Vendor credentialing is the verification that a contractor meets a building's requirements before it is approved to work: insurance at the required limits with the right endorsements, trade and business licences, tax documentation, background or safety checks, and a signed agreement. It is the front end of vendor compliance; renewals and re-verification are the back end.
Every commercial building runs on outside trades, and every one of them walks in carrying risk: an uninsured injury, an unlicensed repair, a worker who should not have access to a tenant floor. Vendor credentialing is the gate. It is also the part of vendor management that gets done carefully once, at onboarding, and then quietly decays.
What does a commercial building verify?
The requirement set comes from three places: the owner's insurance program, the law, and the service contract. NetVendor's explainer on credentialing lists the usual documents from the software side; the table below is what a commercial property team actually asks for, by item and by reason.
| Credential | What is checked | Why |
|---|---|---|
| Certificate of insurance | Coverages, limits, dates, named insured | Proof the vendor is insured for the work |
| Endorsements | Additional insured, primary and non-contributory, waiver of subrogation | The building is protected under the vendor's policy, and first |
| Business and trade licences | Current, in the right jurisdiction, for the trade | Legal work and insurer expectations |
| Tax documentation | W-9 in the US, TIN match | Payment and reporting compliance |
| Signed service agreement | Indemnity, insurance clause, safety and access rules | The contract the certificate has to satisfy |
| Background or sanctions checks | Where site access or the owner's policy requires it | Tenant floors, secure areas, owner policy |
| Safety program or bonding | For higher-risk trades and larger contracts | Construction, roofing, elevator, environmental |
The endorsements row is where most credentialing programs are weakest. A certificate that says the owner is an additional insured proves nothing unless the endorsement is attached; the certificate of insurance is informational by its own terms. A programme that files certificates without endorsements is credentialing on paper.
Who runs the process?
Three models exist, and larger owners use more than one.
In-house. The property team collects documents at onboarding, reviews them against a checklist, and files them. Works at one or two buildings with a stable vendor base; breaks at portfolio scale because the review depth depends on who is doing it that day. The vendor onboarding checklist for commercial buildings is the in-house version done properly.
Credentialing services. A third party verifies vendors to the owner's standard, often through a portal, sometimes with human review of every document. RealPage Vendor Credentialing, formerly Compliance Depot, describes its service as customized to the owner's requirements. NetVendor describes AI screening with human verification of every credential, including background checks, sanctions screening, TIN matching, and COI. In heavier industry, Avetta and ISNetworld run contractor prequalification programs that some industrial landlords adopt for their own sites.
Managed operations. The verification, the chase, and the renewal are run by an operator under the owner's written policy, with a service level on the outcome. Premise runs COI compliance this way as one of five operations, on top of the client's Yardi or MRI. Which of the three models fits depends on vendor volume, how negotiated the leases are, and who you want holding the renewal calendar.
Credentialing decides whether a vendor gets in. Compliance decides whether they should still be there in August. Most buildings staff the first and hope about the second.
Why does the renewal matter more than the onboarding?
Because a credential is a snapshot. Insurance expires annually on dates scattered across the vendor list. Licences lapse. Companies change names, get acquired, switch brokers. A vendor base of 150 contractors generates a renewal event two or three times a week, and each one needs a request, a follow-up, a review, and a record. Guides from the compliance software side, including VendorAccess's checklist, make the same observation: the checklist is the easy part, and the programme lives or dies on renewals.
What tends to happen is that renewals get requested and not reviewed. The new certificate arrives, replaces the old one in the folder, and nobody re-reads the description box. The building's compliance rate on paper stays high while the number of vendors with a missing endorsement or a reduced limit grows. The articles on chasing expiring certificates and tracking COIs across a portfolio cover that failure in detail.
How should you set up a programme that holds?
Write the requirement first, by trade and by risk tier, and put it in the service agreement. Decide what happens to a non-compliant vendor: work orders on hold, payments blocked, or a warning, and make sure the system of record can enforce it. Decide who reviews, and to what depth: certificate only, or certificate plus endorsements, or full policy on large contracts. Set the renewal lead time and the escalation path: request at 45 days, chase at 30, escalate to the vendor's broker at 15, hold work at zero. Then measure the rate honestly, as verified compliant vendors over active vendors, not as certificates on file.
What should the owner see?
A monthly number: the share of active vendors that are verified compliant, by property and by trade, with the exceptions listed and the action on each. If that number takes a day to produce, the programme is a filing system. If it comes from the system, the gate is working, and the harder question can be asked of whoever runs it: what is the service level on getting an expired vendor back to compliant, and who is accountable when it slips.
Frequently asked questions
What is vendor credentialing in property management?
The process of verifying that a vendor meets a defined set of insurance, licensing, tax, and eligibility requirements before it is approved to perform work on a property. Software vendors such as NetVendor define it that way; owners define the requirements themselves, by trade and by risk.
What documents are checked during vendor credentialing?
A certificate of insurance with the required coverages, limits, and endorsements; business and trade licences; a tax form such as a W-9 in the US; a signed service agreement with indemnity terms; and, for vendors with regular site access or specific trades, background checks, safety programs, or bonding.
How is vendor credentialing different from vendor compliance?
Credentialing is the approval at the start. Compliance is the state of meeting requirements over time, including renewals. A vendor credentialed in January is not compliant in August if its certificate expired in July. Products and services in this category usually cover both under one name.
Who pays for credentialing, the owner or the vendor?
Depends on the model. Some credentialing services charge vendors an annual fee to be verified; others charge the owner. Vendor-paid models keep the owner's cost low and can slow the onboarding of small local trades, which is a practical consideration for buildings that rely on them.
How often should vendor credentials be re-verified?
At every expiration, which for insurance is usually annual and staggered across vendors, and at any change in the contract or the work. Most programs also re-run background and sanctions checks on a fixed cycle. The re-verification cadence is what separates a credentialing program from a one-time onboarding.
Do credentialing platforms integrate with Yardi and MRI?
Most claim an integration. The useful version syncs the vendor master and blocks work orders or payments to vendors whose status is not approved. Ask to see that block working against a real vendor record in a demo, rather than an export.