are, mostly email, with the system running underneath. The broker's certificate desk is the only party that needs to act, and it acts on a precise emailed request.
How far ahead of expiry should the first COI request go out?
About 60 days for tenants and 45 for vendors, then a follow-up cadence. Vendor compliance tools converge on reminders at 60, 30, and 7 days before expiry; the phone call at about day 30 is what most software cadences leave out.
What should a COI request to a broker include?
The exact certificate holder name and address, the additional insured entities word for word, the coverage lines and minimum limits, the endorsement forms required, and a due date. Brokers produce exactly what is asked, so a vague request produces last year's defects again.
Can AI read certificates of insurance reliably?
Yes for the standard fields: dates, limits, named insured, certificate holder, and the presence of endorsements. Messy certificates (a broker cover letter, a handwritten box) still get flagged for a person. Jones reports its reviews typically complete in under 24 hours; vendor comparisons of portal tools cite two days to two weeks.
What happens when a vendor never sends a compliant certificate?
At day zero the vendor is blocked from dispatch until compliant, with a documented emergency exception path and a next-day cure. A certificate pending more than 14 days is no longer a paperwork problem; someone has to grant a documented exception or stop the relationship.