Leasing & Compliance

Vendor compliance checklist for commercial buildings: the ten items that get enforced

Sep 16, 2026 · 7 min read · Premise Team

The short answer

Vendor onboarding for a commercial building means collecting and verifying ten items before the first work order: legal identity, a certificate of insurance meeting the trade requirement, the endorsement forms, licenses, a signed vendor agreement, safety documentation, access data, emergency contacts, verified banking details, and a compliance status with an owner. A checklist that gates nothing is a survey.

The vendor who caused the problem was almost never a stranger. It was the plumber the building had used for six years, whose general liability lapsed in March, who nobody re-checked because "we know them." Vendor onboarding is easy to do well on day one and easy to forget on day four hundred. The checklist below is built for both.

It is written for commercial buildings: office, retail, mixed-use, industrial. Multifamily has a similar list with different contract forms. The point is not the paperwork. The point is that nobody sets foot in a mechanical room or a tenant's suite until the building can prove it checked.

What is vendor onboarding actually protecting?

Three things, and it helps to keep them separate because they need different documents.

  • Liability transfer. If the vendor's work injures someone or damages property, the vendor's insurance responds first. That requires the right coverage, the right limits, and the right endorsements naming the right entity.
  • Regulatory exposure. Unlicensed electrical work, unregistered elevator contractors, missing safety training. The building inherits the violation.
  • Operational reliability. Emergency contacts, response commitments, and a clear scope so that a 2 a.m. call reaches someone who will show up.

Most checklists over-collect on the first and under-collect on the third.

The checklist

Collect, verify, and file each item before the first work order is issued. "Verify" means someone or something read it against a requirement, not that it arrived.

Item Verified against Re-checked when
Legal identity and W-9 The name on the insurance certificate Any entity change
Certificate of insurance and endorsements The trade-tier requirement, per building standard Every renewal; reminders at 60, 30, and 7 days are the vendor-tool norm
Licenses and registrations The licensing authority's register Their own expiry dates
Vendor agreement and safety acknowledgments Your contract template and building rules Contract renewal or scope change
Banking details Call-back to a known number Any change request
Compliance status Approved, conditional (with approver and expiry), or not approved Monthly sample audit
  1. Legal identity. Exact legal name, DBA, address, and a W-9 or equivalent. The name here must match the name on the insurance certificate. Mismatches are the most common defect we see.
  2. Certificate of insurance meeting the trade-specific requirement: general liability with the ownership entity and manager as additional insured, workers' compensation, auto if they drive on site, umbrella where the trade warrants it. Waiver of subrogation and primary and non-contributory wording where your contracts require them. We cover the collection mechanics in how to automate COI collection.
  3. Endorsement forms, not only the certificate. A certificate says an endorsement exists; the endorsement proves it.
  4. Licenses and registrations for licensed trades, with expiry dates tracked like insurance.
  5. Signed vendor agreement with indemnity, insurance requirements, and building rules attached. If the vendor works under a tenant's contract rather than yours, get the tenant's confirmation in writing.
  6. Safety documentation appropriate to the work: hot work permits process, lockout/tagout acknowledgment, confined-space where relevant, and the building's contractor rules signed.
  7. Access and security data. Named personnel for badge issuance, background-check attestations if your policy requires them, after-hours access procedure acknowledged.
  8. Emergency contacts with a stated response window, in the vendor's own words, so you can hold them to it.
  9. Banking and invoicing setup, verified by call-back to a known number, because vendor onboarding is where payment fraud enters.
  10. A compliance status and an owner. Every vendor record ends in one of three states: approved, conditionally approved (with the specific exception, its approver, and its expiry), or not approved. Someone's name is on it.

What to ask before you approve an exception: "If this vendor causes a loss on Thursday, what will I say to the owner about why they were on site?" If there is no good sentence, there is no exception.

Where does vendor onboarding fail in practice?

We see the same five failures across portfolios of every size.

The known vendor. Long-standing vendors skip the process because relationships feel like verification. They are not. Re-onboard everyone at renewal.

The scale of the vendor universe is the argument for a process rather than a memory: BCS reports a pre-vetted network of 78,000 vendors and Jones a network of 30,000+ vendor profiles, which is the scale the compliance vendors are built for.

Tenant-hired contractors. A tenant's fit-out contractor is on your floor with your elevators and your sprinkler system, under a contract you did not write. Require the same certificate and rules acknowledgment through the lease's alterations clause, and check before the first delivery.

The emergency. A pipe bursts at 11 p.m. and the only available contractor is not on the list. Have a documented emergency exception path with a next-business-day cure requirement, so the exception is a decision rather than an omission.

Portfolio drift. Building A requires a $2M umbrella; Building B requires $1M; Building C has no written standard. The same vendor is compliant in one and deficient in another. This is a policy problem, handled in portfolio-wide COI tracking.

The unowned queue. Deficient records sit in a shared inbox. Nobody is measured on clearing them. Nothing clears.

Enforcement is the whole point

A checklist that does not gate anything is a survey. The gate has to be operational: the work order system, the badge desk, the dock. Several vendor compliance tools can now block dispatch to non-compliant vendors inside the property management system; NetVendor, for instance, positions itself on enforcement rather than tracking, and Yardi markets VendorShield as doing the same within Voyager. If your tooling cannot gate, the gate has to be a person, and that person needs authority to say no to a property manager under pressure.

This is the part of the process that benefits most from being run outside the property team. When Premise runs vendor compliance as part of its managed operations, every vendor request is approved or declined against the client's written policies, by operators whose job is to hold the line, with the exception path documented. The property manager gets the decision and the reasoning, not the queue.

Keeping it current after day one

Onboarding is an event; compliance is a state. To keep the state true:

  • Track expiry on every dated document, not only insurance, with requests going out 60 days ahead and reminders at 30 and 7.
  • Re-verify on change: scope, entity, ownership, contract renewal.
  • Audit a random sample monthly: pull ten approved vendors, re-read their files, count defects. The number is your real compliance rate.
  • Report to ownership quarterly in one page: approved, conditional, deficient, and days-to-cure.

If you are also building the request side of this, vendor compliance status should be visible in the request system at the moment a work order is assigned, not discovered at the dock.

Print the ten items. Tape them to the dock desk. Then make the dock the gate.

Frequently asked questions

What documents should a vendor provide before working in a commercial building?

A W-9 or equivalent with the exact legal name, a certificate of insurance meeting the trade-specific requirement, the endorsement forms behind it, trade licenses, a signed vendor agreement with indemnity and building rules, safety acknowledgments, named personnel for access, emergency contacts, and banking details verified by call-back.

What insurance should a commercial building require from vendors?

General liability naming the ownership entity and manager as additional insured, workers' compensation, auto if they drive on site, and an umbrella for higher-risk trades, with waiver of subrogation and primary and non-contributory wording where the contract requires them. Limits vary by trade tier.

How often should vendor compliance be re-checked?

Insurance at every renewal (annually for most policies), licenses at their own expiry, and everything on any change of scope, entity, or contract. Vendor compliance tools typically send reminders at 60, 30, and 7 days before expiry; a monthly random audit of ten files catches what the reminders miss.

What about contractors hired by tenants?

They are on your floor with your elevators and your sprinkler system under a contract you did not write. Require the same certificate and rules acknowledgment through the lease's alterations clause, and check before the first delivery, not after.

Where should vendor compliance be enforced?

At the operational gate: the work order system, the badge desk, and the dock. Tools such as NetVendor and Yardi's VendorShield position themselves as gating dispatch to non-compliant vendors inside the property management system; if your tooling cannot gate, a person with authority to say no has to.

Related insights

Start where it is hurting the most.

One operation. One property. SLA-backed from day one.

Start your pilot
© 2026 PremiseHQ AI. All rights reserved. Privacy Policy