Most of project portfolio management is about choosing and steering work. But the moment your delivery depends on outside vendors and contractors, a different kind of risk enters the picture, and it has nothing to do with schedule or scope. It is compliance: the certificates of insurance, licenses, and contractual requirements that have to stay current for that contractor to be on the job at all.
This risk is easy to ignore because it is invisible right up until it is not. A contractor's general liability insurance lapses. A subcontractor was never verified. Then there is an incident, or an audit, or a client who asks to see the paperwork, and suddenly a document nobody was tracking is holding up an entire program.
Key takeaways
- Vendor compliance is portfolio risk. A lapsed certificate can stop work as surely as a missing resource.
- Track requirements and expiration dates centrally, not in scattered email folders.
- Verify before work starts and re-verify on renewal, because compliance is a moving target.
Why this is a portfolio problem, not just a procurement one
It is tempting to file vendor compliance under procurement and forget it. But from a portfolio perspective, an out-of-compliance contractor is a delivery risk identical in effect to a key resource leaving: the work cannot proceed. When several projects share the same vendors, one expired certificate can ripple across the portfolio. That is a shared dependency in every practical sense, and it belongs in the same view you use for project dependency management. That also makes compliance status something portfolio leaders should be able to see, not a detail buried two layers down. Owning that cross-project view is squarely a project management office job, since no single project manager has line of sight across every vendor the portfolio shares.
What you are actually tracking
For each vendor or contractor, compliance usually comes down to a short list: the required coverage types and limits, the certificates of insurance that prove them, any licenses or certifications the work demands, and the expiration date on each. The challenge is rarely understanding the requirements. It is keeping the documents current across dozens of vendors, each on its own renewal cycle, without the whole thing living in one person's inbox.
Make compliance a tracked status, not a fire drill
The organizations that handle this well treat compliance as a standing status with dates and owners, the same way they treat project milestones. Each vendor has a record, each required document has an expiration, and something flags the renewal before it lapses rather than after. An approaching expiry is a risk with a known date, so the cleanest home for it is the project risk register that delivery already reviews. For portfolios with a large or constantly changing roster of vendors, dedicated certificate of insurance tracking software automates the collection and expiration monitoring so a lapse gets caught before it stops the work. The tool matters less than the habit: verify before work begins, re-verify on renewal, and keep the status visible to the people accountable for delivery.
Fold compliance into the gate
The natural place to enforce this is at a project gate. Before a project that depends on external vendors moves into delivery, vendor compliance should be a checklist item in the stage-gate process, alongside the project budget and capacity. That ties it into the same portfolio governance machinery that controls everything else, instead of leaving it as an afterthought that only gets attention when something goes wrong. A compliance lapse caught at a gate is a quick fix. The same lapse caught during an incident is a crisis.
The documents behind the program
Vendor compliance is one example of a broader truth about project portfolios: a surprising amount of delivery risk lives in documents, not in the plan. Contracts, certificates, statements of work, and approvals all carry information the portfolio depends on, and all of it has to be captured and kept current. For how to handle that document load at scale, see from project documents to portfolio data.
Tier the roster before you track anything
The instinct on discovering a compliance gap is to start collecting documents from every vendor in the portfolio. That is the wrong first move, and it is why so many compliance programs collapse under their own weight in the second quarter. Most portfolios have a long tail of suppliers where full insurance verification is genuine overhead: the training provider who delivers a webinar, the SaaS vendor nobody meets, the design agency working entirely off site.
Requirements should follow exposure. Decide the tiers first, write down what each tier must produce, and only then worry about how you collect it.
| Tier | Typical vendors | Evidence required | Re-verification |
|---|---|---|---|
| Tier 1: on site or safety exposed | Construction, facilities, field engineering, installation, anyone on your premises | General liability with your organization named as additional insured, workers compensation, auto, licenses, subcontractor evidence | Before work, at every renewal, and on any change of scope or site |
| Tier 2: professional services with client data or advice | Consultancies, systems integrators, engineering design, financial advisory | Professional liability at the contracted limit, general liability, cyber where data is handled | Before work and annually |
| Tier 3: systems access, no premises | SaaS providers, offshore development, managed services | Cyber liability, security attestations, access agreements. Insurance certificates matter less than controls. | Annually, at contract renewal |
| Tier 4: low exposure | Training, print, catering, licensed content, one off deliverables | Contract terms only. Do not build a certificate workflow for these. | None beyond contract renewal |
Swipe to see more →
The point of the tiering is not to be lenient. It is that a program which demands certificates from all 300 suppliers will chase paper from tier 4 while tier 1 quietly lapses, because the people doing the chasing have a fixed number of hours. Concentrate the effort where an incident would actually land.
A valid certificate is not the same as coverage that protects you
This is the gap that surprises organizations during their first real claim, and it is the reason a compliance program built only on collecting certificates and watching expiry dates gives false comfort. A certificate can be entirely genuine, unexpired, and issued by a solid insurer, and still leave you exposed.
| What the certificate shows | What is actually required | The gap |
|---|---|---|
| General liability in force | Your organization named as additional insured | Without the endorsement, the policy covers the vendor, not you. This is the single most common defect. |
| Coverage limits listed | Limits at or above the contracted amount | Certificates get filed without anyone comparing the number against the contract clause |
| Policy dates valid today | Coverage in force for the whole period of work | A policy can be canceled mid term. The certificate does not update itself. |
| Named insured is the vendor | Named insured matches the contracting entity | Group companies sign with one entity and insure under another |
| Prime contractor covered | Subcontractors covered too | Most portfolios verify the prime and never see who the prime brings on site |
| Waiver of subrogation absent | Waiver present where the contract requires it | The insurer can pursue you for what it pays out |
Swipe to see more →
Two of these deserve a specific note. The additional insured endorsement is the difference between evidence that a vendor is insured and evidence that you are protected, and checking for it takes one extra look at the document. The subcontractor gap is harder: your contract is with the prime, so the practical control is a contract clause obliging the prime to hold equivalent evidence for anyone they bring on, plus a spot check rather than a full collection exercise.
Exposure days, the number worth tracking
Compliance programs tend to report activity: certificates collected, vendors onboarded, reminders sent. None of that says whether you were exposed. The measure that does is exposure days: across the last quarter, the total number of days on which an active contractor worked on a portfolio project while a required document was missing or expired.
| Exposure days per quarter | What it tells you | What to fix |
|---|---|---|
| Zero | Verification at the gate and renewal monitoring are both working | Nothing. Keep sampling to confirm the number is real. |
| 1 to 30 | Renewals are being caught late. Usually a reminder that fires on the expiry date rather than before it. | Move the trigger 30 to 60 days ahead of expiry, and give it an owner |
| 31 to 90 | Onboarding verification is being skipped under schedule pressure | Make evidence a hard gate condition rather than a checklist item |
| Over 90 | You are finding lapses through incidents and audits, not through monitoring | Treat as a portfolio risk with an owner and a date, not a procurement backlog |
Swipe to see more →
You can only calculate this if you record when work actually happened alongside when documents were valid, which is itself a useful discipline. Calibrate the bands against your own history rather than treating them as industry constants. The number's real value is that it converts a vague sense that "compliance is a bit behind" into something a portfolio review can act on, and it makes the case for investment far better than a count of certificates on file.
Three routes, and when a spreadsheet is the right answer
There is a reflex in this area to buy software first. Sometimes that is correct and sometimes it is an expensive way to formalize a requirement list nobody has agreed. The honest comparison looks like this.
| Route | Works when | Breaks when | Real cost |
|---|---|---|---|
| A tracked spreadsheet with calendar reminders | Under roughly 25 active vendors, stable roster, one clear owner | The owner goes on leave, or the roster starts changing monthly | A few hours a month, and total dependence on one person remembering |
| A module in an existing procurement or ERP system | You already run vendor onboarding there and the fields exist | The system tracks vendors but not project assignment, so you cannot answer who is on site today | Configuration time, usually low incremental license cost |
| Dedicated tracking software | Large or fast changing rosters, multiple tiers, audit exposure, subcontractor chains | Requirements were never defined, in which case it automates the wrong checklist faster | Subscription plus the internal owner it still requires |
Swipe to see more →
If your roster is small and stable, a spreadsheet with an owner and a reminder that fires 45 days before expiry will outperform a tool nobody has configured properly, and it costs nothing. Buy the software when the roster's size or churn has genuinely defeated a person paying attention, not before, and never as a substitute for deciding what each tier must produce. Automating an undefined requirement list produces a tidy dashboard reporting on the wrong fields.
Who owns this, in practice
Compliance falls between functions, which is exactly why it lapses. Procurement owns the contract clause, the project manager owns the vendor's delivery, legal owns the requirement, and nobody owns the middle: confirming that the evidence on file today matches what the contract demands for work happening this week. Write it down explicitly.
| Activity | Sensible owner |
|---|---|
| Setting required coverage types and limits by tier | Legal or risk, once, reviewed annually |
| Getting the clause into the contract | Procurement |
| Collecting evidence before work starts | Project manager, as a gate condition |
| Monitoring expiry and chasing renewals | A single named administrator, or the tool |
| Reporting status across the portfolio | PMO, in the standing portfolio view |
| Deciding whether work stops on a lapse | Portfolio or program lead, against a pre agreed rule |
Swipe to see more →
The last row is the one worth settling before you need it. Agree in advance what a lapse triggers: a warning, a stop on new work, or a full stand down. Deciding that in the moment, with a schedule under pressure and a contractor already on site, produces the wrong answer almost every time. Assigning these owners is the same exercise as any other accountability split, and a RACI matrix is the usual place to record it.
Five ways vendor compliance programs fail
- Collecting certificates without reading them. The document is on file, the additional insured endorsement is missing, and everyone believes they are covered. Filing is not verification.
- A reminder that fires on the expiry date. By then the vendor has a lapse and you have a choice between stopping work and accepting exposure. Fire it 30 to 60 days early.
- Tracking vendors but not assignments. You know a vendor's status but cannot answer which projects they are currently working on, so you cannot size the exposure when something lapses.
- Verifying the prime and ignoring the chain. The compliant contractor brings two subcontractors nobody has seen. This is where most real incidents originate.
- Treating it as procurement's problem. Procurement's involvement ends at contract signature. The exposure runs for the whole delivery period, which belongs to the portfolio.
Frequently asked questions
What is a certificate of insurance?
A certificate of insurance (COI) is a one-page document from an insurer that proves a vendor or contractor carries specific coverage, such as general liability or workers' compensation, with named limits and effective dates. On a project it is the evidence that a contractor's insurance is real and current. It is a summary, not the policy itself, so it can lapse or be canceled without the certificate updating.
What does a certificate of insurance cover?
A certificate of insurance lists the coverage types a vendor holds, most commonly general liability, professional liability, workers' compensation, and auto, each with policy limits and expiration dates. On projects it is used to confirm a contractor carries the coverage the contract requires before work begins. Read the actual limits and dates rather than assuming the certificate alone means the vendor meets your requirements.
How do you track certificates of insurance for multiple vendors?
Track certificates of insurance in one central record with a field for each vendor's required coverage, the certificate on file, and its expiration date, then set a reminder that fires before each expiry rather than after. For a large or changing vendor roster, tracking software automates collection and expiration monitoring. The principle holds regardless of tooling: verify before work starts, re-verify on renewal, and keep the status visible to whoever owns delivery.
Why is vendor compliance a portfolio-level concern?
Vendor compliance is a portfolio concern because an out-of-compliance contractor is a delivery risk identical in effect to losing a key resource: the work cannot proceed. When several projects share the same vendors, one lapsed certificate can ripple across the portfolio at once. That makes compliance status something portfolio leaders should be able to see at a glance, not a procurement detail buried two layers down.
What is an additional insured endorsement?
An additional insured endorsement extends a vendor's liability policy to cover your organization for claims arising from that vendor's work. Without it, a valid certificate proves the vendor is insured but leaves you unprotected, which is the most common defect found in vendor compliance files. Check that the endorsement is present and names the correct legal entity, not just that a certificate exists.
How often should vendor compliance be verified?
Verify before work starts, then re-verify at every policy renewal, with a reminder that fires 30 to 60 days ahead of expiry rather than on the date itself. High exposure vendors working on site should also be re-checked on any change of scope or location. A policy can be canceled mid term without the certificate changing, so periodic confirmation matters more than the expiry date alone.
Who is responsible for vendor compliance on a project?
Responsibility splits across functions, which is why it lapses. Legal or risk sets the required coverage, procurement puts it in the contract, the project manager confirms evidence before work begins, a named administrator monitors renewals, and the PMO reports status across the portfolio. The decision that must be agreed in advance is who can halt work when something lapses.
What happens if a contractor's insurance lapses mid-project?
Work continues under exposure until somebody notices, which is the problem. Agree the rule before it happens: whether a lapse triggers a warning, a stop on new work, or a full stand down. Deciding in the moment, with a contractor on site and a schedule under pressure, reliably produces the more expensive answer.
Do you need to track certificates for every vendor?
No, and trying to is why compliance programs stall. Tier the roster by exposure. Vendors on your premises or exposed to safety risk need full verification, professional services need liability cover at the contracted limit, and low exposure suppliers such as training or print need contract terms only. Concentrating effort where an incident would actually land beats chasing paper from everyone.
Where this fits
| If you are | Go to |
|---|---|
| Recording the lapse as a risk with an owner and a date | Project risk register |
| Making evidence a hard condition to pass a gate | Stage gate process |
| Handling the wider document load behind the portfolio | From project documents to portfolio data |
| Managing the commitments and purchase orders behind these vendors | Project budgets and portfolio spend |
| Buying outside delivery help rather than contracting suppliers | PMO consulting services |
| Recording who owns each step | RACI matrix |
Swipe to see more →
Last updated September 2026.