Construction Third Party Risk: The COI Gap GCs Miss | Billy

Third Party Risk Is Construction’s Fastest Growing Liability | Billy
Risk Management · July 2026

Third Party Risk Is Construction’s
Fastest Growing Liability.
Here’s What GCs Can Control.

87% of executives say third party risk matters more today than it did three years ago. In construction, that risk has a name everyone already knows.

Billy Team · 7 min read · COI Compliance & Vendor Risk
87% of executives say third party risk is growing · Deloitte 2025
$14.82M average cost of noncompliance · Ponemon Institute
0% of exposure transfers when a COI alone is all you have on file

The subcontractor whose COI expired two weeks ago. Nobody flagged it. Then a claim came in.

That’s the construction version of third party risk and according to a new report from the Rochester Business Journal featuring a risk management consultant, a construction attorney, and an insurance partner, most businesses still aren’t managing it well enough.

The three professionals agreed on something every GC should hear:

When you outsource a function, you don’t always outsource the risk.

Mark S. Verdi, CIC · Partner, Lawley

That’s the operating reality for every general contractor managing a subcontractor network. The sub carries the liability on paper. But when a claim comes in, you’re in the room too.

Risk Consultant
Kirsten Shepard, CIC, CRM, CISR Elite
OneGroup
Construction Attorney
Lauren R. Mendolera
Harter Secrest & Emery
Insurance Partner
Mark S. Verdi, CIC
Lawley
▶ Watch Understanding Risk Transfer in Construction — Why Contracts and COIs Must Work Together

Risk transfer only works when the contract language, insurance requirements, and COI verification are all aligned. Billy automates the verification side so nothing falls through.


The Problem Is Bigger Than a Missing Certificate

Certificates of insurance are the standard mechanism for proving a subcontractor is covered. But relying on them alone is one of the most common risk management mistakes in construction.

Construction attorney Lauren R. Mendolera identifies the core flaw: a certificate of insurance is not legally binding on the insurer. It can be generated by a broker and doesn’t guarantee the underlying policy is active, accurate, or sufficient for your contract requirements.

What actually protects you:

  • Reviewing policy endorsements, not just the certificate face page
  • Verifying additional insured status is on the policy, not just requested
  • Tracking active coverage continuously, not only at contract signing
  • Periodically reassessing vendors for compliance, safety performance, and claims history
  • Signed contracts establishing minimum insurance requirements before work begins

That last point matters more than most GCs realize. Mendolera notes that many cyber liability policies only extend coverage to a third party vendor storing your data if you have a signed contract in place. Without it, there’s a coverage gap and in construction, informal vendor relationships are still common.

This is where vendor prequalification becomes the first line of defense. Getting contracts and compliance requirements in place before day one of work is not overhead. It’s protection.


Construction Is Uniquely Exposed

The construction industry faces a compounding version of this problem. A single commercial project may involve a general contractor, five to twenty subcontractors, specialty trades, material suppliers, and equipment lessors, each carrying their own insurance programs and each representing a potential gap.

Risk consultant Kirsten Shepard puts it plainly: a single vendor failure can disrupt operations, damage reputation, and trigger downstream liabilities across every party in the chain.

Never does the roofer just sue the subcontractor. He always sues the contractor and the owner, and then everybody fights over liability.

Lauren R. Mendolera · Harter Secrest & Emery

Courts are increasingly willing to draw multiple parties into claims even when responsibility is indirect. A roofing sub’s incident doesn’t just expose the roofing sub. It exposes the GC, the owner, and anyone with a contractual relationship to the work.

This dynamic is part of what’s driving the rise of nuclear verdicts in construction. Aggressive litigation strategies are built around spreading liability across every party who didn’t have airtight documentation.

For GCs managing 50, 100, or 200+ active vendors, tracking this exposure manually is a systemic risk, not just an operational inconvenience.


Cyber Liability Is Now a COI Requirement and Most Subs Don’t Know It

One of the fastest growing compliance gaps in construction contracts is cyber liability coverage. As more project data moves to cloud platforms, BIM models, and connected jobsite technology, subcontractors handling sensitive data are increasingly required to carry cyber coverage.

The problem: most subs either don’t have it, don’t know it’s required, or don’t understand that a COI without a signed vendor contract may not trigger the coverage at all.

Manual COI review, scanning a PDF for GL, WC, and auto limits, typically misses cyber liability entirely. It’s buried in endorsements, not on the face page. A reviewer focused on headline numbers won’t catch it.

Billy’s AI Review Assistant reads the entire certificate including endorsements and flags cyber liability gaps against your contract requirements automatically. No manual PDF review required.


What Best in Class Vendor Risk Management Looks Like in 2026

The risk professionals quoted in the RBJ piece are aligned on what actually works. Here’s how it maps to construction COI compliance:

1

Contractual risk transfer before work begins

Every subcontract should establish minimum insurance requirements, including GL, WC, auto, professional liability, and cyber, before a worker steps on site. Prequalify subs on insurance strength, not just price and schedule.

2

Verify the policy, not just the certificate

Require additional insured endorsements and waivers of subrogation and verify they’re on the actual policy. A certificate listing your company as additional insured means nothing if the endorsement isn’t there.

3

Track coverage continuously, not at contract signing

Sub renewals happen on their schedule, not yours. A COI that was current in March may be expired in August. Compliance needs monitoring throughout the project lifecycle. Automated expiration tracking closes this gap.

4

Connect compliance to payment

The most effective enforcement mechanism a GC has is payment. If a sub’s coverage is lapsed, their payment should be on hold until it’s current. This requires compliance status and accounting to talk to each other, which is exactly what Billy’s integrations with Procore and Sage 300 enable.

5

Build the audit trail

Nuclear verdicts and aggressive litigation mean your documentation is your defense. Every COI collected, every expiration tracked, every follow up sent: it needs to be logged, searchable, and defensible. Not living in someone’s email.


The Gap Between “We Track COIs” and “We’re Protected”

Most GCs have some version of a COI process. The gap isn’t awareness. It’s execution at scale.

When you’re managing 50 subcontractors across 10 active projects, manual tracking means:

Without a compliance system With Billy
Renewals discovered after expiration Automated alerts 30, 60, 90 days out
Cyber liability gaps nobody caught AI flags missing coverages including cyber
Payment holds happen after the fact Compliance gates trigger automatically
Audit prep takes days across 3 systems Audit ready dashboard, always current
No defensible trail if a claim comes in Complete, searchable documentation history

Billy’s AI Review Assistant reads COI documents, extracts coverage types and limits, flags gaps against your contract requirements, and sends automated follow ups to subs without anyone manually reviewing a PDF. Compliance status syncs to Procore, Sage 300, Sage Intacct, and Viewpoint Vista, connecting your projects, your accounting, and your compliance in one place.

When your risk management consultant says don’t rely solely on certificates of insurance, Billy is the system that operationalizes that advice.



Ready to close the gap?

See how Billy automates COI compliance and vendor prequalification.

Used by GCs managing 50 to 500+ subcontractors. Integrates with Procore, Sage 300, Sage Intacct, Viewpoint Vista, and more.

COI Compliance Third Party Risk Subcontractor Management Vendor Prequalification Construction Insurance Risk Management Cyber Liability AI in Construction

Sources

Rochester Business Journal, “Third party risk grows as businesses expand vendor networks,” June 24, 2026. Quotes from Kirsten Shepard (OneGroup), Lauren R. Mendolera (Harter Secrest & Emery), and Mark S. Verdi (Lawley).

Deloitte Third Party Risk Management Survey, 2025. Ponemon Institute Cost of Noncompliance Report.

Similar Posts