A certificate of insurance takes about four minutes to issue when everything is in order. The request names the holder, the policy is in force, the holder wants standard limits and nothing exotic, the CSR opens the certificate tool, picks the account, picks the holder, prints. Four minutes.
The four minutes are not the problem. The problem is the requests that are not in order, the time it takes to find out which ones those are, and what happens when a CSR under time pressure issues one of them anyway.
Where the time goes
Watch a certificates desk for a day and the work looks like this:
- Finding the request. It came into the shared certificates mailbox, or a CSR's personal inbox, or a client forwarded it with "can you handle this?", or it is sitting in a general contractor's compliance portal with a deadline nobody saw.
- Working out who it is for. The holder's request names the contractor by its trade name; the AMS has it under the legal entity. The email came from an admin at the client's office with no account number.
- Reading what they want. The holder's requirements are on page 14 of a subcontract: specific per-occurrence limits, additional insured on a primary and non-contributory basis, waiver of subrogation, 30 days' notice of cancellation, and completed operations coverage.
- Checking the policy. Does the GL carry the blanket additional-insured endorsement, and does it include completed ops? Is the waiver of subrogation blanket or scheduled? What does the policy actually say about notice of cancellation to certificate holders?
- Issuing, or not. If the policy supports it, issue. If it does not, go back to the client and explain that their contract asks for something they have not bought, and that this is an endorsement conversation, not a certificate.
The four-minute certificate is the last step. The other steps are where a day goes, and the checking step is where an agency's E&O exposure is.
The expensive failure mode
The failure that costs real money is not a slow certificate. It is a certificate that says the policy provides something it does not. A certificate is an information document, not a contract, and the ACORD 25 says so in large type. Courts and E&O carriers have nonetheless found agencies liable, repeatedly, where a certificate misrepresented coverage and someone relied on it. A CSR who checks "additional insured" because the holder asked for it, without confirming the endorsement, has created that exposure in four minutes.
The uncomfortable part is that this failure mode is caused by the pressure to make certificates fast. The faster you push the desk, the less checking happens, and checking is the whole job.
What "in order" means
A certificate request is in order when all of the following are true:
- The named insured is identified unambiguously and matches an account in the AMS.
- Every policy referenced is in force on the certificate date.
- Every limit requested is at or below the policy limit.
- Every status requested (additional insured, primary and non-contributory, waiver of subrogation, completed operations) is supported by an endorsement actually on the policy, either blanket or with this holder scheduled.
- Any notice-of-cancellation wording requested matches what the policy will actually do.
- The holder's name and address are as they want them on the certificate.
Those six checks are mechanical. They are also exactly the checks that get skipped at 4:55pm on a Friday.
Automate the checking
The productive way to think about certificate handling is to move the checking to the front, before a CSR spends any time, and make the checking the thing that is automated, not the issuing.
That means, per request:
- extract the named insured, the holder, and the requirements from wherever they came in;
- match the insured to the AMS account (and flag when the match is uncertain, rather than guessing);
- pull the in-force policies and their endorsement schedules;
- run the six checks;
- draft the certificate in the issuing tool if everything passes;
- if something fails, say exactly what and why, in terms a CSR can put in an email to the client.
The CSR's job becomes one decision per request: approve the draft, or send the explanation. The four minutes becomes one minute for the clean requests and, for the messy ones, the time saved is the twenty minutes of digging that now happens before the request lands on the desk.
The issuing still requires a human click. That is not a limitation of the technology; it is where the accountability sits, and it should stay there.
Holder portals
Compliance portals (the ones general contractors and property managers use) are a growing share of certificate volume and are the least visible. Requests sit there with deadlines, and a missed deadline can hold up a client's payment. If you are building or buying any certificate handling, make sure it reads those portals, not just the mailbox. It is the channel most likely to be ignored and the one clients get angriest about.
Where to start
If certificates are a bottleneck, start by measuring two numbers for a week: how many requests came in, across every channel including portals and forwarded emails, and how many needed something other than a straight issue. Agencies are usually surprised by the second number. It is the case for putting an engineer on the checking rather than a temp on the issuing.
If you want an engineer to build the checking against your own book, for agencies on Applied Epic, HawkSoft, or EZLynx, that is our COI Agent work.