How-to guideApr 30, 2026by Docurensic Team5 min read

Fake Certificates of Insurance: How to Spot Them Before They Cost You

A COI is a promise printed on one page — and one of the most-faked business documents. What a certificate actually proves, the red flags, and how to verify one properly.

Fake Certificates of Insurance: How to Spot Them Before They Cost You
In this guide
  1. Why COIs get faked
  2. What a COI actually proves (less than you think)
  3. Red flags on the document itself
  4. Verify with the issuer, not the vendor
  5. Put COI checks into intake, not audits
  6. Frequently asked questions

Somewhere on your desk (or in your inbox) is a certificate of insurance from a vendor, a contractor, a carrier, or a tenant. One page, familiar layout, policy numbers, limits, effective dates, maybe an agency block in the corner. It looks official because the format is standardized.

Here's the uncomfortable part: that standardization cuts both ways. Because nearly every COI looks the same, a fake COI has a perfect template to imitate — and because certificates are usually collected by people with a hundred other things to do, most are filed without a single verification step. If you wanted to design a document to be faked, you'd design the COI intake process exactly as most companies run it.

Why COIs get faked

The motive is straightforward: insurance is expensive, and a COI unlocks work. A contractor who let coverage lapse, a carrier who can't afford cargo insurance, a tenant who never bought a policy — each needs one page to pass a checkpoint. The temptation isn't abstract; it's a monthly premium versus ten minutes in a PDF editor.

And the checkpoint rarely checks. A certificate gets requested, received, glanced at for the right limits, and filed. The fraud only surfaces when there's a claim — which is to say, at the worst possible moment, when the uninsured loss has already happened and the "coverage" evaporates.

What a COI actually proves (less than you think)

Even a genuine certificate proves less than people assume, which is worth understanding before we get to fakes:

So the right mental model: a real COI is a pointer to coverage, and a fake COI is a pointer to nothing. Either way, the certificate isn't the thing — verification is.

Red flags on the document itself

Before any phone call, the document can betray itself:

Automated intake helps here for the same reason it helps with invoices: machines check every certificate with the same attention, including the ones that arrive on a busy Friday.

Verify with the issuer, not the vendor

The document checks filter; the phone call decides. Call the issuing agency listed on the certificate — using a number you looked up independently, not the one printed on the page (a fabricated COI happily prints an accomplice's number). Ask them to confirm the policy is active, the limits match, and the certificate was actually issued by their office. Agencies field these calls routinely; a legitimate one answers in minutes.

For higher stakes, go one layer deeper and confirm with the carrier. And if you hold certificates from many counterparties — a fleet of subcontractors, a carrier network — make the verification call part of onboarding, not something reserved for suspicion. The vendors who push back hardest against a routine verification call are telling you something. (It's the same principle as the rest of vendor onboarding: verify through channels the counterparty doesn't control.)

Put COI checks into intake, not audits

The failure mode isn't usually one missed fake — it's a filing cabinet of unverified, expiring certificates. The durable fix is process:

For industries that run on COIs — construction and trades, freight, property and insurance workflows — this is one of the highest-yield checks per minute spent anywhere in the intake stack.

Frequently asked questions

How do I verify a certificate of insurance is real?

Two layers. First the document: date logic, policy number format for the named carrier, internal consistency, and whether the file shows editing after creation. Then the channel: call the issuing agency on an independently found number and confirm the policy is active with those limits. The call is the decisive step — a clean-looking certificate means little until the issuer confirms it.

What's the difference between the COI and the policy?

The policy is the contract; the certificate is a one-page summary issued as evidence of it. The certificate grants no coverage and controls nothing — exclusions, conditions, and cancellation all live in the policy. That's why a genuine certificate can still mislead, and why anything high-stakes justifies requesting policy documentation, not just the cert.

How often should certificates be re-checked?

At intake, at every renewal, and on any event that changes the risk — new scope of work, a claim, a vendor changing carriers mid-project. Continuous tracking of expiration dates should be automated; certificates age into worthlessness on a schedule, which is the one part of this problem that's completely predictable.

Put it to the test

Scan a document and get a plain-English verdict in seconds. Free to start.

Start scanning free

Keep reading

Case studyJun 23, 20263 min

Bill of Lading Fraud: Anatomy of a Fake BOL

A walkthrough of how bill of lading fraud actually unfolds — from a forged rate confirmation to a doctored proof of delivery — and where the paperwork gives the scheme away.