New·Issue certificates without leaving your inbox: Coily for Outlook & Gmail is live.

All news
InsightsJuly 16, 2026The Coily team

The E&O gap hiding in your COI workflow.

Every certificate of insurance carries a sentence to the effect that it is issued as a matter of information only and confers no rights upon the holder. Teams read that as a shield. It's better read as a warning: the certificate doesn't create coverage, which means the only thing it can do is represent coverage, and the representation is yours. The policy belongs to the carrier. The certificate, and everything it asserts, belongs to your agency.

That's the whole E&O exposure in one sentence. A certificate is your written statement about what someone else's policy says, produced dozens of times a day, usually under time pressure. When the statement and the policy disagree, the difference has your name on it.

The failure modes are boringly consistent

Ask anyone who reviews agency E&O claims and the same patterns come up. None of them are exotic.

  • The certificate outlives the policy. A cert gets issued (or worse, reissued from last year's) against a policy that has expired, been rewritten, or not yet renewed. The document looks perfect. It describes coverage that no longer exists.
  • The endorsement isn't there. The request demands additional insured status including completed operations, and the certificate says so. But ongoing-operations and completed-operations coverage live on different endorsement forms (CG 20 10 and CG 20 37 are the classic pair), and the policy carries only one of them. Checking a box in the management system asserted a form that isn't on the policy.
  • The aggregate isn't per-project. The contract assumes a per-project general aggregate; the certificate implies it; the policy was never endorsed for it. On a multi-project insured, that's the difference between a full limit and a shared, partly-eroded one.
  • Limits drift at renewal. The insured renewed with different limits or a restructured program in March. Certificates keep going out with last year's numbers because the template never got updated.

Notice what these have in common: in every case the certificate was internally flawless. The failure was the gap between the document and the policy behind it.

Volume makes it inevitable, not careless

It's tempting to file these under carelessness. That misreads the arithmetic. A busy desk handles a steady stream of requests, each one a dense page of requirements, against policies that change underneath them. A conscientious person verifying every provision against the actual forms, every time, at that volume, has been set up to fail eventually, not because they're sloppy, but because "read the endorsement schedule again" competes with a ringing phone on every single request. Manual process doesn't eliminate the error rate. It just decides the error rate slowly.

Process principles that close the gap

Whatever tooling you use, the principles are the same.

  • Verify against the policy, not the AMS checkbox. The management system records what someone once believed about the policy. The endorsement forms are the policy. Every provision a certificate asserts should trace to a form actually on file.
  • Freeze what you certified. Keep a snapshot of the policy data behind each certificate at the moment of issuance. When a question arrives months later, you want a record, not a reconstruction from memory and renewal files.
  • Route ambiguity to a licensed professional. If a requirement is unclear, or the policy doesn't obviously back it, the answer is not the most plausible checkbox; it's a human with a license and the context to decide. Speed should never be the reason an unverified provision goes out the door.

Verification-first issuance

This is why we think issuance should be verification-first: the certificate is generated from the check against the policy's forms, rather than checked after the fact, and anything that can't be verified is refused and escalated instead of asserted. Done that way, speed stops being the enemy of accuracy, because the fast path and the correct path are the same path. The certificate that goes out in seconds is the one that was verified, and the one you can prove later.

This article is educational content about common industry practices, not legal advice. Consult your own counsel and E&O carrier about your agency's exposures.

See how Coily works.

A certificate request becomes a verified, provable ACORD 25, in one unbroken flow.