Third Party Risk Is Construction’s
Fastest Growing Liability.
Here’s What GCs Can Control.
87% of executives say third party risk matters more today than it did three years ago. In construction, that risk has a name everyone already knows.
The subcontractor whose COI expired two weeks ago. Nobody flagged it. Then a claim came in.
That’s the construction version of third party risk and according to a new report from the Rochester Business Journal featuring a risk management consultant, a construction attorney, and an insurance partner, most businesses still aren’t managing it well enough.
The three professionals agreed on something every GC should hear:
When you outsource a function, you don’t always outsource the risk.
Mark S. Verdi, CIC · Partner, LawleyThat’s the operating reality for every general contractor managing a subcontractor network. The sub carries the liability on paper. But when a claim comes in, you’re in the room too.
Risk transfer only works when the contract language, insurance requirements, and COI verification are all aligned. Billy automates the verification side so nothing falls through.
The Problem Is Bigger Than a Missing Certificate
Certificates of insurance are the standard mechanism for proving a subcontractor is covered. But relying on them alone is one of the most common risk management mistakes in construction.
Construction attorney Lauren R. Mendolera identifies the core flaw: a certificate of insurance is not legally binding on the insurer. It can be generated by a broker and doesn’t guarantee the underlying policy is active, accurate, or sufficient for your contract requirements.
What actually protects you:
- Reviewing policy endorsements, not just the certificate face page
- Verifying additional insured status is on the policy, not just requested
- Tracking active coverage continuously, not only at contract signing
- Periodically reassessing vendors for compliance, safety performance, and claims history
- Signed contracts establishing minimum insurance requirements before work begins
That last point matters more than most GCs realize. Mendolera notes that many cyber liability policies only extend coverage to a third party vendor storing your data if you have a signed contract in place. Without it, there’s a coverage gap and in construction, informal vendor relationships are still common.
This is where vendor prequalification becomes the first line of defense. Getting contracts and compliance requirements in place before day one of work is not overhead. It’s protection.
Construction Is Uniquely Exposed
The construction industry faces a compounding version of this problem. A single commercial project may involve a general contractor, five to twenty subcontractors, specialty trades, material suppliers, and equipment lessors, each carrying their own insurance programs and each representing a potential gap.
Risk consultant Kirsten Shepard puts it plainly: a single vendor failure can disrupt operations, damage reputation, and trigger downstream liabilities across every party in the chain.
Never does the roofer just sue the subcontractor. He always sues the contractor and the owner, and then everybody fights over liability.
Lauren R. Mendolera · Harter Secrest & EmeryCourts are increasingly willing to draw multiple parties into claims even when responsibility is indirect. A roofing sub’s incident doesn’t just expose the roofing sub. It exposes the GC, the owner, and anyone with a contractual relationship to the work.
This dynamic is part of what’s driving the rise of nuclear verdicts in construction. Aggressive litigation strategies are built around spreading liability across every party who didn’t have airtight documentation.
For GCs managing 50, 100, or 200+ active vendors, tracking this exposure manually is a systemic risk, not just an operational inconvenience.
Cyber Liability Is Now a COI Requirement and Most Subs Don’t Know It
One of the fastest growing compliance gaps in construction contracts is cyber liability coverage. As more project data moves to cloud platforms, BIM models, and connected jobsite technology, subcontractors handling sensitive data are increasingly required to carry cyber coverage.
The problem: most subs either don’t have it, don’t know it’s required, or don’t understand that a COI without a signed vendor contract may not trigger the coverage at all.
Manual COI review, scanning a PDF for GL, WC, and auto limits, typically misses cyber liability entirely. It’s buried in endorsements, not on the face page. A reviewer focused on headline numbers won’t catch it.
Billy’s AI Review Assistant reads the entire certificate including endorsements and flags cyber liability gaps against your contract requirements automatically. No manual PDF review required.
What Best in Class Vendor Risk Management Looks Like in 2026
The risk professionals quoted in the RBJ piece are aligned on what actually works. Here’s how it maps to construction COI compliance:
Contractual risk transfer before work begins
Every subcontract should establish minimum insurance requirements, including GL, WC, auto, professional liability, and cyber, before a worker steps on site. Prequalify subs on insurance strength, not just price and schedule.
Verify the policy, not just the certificate
Require additional insured endorsements and waivers of subrogation and verify they’re on the actual policy. A certificate listing your company as additional insured means nothing if the endorsement isn’t there.
Track coverage continuously, not at contract signing
Sub renewals happen on their schedule, not yours. A COI that was current in March may be expired in August. Compliance needs monitoring throughout the project lifecycle. Automated expiration tracking closes this gap.
Connect compliance to payment
The most effective enforcement mechanism a GC has is payment. If a sub’s coverage is lapsed, their payment should be on hold until it’s current. This requires compliance status and accounting to talk to each other, which is exactly what Billy’s integrations with Procore and Sage 300 enable.
Build the audit trail
Nuclear verdicts and aggressive litigation mean your documentation is your defense. Every COI collected, every expiration tracked, every follow up sent: it needs to be logged, searchable, and defensible. Not living in someone’s email.
The Gap Between “We Track COIs” and “We’re Protected”
Most GCs have some version of a COI process. The gap isn’t awareness. It’s execution at scale.
When you’re managing 50 subcontractors across 10 active projects, manual tracking means:
| Without a compliance system | With Billy |
|---|---|
| Renewals discovered after expiration | Automated alerts 30, 60, 90 days out |
| Cyber liability gaps nobody caught | AI flags missing coverages including cyber |
| Payment holds happen after the fact | Compliance gates trigger automatically |
| Audit prep takes days across 3 systems | Audit ready dashboard, always current |
| No defensible trail if a claim comes in | Complete, searchable documentation history |
Billy’s AI Review Assistant reads COI documents, extracts coverage types and limits, flags gaps against your contract requirements, and sends automated follow ups to subs without anyone manually reviewing a PDF. Compliance status syncs to Procore, Sage 300, Sage Intacct, and Viewpoint Vista, connecting your projects, your accounting, and your compliance in one place.
When your risk management consultant says don’t rely solely on certificates of insurance, Billy is the system that operationalizes that advice.
See how Billy automates COI compliance and vendor prequalification.
Used by GCs managing 50 to 500+ subcontractors. Integrates with Procore, Sage 300, Sage Intacct, Viewpoint Vista, and more.
Sources
Rochester Business Journal, “Third party risk grows as businesses expand vendor networks,” June 24, 2026. Quotes from Kirsten Shepard (OneGroup), Lauren R. Mendolera (Harter Secrest & Emery), and Mark S. Verdi (Lawley).
Deloitte Third Party Risk Management Survey, 2025. Ponemon Institute Cost of Noncompliance Report.