New·Issue certificates without leaving your inbox: Coily for Outlook & Gmail is live.

All news
InsightsJuly 18, 2026The Coily team

COI issuance in 2026: five trends reshaping the certificate desk.

Certificates of insurance rarely make anyone's list of exciting insurance topics, right up until a desk drowns in them, or one goes out wrong. Here are the five trends we watch most closely, and what each one means for the people actually issuing.

1. Volume only moves in one direction

Contractual risk transfer has become the default way American businesses manage third-party risk. Leases demand certificates. General contractors demand them from every sub. Vendor-management programs demand them annually, per location, per project. Every one of those demands lands on an agency service desk as another request, and unlike policies, certificates renew constantly, informally, and on someone else's deadline. Agencies we talk to describe certificate work as the single largest block of repetitive service time on the desk, and none of them expect it to shrink.

What it means: a workflow that costs twenty minutes per certificate doesn't scale linearly; it scales into overtime, backlog, and rushed review. The desk needs the per-certificate cost to collapse without the checking collapsing with it.

2. Holders are stricter than they used to be

The certificate holder side of the market has industrialized. Property managers, GCs, and lenders increasingly run third-party compliance programs, and those programs don't skim a certificate, they parse it. Requests now routinely name specific endorsement forms (CG 20 10 and CG 20 37 for ongoing and completed operations), demand primary and non-contributory wording, and bounce certificates that don't match to the letter.

What it means: "close enough" certificates come back. The requirement isn't just to issue fast; it's to issue exactly what was asked, backed by what the policy actually says.

3. Tracking industrialized; issuance didn't

Over the past decade a whole software category grew up around COI tracking: the inbound problem of collecting and checking certificates from vendors. The issuance side, where agencies produce certificates, mostly stayed where it was: retype the request into a management system, eyeball the policy, generate the form. The asymmetry is striking: the party receiving the certificate often has better software than the party whose license is on it.

What it means: the issuing desk is the underserved side of the market, and the gap between a parsed, machine-checked request and a hand-typed response is where errors live.

4. AI has reached the service desk, with a caveat

Extraction is now genuinely good: modern AI reads a rambling certificate request and pulls the holder, provisions, and limits more reliably than a rushed human skim. But extraction is the easy half. An extracted requirement still has to be verified against the policy: the endorsement forms, the current limits, the effective dates. AI that reads but doesn't verify just produces wrong certificates faster.

What it means: the question to ask any AI certificate tool isn't "can it read the email?" It's "what happens between the reading and the issuing?" If the answer isn't a check against the policy record, the speed is borrowed against the agency's E&O.

5. Provability is becoming table stakes

When a certificate is questioned (by a holder, a carrier auditor, or an E&O defense attorney), the question is always the same: what did the policy say when you issued this? Desks that can answer with a record win those conversations quickly. Desks that answer with a reconstruction don't. Expectations here are rising the same way they rose for audit trails in every other regulated workflow.

What it means: every issued certificate should carry its own evidence (the policy state it was issued from and the checks it passed), captured at issuance, not assembled later.

Where Coily sits

We built Coily as a direct answer to all five: AI reads the request in the inbox, FormLock verifies every provision against the policy's actual endorsement forms before anything is issued, ambiguity routes to a licensed human, and every certificate ships with a tamper-evident Verification Report. Fast, strict, and provable, because the trends all point the same direction.

See how Coily works.

A certificate request becomes a verified, provable ACORD 25, in one unbroken flow.