COI essentials
Certificate holder and additional insured appear on the same page of every COI, but they confer different rights. Confusing them costs nothing until a subcontractor's work injures someone, and then the difference decides whose policy responds.
Every certificate of insurance a general contractor receives carries both labels, usually a few lines apart. Being the certificate holder means your company got a copy of the document. Being an additional insured, when the status is real, means your company can be defended and paid under the subcontractor's policy. One is effectively a delivery receipt; the other is the coverage itself. Telling them apart is easy. Verifying the one that matters is the part most payment runs skip.
Being named as certificate holder grants nothing. The label means the broker issued a copy of the summary to your company: it identifies the insurer and states the policy period, nothing more. The certificate form says the same on its face, in those words: this certificate confers no rights upon the certificate holder. A file cabinet full of certificates naming your company as holder is a record that insurance was represented to exist on certain dates. It is not a right to claim under any of those policies, no matter how the loss arose.
Additional insured status is different in kind. It extends the subcontractor's policy to your company as an insured party for liability arising out of the subcontractor's operations. When a subcontractor's crew damages adjacent property or injures a third party, the claim usually names everyone in sight, your company included. With the status, you tender the claim to the subcontractor's insurer and their policy responds first. Without it, your own general liability policy pays, and your loss history absorbs the hit.
The failure mode is ordinary: the additional insured box is checked, everyone files the PDF, and the coverage does not exist. The box on a certificate is informational. The right itself is created by an endorsement attached to the subcontractor's policy, typically form CG 20 10 for ongoing operations and CG 20 37 for completed operations. If the endorsement was never issued, was issued in a narrower form, or was issued to an entity name that does not match your contract, the checked box describes coverage that is not there. Only the endorsement proves the status. A contract that requires additional insured status should require the endorsement document, not the summary alone.
The check is threefold, and it belongs inside the same verification pass that reads the rest of the certificate. First, the status: the contract's named party must appear as additional insured, exactly, and an entity-name mismatch counts as a gap. Second, the form: collect the endorsement document and compare its form number against the contract requirement. Ongoing and completed operations are separate coverages, and a subcontract that requires both is not satisfied by one. Third, the window: endorsements attach to policy periods, so a policy that renews mid-project needs the endorsement on both terms. Every discrepancy becomes a tracked exception with an owner and a deadline. The payment-time verification procedure is where this check lands, because a status that was true at onboarding says nothing about the renewal that happened since.
Kernos runs this audit as a rules-engine pass at each payment run, not as an onboarding habit. Contract requirements become objects: coverage lines, limits, additional insured status, required endorsement forms. Certificates and endorsement documents are parsed from the PDFs you already receive and compared field by field. A checked box without the form behind it becomes an exception someone has to resolve, routed through an approval flow where the person who raises it cannot be the one who clears it. Every decision lands in an append-only audit chain, so the record shows what was verified when the payment released. See the construction compliance overview, run the payment-run checklist against your next cycle, or start from the platform overview.