Fake Certificates of Insurance: How to Spot Them Before They Cost You
A COI is a promise printed on one page — and one of the most-faked business documents. What a certificate actually proves, the red flags, and how to verify one properly.

Somewhere on your desk (or in your inbox) is a certificate of insurance from a vendor, a contractor, a carrier, or a tenant. One page, familiar layout, policy numbers, limits, effective dates, maybe an agency block in the corner. It looks official because the format is standardized.
Here's the uncomfortable part: that standardization cuts both ways. Because nearly every COI looks the same, a fake COI has a perfect template to imitate — and because certificates are usually collected by people with a hundred other things to do, most are filed without a single verification step. If you wanted to design a document to be faked, you'd design the COI intake process exactly as most companies run it.
Why COIs get faked
The motive is straightforward: insurance is expensive, and a COI unlocks work. A contractor who let coverage lapse, a carrier who can't afford cargo insurance, a tenant who never bought a policy — each needs one page to pass a checkpoint. The temptation isn't abstract; it's a monthly premium versus ten minutes in a PDF editor.
And the checkpoint rarely checks. A certificate gets requested, received, glanced at for the right limits, and filed. The fraud only surfaces when there's a claim — which is to say, at the worst possible moment, when the uninsured loss has already happened and the "coverage" evaporates.
What a COI actually proves (less than you think)
Even a genuine certificate proves less than people assume, which is worth understanding before we get to fakes:
- It's evidence a policy existed when the certificate was issued — not a guarantee it's still in force today. Policies get cancelled for non-payment the week after a certificate prints.
- It confers no rights by itself. The standard forms say so explicitly: the certificate is informational, and the policy's own terms govern.
- Exclusions live in the policy, not on the certificate. A COI showing general liability tells you nothing about whether the specific work you're hiring for is excluded.
So the right mental model: a real COI is a pointer to coverage, and a fake COI is a pointer to nothing. Either way, the certificate isn't the thing — verification is.
Red flags on the document itself
Before any phone call, the document can betray itself:
- Date arithmetic. Policy periods that don't span the work, effective dates after the issue date, or a certificate "issued" on a weekend by an agency that was closed.
- Policy numbers that don't fit. Carriers use consistent formats. A number with the wrong shape for the named carrier is a real signal — fabricators invent plausible-looking numbers, not correct ones.
- Editing traces. Certificates are usually generated by agency software. A COI that's been through an editor after creation — touched fonts, misaligned fields, a modification history that postdates issuance — was altered by someone, and there are few innocent reasons.
- Internal inconsistencies. Limits that don't match between sections, a carrier NAIC number that belongs to a different insurer, an agency block whose address and phone don't correspond.
Automated intake helps here for the same reason it helps with invoices: machines check every certificate with the same attention, including the ones that arrive on a busy Friday.
Verify with the issuer, not the vendor
The document checks filter; the phone call decides. Call the issuing agency listed on the certificate — using a number you looked up independently, not the one printed on the page (a fabricated COI happily prints an accomplice's number). Ask them to confirm the policy is active, the limits match, and the certificate was actually issued by their office. Agencies field these calls routinely; a legitimate one answers in minutes.
For higher stakes, go one layer deeper and confirm with the carrier. And if you hold certificates from many counterparties — a fleet of subcontractors, a carrier network — make the verification call part of onboarding, not something reserved for suspicion. The vendors who push back hardest against a routine verification call are telling you something. (It's the same principle as the rest of vendor onboarding: verify through channels the counterparty doesn't control.)
Put COI checks into intake, not audits
The failure mode isn't usually one missed fake — it's a filing cabinet of unverified, expiring certificates. The durable fix is process:
- Verify at intake. Document checks plus the agency call, before work starts or freight moves.
- Track expirations. Every certificate has a date; something should be watching them and chasing renewals automatically.
- Re-verify on renewal. A vendor whose coverage lapsed mid-relationship looks exactly like a vendor whose certificate is about to be "extended" in an editor.
For industries that run on COIs — construction and trades, freight, property and insurance workflows — this is one of the highest-yield checks per minute spent anywhere in the intake stack.
Frequently asked questions
How do I verify a certificate of insurance is real?
Two layers. First the document: date logic, policy number format for the named carrier, internal consistency, and whether the file shows editing after creation. Then the channel: call the issuing agency on an independently found number and confirm the policy is active with those limits. The call is the decisive step — a clean-looking certificate means little until the issuer confirms it.
What's the difference between the COI and the policy?
The policy is the contract; the certificate is a one-page summary issued as evidence of it. The certificate grants no coverage and controls nothing — exclusions, conditions, and cancellation all live in the policy. That's why a genuine certificate can still mislead, and why anything high-stakes justifies requesting policy documentation, not just the cert.
How often should certificates be re-checked?
At intake, at every renewal, and on any event that changes the risk — new scope of work, a claim, a vendor changing carriers mid-project. Continuous tracking of expiration dates should be automated; certificates age into worthlessness on a schedule, which is the one part of this problem that's completely predictable.
Put it to the test
Scan a document and get a plain-English verdict in seconds. Free to start.
Keep reading
Where Document Fraud Actually Concentrates, by Industry
'Document fraud' means something different in freight, lending, insurance, and HR. Where the risk concentrates by industry — and why the forgery technique should decide your defense.
Medical Billing Fraud: Reading an EOB Like an Investigator
Most medical billing fraud isn't a doctored PDF — it's honest-looking documents describing dishonest care. How to read the EOB, the bill, and the codes together.
Bill of Lading Fraud: Anatomy of a Fake BOL
A walkthrough of how bill of lading fraud actually unfolds — from a forged rate confirmation to a doctored proof of delivery — and where the paperwork gives the scheme away.