Most of project portfolio management is about choosing and steering work. But the moment your delivery depends on outside vendors and contractors, a different kind of risk enters the picture, and it has nothing to do with schedule or scope. It is compliance: the certificates of insurance, licenses, and contractual requirements that have to stay current for that contractor to be on the job at all.

This risk is easy to ignore because it is invisible right up until it is not. A contractor's general liability insurance lapses. A subcontractor was never verified. Then there is an incident, or an audit, or a client who asks to see the paperwork, and suddenly a document nobody was tracking is holding up an entire program.

Key takeaways

  • Vendor compliance is portfolio risk. A lapsed certificate can stop work as surely as a missing resource.
  • Track requirements and expiration dates centrally, not in scattered email folders.
  • Verify before work starts and re-verify on renewal, because compliance is a moving target.

Why this is a portfolio problem, not just a procurement one

It is tempting to file vendor compliance under procurement and forget it. But from a portfolio perspective, an out-of-compliance contractor is a delivery risk identical in effect to a key resource leaving: the work cannot proceed. When several projects share the same vendors, one expired certificate can ripple across the portfolio. That is a shared dependency in every practical sense, and it belongs in the same view you use for project dependency management. That also makes compliance status something portfolio leaders should be able to see, not a detail buried two layers down. Owning that cross-project view is squarely a project management office job, since no single project manager has line of sight across every vendor the portfolio shares.

What you are actually tracking

For each vendor or contractor, compliance usually comes down to a short list: the required coverage types and limits, the certificates of insurance that prove them, any licenses or certifications the work demands, and the expiration date on each. The challenge is rarely understanding the requirements. It is keeping the documents current across dozens of vendors, each on its own renewal cycle, without the whole thing living in one person's inbox.

Make compliance a tracked status, not a fire drill

The organizations that handle this well treat compliance as a standing status with dates and owners, the same way they treat project milestones. Each vendor has a record, each required document has an expiration, and something flags the renewal before it lapses rather than after. An approaching expiry is a risk with a known date, so the cleanest home for it is the project risk register that delivery already reviews. For portfolios with a large or constantly changing roster of vendors, dedicated certificate of insurance tracking software automates the collection and expiration monitoring so a lapse gets caught before it stops the work. The tool matters less than the habit: verify before work begins, re-verify on renewal, and keep the status visible to the people accountable for delivery.

Fold compliance into the gate

The natural place to enforce this is at a project gate. Before a project that depends on external vendors moves into delivery, vendor compliance should be a checklist item in the stage-gate process, alongside the project budget and capacity. That ties it into the same portfolio governance machinery that controls everything else, instead of leaving it as an afterthought that only gets attention when something goes wrong. A compliance lapse caught at a gate is a quick fix. The same lapse caught during an incident is a crisis.

The documents behind the program

Vendor compliance is one example of a broader truth about project portfolios: a surprising amount of delivery risk lives in documents, not in the plan. Contracts, certificates, statements of work, and approvals all carry information the portfolio depends on, and all of it has to be captured and kept current. For how to handle that document load at scale, see from project documents to portfolio data.

Tier the roster before you track anything

The instinct on discovering a compliance gap is to start collecting documents from every vendor in the portfolio. That is the wrong first move, and it is why so many compliance programs collapse under their own weight in the second quarter. Most portfolios have a long tail of suppliers where full insurance verification is genuine overhead: the training provider who delivers a webinar, the SaaS vendor nobody meets, the design agency working entirely off site.

Requirements should follow exposure. Decide the tiers first, write down what each tier must produce, and only then worry about how you collect it.

TierTypical vendorsEvidence requiredRe-verification
Tier 1: on site or safety exposedConstruction, facilities, field engineering, installation, anyone on your premisesGeneral liability with your organization named as additional insured, workers compensation, auto, licenses, subcontractor evidenceBefore work, at every renewal, and on any change of scope or site
Tier 2: professional services with client data or adviceConsultancies, systems integrators, engineering design, financial advisoryProfessional liability at the contracted limit, general liability, cyber where data is handledBefore work and annually
Tier 3: systems access, no premisesSaaS providers, offshore development, managed servicesCyber liability, security attestations, access agreements. Insurance certificates matter less than controls.Annually, at contract renewal
Tier 4: low exposureTraining, print, catering, licensed content, one off deliverablesContract terms only. Do not build a certificate workflow for these.None beyond contract renewal

Swipe to see more →

The point of the tiering is not to be lenient. It is that a program which demands certificates from all 300 suppliers will chase paper from tier 4 while tier 1 quietly lapses, because the people doing the chasing have a fixed number of hours. Concentrate the effort where an incident would actually land.

A valid certificate is not the same as coverage that protects you

This is the gap that surprises organizations during their first real claim, and it is the reason a compliance program built only on collecting certificates and watching expiry dates gives false comfort. A certificate can be entirely genuine, unexpired, and issued by a solid insurer, and still leave you exposed.

What the certificate showsWhat is actually requiredThe gap
General liability in forceYour organization named as additional insuredWithout the endorsement, the policy covers the vendor, not you. This is the single most common defect.
Coverage limits listedLimits at or above the contracted amountCertificates get filed without anyone comparing the number against the contract clause
Policy dates valid todayCoverage in force for the whole period of workA policy can be canceled mid term. The certificate does not update itself.
Named insured is the vendorNamed insured matches the contracting entityGroup companies sign with one entity and insure under another
Prime contractor coveredSubcontractors covered tooMost portfolios verify the prime and never see who the prime brings on site
Waiver of subrogation absentWaiver present where the contract requires itThe insurer can pursue you for what it pays out

Swipe to see more →

Two of these deserve a specific note. The additional insured endorsement is the difference between evidence that a vendor is insured and evidence that you are protected, and checking for it takes one extra look at the document. The subcontractor gap is harder: your contract is with the prime, so the practical control is a contract clause obliging the prime to hold equivalent evidence for anyone they bring on, plus a spot check rather than a full collection exercise.

Exposure days, the number worth tracking

Compliance programs tend to report activity: certificates collected, vendors onboarded, reminders sent. None of that says whether you were exposed. The measure that does is exposure days: across the last quarter, the total number of days on which an active contractor worked on a portfolio project while a required document was missing or expired.

Exposure days per quarterWhat it tells youWhat to fix
ZeroVerification at the gate and renewal monitoring are both workingNothing. Keep sampling to confirm the number is real.
1 to 30Renewals are being caught late. Usually a reminder that fires on the expiry date rather than before it.Move the trigger 30 to 60 days ahead of expiry, and give it an owner
31 to 90Onboarding verification is being skipped under schedule pressureMake evidence a hard gate condition rather than a checklist item
Over 90You are finding lapses through incidents and audits, not through monitoringTreat as a portfolio risk with an owner and a date, not a procurement backlog

Swipe to see more →

You can only calculate this if you record when work actually happened alongside when documents were valid, which is itself a useful discipline. Calibrate the bands against your own history rather than treating them as industry constants. The number's real value is that it converts a vague sense that "compliance is a bit behind" into something a portfolio review can act on, and it makes the case for investment far better than a count of certificates on file.

Three routes, and when a spreadsheet is the right answer

There is a reflex in this area to buy software first. Sometimes that is correct and sometimes it is an expensive way to formalize a requirement list nobody has agreed. The honest comparison looks like this.

RouteWorks whenBreaks whenReal cost
A tracked spreadsheet with calendar remindersUnder roughly 25 active vendors, stable roster, one clear ownerThe owner goes on leave, or the roster starts changing monthlyA few hours a month, and total dependence on one person remembering
A module in an existing procurement or ERP systemYou already run vendor onboarding there and the fields existThe system tracks vendors but not project assignment, so you cannot answer who is on site todayConfiguration time, usually low incremental license cost
Dedicated tracking softwareLarge or fast changing rosters, multiple tiers, audit exposure, subcontractor chainsRequirements were never defined, in which case it automates the wrong checklist fasterSubscription plus the internal owner it still requires

Swipe to see more →

If your roster is small and stable, a spreadsheet with an owner and a reminder that fires 45 days before expiry will outperform a tool nobody has configured properly, and it costs nothing. Buy the software when the roster's size or churn has genuinely defeated a person paying attention, not before, and never as a substitute for deciding what each tier must produce. Automating an undefined requirement list produces a tidy dashboard reporting on the wrong fields.

Who owns this, in practice

Compliance falls between functions, which is exactly why it lapses. Procurement owns the contract clause, the project manager owns the vendor's delivery, legal owns the requirement, and nobody owns the middle: confirming that the evidence on file today matches what the contract demands for work happening this week. Write it down explicitly.

ActivitySensible owner
Setting required coverage types and limits by tierLegal or risk, once, reviewed annually
Getting the clause into the contractProcurement
Collecting evidence before work startsProject manager, as a gate condition
Monitoring expiry and chasing renewalsA single named administrator, or the tool
Reporting status across the portfolioPMO, in the standing portfolio view
Deciding whether work stops on a lapsePortfolio or program lead, against a pre agreed rule

Swipe to see more →

The last row is the one worth settling before you need it. Agree in advance what a lapse triggers: a warning, a stop on new work, or a full stand down. Deciding that in the moment, with a schedule under pressure and a contractor already on site, produces the wrong answer almost every time. Assigning these owners is the same exercise as any other accountability split, and a RACI matrix is the usual place to record it.

Five ways vendor compliance programs fail

  • Collecting certificates without reading them. The document is on file, the additional insured endorsement is missing, and everyone believes they are covered. Filing is not verification.
  • A reminder that fires on the expiry date. By then the vendor has a lapse and you have a choice between stopping work and accepting exposure. Fire it 30 to 60 days early.
  • Tracking vendors but not assignments. You know a vendor's status but cannot answer which projects they are currently working on, so you cannot size the exposure when something lapses.
  • Verifying the prime and ignoring the chain. The compliant contractor brings two subcontractors nobody has seen. This is where most real incidents originate.
  • Treating it as procurement's problem. Procurement's involvement ends at contract signature. The exposure runs for the whole delivery period, which belongs to the portfolio.

Frequently asked questions

What is a certificate of insurance?

A certificate of insurance (COI) is a one-page document from an insurer that proves a vendor or contractor carries specific coverage, such as general liability or workers' compensation, with named limits and effective dates. On a project it is the evidence that a contractor's insurance is real and current. It is a summary, not the policy itself, so it can lapse or be canceled without the certificate updating.

What does a certificate of insurance cover?

A certificate of insurance lists the coverage types a vendor holds, most commonly general liability, professional liability, workers' compensation, and auto, each with policy limits and expiration dates. On projects it is used to confirm a contractor carries the coverage the contract requires before work begins. Read the actual limits and dates rather than assuming the certificate alone means the vendor meets your requirements.

How do you track certificates of insurance for multiple vendors?

Track certificates of insurance in one central record with a field for each vendor's required coverage, the certificate on file, and its expiration date, then set a reminder that fires before each expiry rather than after. For a large or changing vendor roster, tracking software automates collection and expiration monitoring. The principle holds regardless of tooling: verify before work starts, re-verify on renewal, and keep the status visible to whoever owns delivery.

Why is vendor compliance a portfolio-level concern?

Vendor compliance is a portfolio concern because an out-of-compliance contractor is a delivery risk identical in effect to losing a key resource: the work cannot proceed. When several projects share the same vendors, one lapsed certificate can ripple across the portfolio at once. That makes compliance status something portfolio leaders should be able to see at a glance, not a procurement detail buried two layers down.

What is an additional insured endorsement?

An additional insured endorsement extends a vendor's liability policy to cover your organization for claims arising from that vendor's work. Without it, a valid certificate proves the vendor is insured but leaves you unprotected, which is the most common defect found in vendor compliance files. Check that the endorsement is present and names the correct legal entity, not just that a certificate exists.

How often should vendor compliance be verified?

Verify before work starts, then re-verify at every policy renewal, with a reminder that fires 30 to 60 days ahead of expiry rather than on the date itself. High exposure vendors working on site should also be re-checked on any change of scope or location. A policy can be canceled mid term without the certificate changing, so periodic confirmation matters more than the expiry date alone.

Who is responsible for vendor compliance on a project?

Responsibility splits across functions, which is why it lapses. Legal or risk sets the required coverage, procurement puts it in the contract, the project manager confirms evidence before work begins, a named administrator monitors renewals, and the PMO reports status across the portfolio. The decision that must be agreed in advance is who can halt work when something lapses.

What happens if a contractor's insurance lapses mid-project?

Work continues under exposure until somebody notices, which is the problem. Agree the rule before it happens: whether a lapse triggers a warning, a stop on new work, or a full stand down. Deciding in the moment, with a contractor on site and a schedule under pressure, reliably produces the more expensive answer.

Do you need to track certificates for every vendor?

No, and trying to is why compliance programs stall. Tier the roster by exposure. Vendors on your premises or exposed to safety risk need full verification, professional services need liability cover at the contracted limit, and low exposure suppliers such as training or print need contract terms only. Concentrating effort where an incident would actually land beats chasing paper from everyone.

Where this fits

If you areGo to
Recording the lapse as a risk with an owner and a dateProject risk register
Making evidence a hard condition to pass a gateStage gate process
Handling the wider document load behind the portfolioFrom project documents to portfolio data
Managing the commitments and purchase orders behind these vendorsProject budgets and portfolio spend
Buying outside delivery help rather than contracting suppliersPMO consulting services
Recording who owns each stepRACI matrix

Swipe to see more →

Last updated September 2026.

E
Elena Marsh
PMO lead and portfolio strategist. Fifteen years building project management offices and running portfolio governance for technology and professional-services teams.