Disaster Readiness for Contractor COI Records
When the usual office is unavailable, contractor COI records should not disappear with it. Build a continuity record a backup reviewer can find and act on.
When the usual office is unavailable, contractor COI records should not disappear with it.
A current certificate may be saved on one employee's laptop. The renewal request may live in a personal inbox. The only note explaining an open item may be in someone's memory. A storm, wildfire, power failure, cyber incident, or building closure can expose that weakness in a few hours.
COI records are one small part of business continuity. They will not keep a project running by themselves. They do give the backup team a concrete process to test: can an authorized person find the current evidence, understand the last review, and continue the open follow-up without the usual reviewer?
Define the minimum record a backup reviewer needs
Start with one active subcontractor. The continuity record should include the legal entity, project or work tied to the review, received certificate, visible policy dates, correction requests, requested endorsements or policy provisions, review notes, and every replacement version.
Add the operational context. Who normally owns the record? Who is the backup? Which contact should receive a renewal or correction request? What item is still open, and when is the next follow-up due?
Do not reduce the record to a green status. A backup reviewer needs to know what was checked and what remains unresolved. "Current" could mean the date is in the future, the certificate was received, or the full document review is complete. Those are different facts.
The Ready.gov business toolkits encourage organizations to identify risks, develop a plan, and take action before disruption. Apply that sequence to the COI workflow. Identify where records and decisions can be lost. Document the backup process. Then test it under realistic access limits.
Decide how authorized staff will reach the record
Continuity planning is not the same as making every file available to everyone. Access should follow your organization's security, privacy, and records policies.
Write down the normal system of record and the approved backup method. Include who can authorize access if the primary administrator is unavailable. If a cloud service is part of the plan, know how users authenticate and how the company handles account recovery. If an offline or exported backup is required by company policy, give it an owner and a test date.
Avoid a plan that says "call Maria." Maria may be the person affected by the outage.
Also avoid an untested folder link. During a drill, have the backup reviewer sign in using the same device and network conditions that might apply during a disruption. A bookmark on an office desktop is not a recovery procedure.
Preserve history instead of keeping only the latest PDF
The latest certificate rarely explains the whole record. The backup reviewer may need to see that a revised certificate corrected the named insured but did not include the requested endorsement. A later email may show that the item was escalated to the contract owner.
Save each received version with its received date. Keep correction requests and responses with the record. Record who reviewed the document and the result of that review. If an exception was approved, identify the authorized person, what was accepted, and whether a replacement is still expected.
A COI reports policy information available when it was issued. It is not the policy, does not amend coverage, and does not create additional-insured status. Policy terms and endorsements control. The continuity file should preserve the document and review history without pretending to resolve coverage questions.
Keep the field team's emergency view narrow
During a disruption, project managers and accounting staff need facts they can act on, not an insurance interpretation.
A useful operational view can show the subcontractor, project, latest document received date, listed expiration date, review status, open item, next action, and escalation owner. Labels should describe the workflow: "replacement requested," "awaiting human review," or "listed date passed, verification in progress."
Reporting labels are not coverage decisions. A passed listed date does not automatically mean the policy lapsed. It calls for verification. Work, payment, owner-notification, and escalation rules vary by contract, law, and risk program. The authorized team decides what action follows.
Keep phone numbers or alternate contact methods where company policy allows them. A contact list buried in the same unavailable mailbox does not help.
Use the system to support the plan, not become the plan
COI Compass can keep certificate versions, renewal reminders, and upload activity in a shared subcontractor record. Subcontractors can send documents through a no-account link, and the software drafts ACORD 25 fields for review. That gives an authorized backup reviewer a shared starting point.
The software is still only one component. The company remains responsible for continuity planning, access decisions, backups required by its policy, staff training, and the contract review. A software login does not replace a communications plan, payroll continuity, project recovery steps, safety procedures, or vendor coordination.
Document the dependencies around the COI process. If the backup reviewer can see the record but cannot reach the subcontractor, producer, project manager, or contract owner, the workflow stops at the screen.
Run a short drill with the usual reviewer unavailable
Pick one active job. Ask the usual reviewer to observe but not assist.
Give the backup reviewer a clear scenario: the office network is unavailable, a subcontractor's listed expiration date is approaching, and a revised document was expected yesterday. Ask the backup to locate the record, identify the latest received version, explain the open item, find the approved contact, and record the next action.
Note every point where the backup has to guess or request access. Fix those gaps, then run the drill again after roles or systems change.
The result should be modest and testable. One authorized person can find the evidence, understand the history, and continue the follow-up. That is a useful COI continuity check, and it fits inside the broader business continuity plan where it belongs.