
By Patrick Turcotte, COO, Docutrax. Last reviewed: 10 September 2026.
A vendor insurance requirement set is the schedule of coverages, limits, endorsements and named entities a property manager requires from every third party working at a property, written into the contract before work starts. It works only when the lines match the exposure, the endorsements are actually on the vendor's policy, and the entities named are the ones that would be sued.
What should a vendor requirement set actually accomplish?
Three things, in order.
The vendor carries coverage that responds to the exposure it creates at the property. A landscaping crew, an elevator contractor and a security firm generate different claims, and a single requirement set applied to all three will be over-specified for one and under-specified for another.
The risk transfer mechanisms are on the policy, not just on the paperwork. Additional insured status, waiver of subrogation and primary and noncontributory treatment each arise from a specific endorsement on the vendor's policy. None of them follow from a contract clause or a checked box on a certificate.
The coverage reaches the entities that would actually be named in a suit. On a portfolio, that is rarely a single company. The property-owning entity, the management company and often a lender or ground lessor all appear in the chain, and an endorsement naming one of them does not reach the others.
Everything below is a way of getting those three right for the vendors a property actually uses.
Which coverage lines belong in a property management requirement set?
The baseline for most vendors is commercial general liability, business auto, workers compensation with employers liability, and umbrella or excess coverage above them. What varies is what gets added on top, and that is driven by what the vendor does on site, what it touches, and who it comes into contact with.
Line | What it is doing at a property | What the requirement should specify | |
|---|---|---|---|
Commercial general liability | Third party bodily injury and property damage from the vendor's operations, and from its completed work afterward | Occurrence form. Per-occurrence and general aggregate limits. Products-completed operations coverage carried, not just present on the declarations | |
Business auto liability | Vehicles on site, in loading areas, in garages, and driving to and from the property | Covered auto symbol 1, any auto, which is the broadest designation and inherently includes hired and non-owned autos. Where a vendor owns no vehicles, symbols 8 and 9 cover hired and non-owned autos only | |
Workers compensation and employers liability | Statutory benefits for the vendor's injured employees, and the vendor's liability to those employees, which is a separate coverage with its own limits |
| |
Umbrella or excess liability | Additional limits above the underlying general liability, auto and employers liability | Which underlying policies it sits above, and whether it follows form. A certificate carries no schedule of underlying insurance, so attachment cannot be confirmed from one | |
Crime or fidelity, with third-party coverage | Theft by the vendor's employees from the property, its residents or its tenants, which a standard crime policy written for the vendor's own losses does not reach | Third-party or client coverage explicitly, for any vendor whose staff hold keys, access codes or unaccompanied unit access | |
Contractors pollution liability | Fuel, chemicals, refrigerant, sewage, mold remediation, lead and asbestos disturbance, and pressure washing runoff | Required for the trades that actually create the exposure, rather than across the whole vendor population | |
Professional liability | Design, engineering, energy audits, environmental consulting, and any vendor whose deliverable is advice or a drawing rather than physical work | Required where the scope includes professional services, which vendor general liability policies routinely exclude by endorsement rather than in the base form | |
Cyber and technology errors and omissions | Vendors holding resident or tenant data, or connected to building systems, access control or the property management system | Required for proptech, smart-building, access control and payment-adjacent vendors, with the data types named | |
Garagekeepers | Valet and parking operators taking custody of vehicles | Required where custody actually transfers |
Two rules keep this from becoming a checklist that nobody reads. Require a line because a specific vendor category creates the exposure, not because it appeared on a template. And where a line is required, say what has to be true about it, since "cyber liability" as a bare requirement can be satisfied by a policy that excludes the exact data the vendor holds.
How should limits be set, and what does an additional insured actually recover?
This is the section most requirement sets get wrong, and the error is quiet.
The additional insured endorsements in general use cap what the insurer will pay on behalf of the additional insured. The CG 20 10 04 13, the CG 20 37 04 13 and the CG 20 38 12 19 all carry the same provision: where coverage for the additional insured is required by a contract, the most the insurer will pay on behalf of that additional insured is the amount of insurance "required by the contract or agreement" or the amount available under the applicable limits of insurance, whichever is less.
Read that in the direction it runs. The requirement is a ceiling as well as a floor. If the contract requires $1,000,000 and the vendor happens to carry $5,000,000, the additional insured's recovery under these endorsements is capped at the required $1,000,000. The extra limits the vendor bought are not reachable through the additional insured grant, whatever the certificate shows.
That changes how a limit gets set. It is not only a screening threshold for whether a vendor is acceptable. It is also the amount of the vendor's coverage the property can actually reach at claim time. Limits that were set once, across a whole vendor population, and never revisited against current claim severity in that asset class, are quietly setting the recovery ceiling for every relationship in the portfolio.
Two related points. Aggregate limits are shared across everything the vendor does for everyone, so a general aggregate that looks adequate on a certificate may already be substantially eroded by claims elsewhere. And umbrella limits only help if the umbrella actually sits above the policy in question, which a certificate cannot establish, because the form carries no schedule of underlying insurance.
Who should be named as an additional insured, and on which endorsement?
Two separate questions, and both get answered wrong routinely.
Who. The property-owning entity as it appears in the contract, the management company in its own name, and any other party the management agreement or loan documents require, which commonly includes the lender, the asset manager and a ground lessor. Each has to appear as a distinct entity. Naming "the owner and its property manager" without naming them is not something to rely on, because the scheduled forms look to the schedule entry, and a blanket entry covering whoever the contract requires has to be read on the endorsement rather than assumed. Entity accuracy is the defect most likely to survive every other check and surface at tender: a certificate naming the management company when the contract was signed by the property-owning LLC will look correct in a file for years.
Which endorsement. These are different forms doing different jobs, editions of each are in circulation side by side, and a vendor's broker will frequently send whichever one is on file.
Form | What it grants | When it fits a property vendor |
|---|---|---|
CG 20 10 04 13 | Scheduled additional insured status, only for liability caused in whole or in part by the vendor's acts or omissions or those of anyone acting on its behalf | Ongoing operations. It stops at the earlier of completion of all work on the project, a trigger that expressly excludes service, maintenance and repairs, or that portion of the work being put to its intended use |
CG 20 37 04 13 | Scheduled additional insured status for injury caused in whole or in part by the vendor's work at the scheduled location, within the products-completed operations hazard | Completed operations. A separate form, not a broader version of the CG 20 10. If completed operations matter, both are needed |
CG 20 38 12 19 | Automatic status for any person or organization the vendor is performing operations for where both agreed in writing, plus any other person or organization the vendor is required to add under that contract | Where an upstream party, such as an owner behind the management company, must also be covered |
CG 20 33 (04 13 and later editions | Automatic status for the party the vendor contracted with directly | Where only the contracting party needs status. It does not reach parties further upstream |
CG 20 11 04 13 | Status only with respect to liability arising out of the ownership, maintenance or use of "that part of the premises leased to you" | Almost never for a service vendor. This is a landlord-tenant form |
The CG 20 11 is worth naming explicitly because it arrives constantly in property management submissions. It is written for a tenant adding its landlord, it is limited to the premises leased to the named insured, and it excludes any occurrence after the named insured ceases to be a tenant along with structural alterations, new construction and demolition operations performed by or on behalf of the additional insured. A janitorial contractor that leases nothing at the property produces a grant of coverage with nothing to attach to. On a certificate, that endorsement and the correct one look identical: a tick in the ADDL INSD column.
One more thing to check rather than assume. The automatic forms are titled around a written construction agreement, while the 12 19 grant language refers to a contract or agreement. Whether a routine janitorial or landscaping service agreement triggers a particular blanket endorsement depends on that endorsement's own wording, and carrier manuscript versions vary. On service contracts, reading the endorsement is the only way to know.
Which endorsements carry the risk transfer, and what does each require?
Three mechanisms, each on the vendor's policy, each with its own conditions.
Additional insured status comes from the endorsements above. It is not conferred by the certificate holder box and it is not implied by an indemnity clause. Indemnity and additional insured status are separate risk transfer mechanisms that interact; an indemnity clause obligates the vendor to answer for liability, it does not obligate the vendor to add anyone to its policy.
Waiver of subrogation runs in the direction that is easiest to state backwards. The vendor's insurer gives up its right to recover from your organization after it pays a claim. It is an endorsement on the vendor's policy. The general liability waiver and the workers compensation waiver are separate endorsements on separate policies and must never be treated as one. The CG 24 04 waives the general liability carrier's right of recovery against the scheduled person or organization, and the edition decides the scope: the 05 09 edition ties the waiver to injury or damage arising out of the named insured's ongoing operations, or its work done under a contract with that person or organization and falling within the products-completed operations hazard, while the 12 19 edition drops that limitation and instead applies only to the extent the named insured waived its own right of recovery, and only where it did so before the loss. The NCCI WC 00 03 13 waives the workers compensation carrier's right in narrower terms: "We will not enforce our right against the person or organization named in the Schedule," and it adds that "This agreement shall not operate directly or indirectly to benefit anyone not named in the Schedule," applying only to the extent the insured performs work under a written contract requiring it.
Primary and noncontributory treatment has two conditions, not one. Under the CG 20 01 04 13, the vendor's insurance is primary and will not seek contribution from other insurance available to the additional insured only where the additional insured "is a Named Insured under such other insurance" and the vendor "agreed in writing in a contract or agreement that this insurance would be primary and would not seek contribution from any other insurance available to the additional insured." Additional insured status alone does not produce it, and a contract clause alone does not produce it either.
How should requirements change by vendor category?
Applying one requirement set to an entire vendor population is the most common structural failure in property management compliance. It over-specifies for a window washer and under-specifies for the roofer working over an occupied lobby.
Vendor category | What drives the exposure | What to add beyond the baseline |
|---|---|---|
Janitorial, day porter, housekeeping | Unaccompanied access to units, suites and common areas. Slip and fall from wet floors. Key and code custody | Crime or fidelity with explicit third-party coverage. Completed operations, because a floor treatment is completed work. Confirm abuse and molestation is not excluded where staff enter occupied residential units |
Landscaping, snow and ice | Cell 2-2Public walkways, seasonal subcontracting, equipment and vehicle exposure, herbicide and fuel handling | Auto at symbol 1. Verify the snow subcontractor chain carries its own coverage. In Illinois, Colorado and Connecticut, check what the contract's indemnity provision can lawfully say |
Roofing, exterior, facade, hot work | Work above occupied space, water intrusion, hot work ignition, long-tail completed operations | Completed operations status via the CG 20 37, not just ongoing operations. Confirm no height limitation or classification limitation endorsement sits on the policy |
Elevator, escalator, life safety, fire | Bodily injury severity, code and inspection obligations, work that continues to matter for years | Completed operations. Professional liability where the scope includes design or engineering judgment. Higher limits driven by severity, not frequency |
HVAC, plumbing, electrical, mechanical | Water damage to occupied space, refrigerant release, energization and lockout, after-hours access | Contractors pollution for refrigerant and fuel. Completed operations. Confirm the vendor's own subcontractors are covered under its policy terms |
Security, courtesy patrol, concierge | Use of force, detention, contact with residents and the public | Assault and battery coverage confirmed rather than assumed, since it is commonly excluded or sublimited. Abuse and molestation confirmed. Employment practices where the vendor staffs the site |
Pool, spa, amenity, fitness | Chemical handling, drowning exposure, equipment supervision | Contractors pollution for chemical handling. Confirm no aquatic or recreational exclusion applies |
Pest control | Pesticide application in occupied space, sensitive occupant exposure | Contractors pollution or a pesticide applicator endorsement. Applicator licensing confirmed alongside coverage |
Valet and parking | Custody of vehicles and keys | Garagekeepers. Auto at symbol 1. Crime with third-party coverage |
Turnover, make-ready, renovation, capital projects | Structural and alteration work, subcontracted labor, longer completed operations tail, and on multifamily, the residential exclusion problem below | Completed operations, subcontractor coverage warranties reviewed, per-project structure where the contract value justifies it, and confirmation that the residential exclusion does not apply |
Proptech, access control, IT, payment | Resident and tenant data, building system access, payment flows | Cyber and technology errors and omissions with the data types and system access named |
The practical version of this is a small number of requirement sets, one per category, rather than one universal set or a bespoke set per vendor. Both extremes fail: the universal set is wrong everywhere, and the bespoke set is impossible to govern across a portfolio.
Which exclusions quietly defeat a requirement set?
A vendor can satisfy every line, limit and endorsement in the requirement set and still carry a policy that will not respond to the claim the property is most likely to face. None of this appears on a certificate, because the ACORD 25 has no field for exclusions and no endorsement schedule.
The multi-unit and tract housing residential exclusion is the one that matters most on multifamily and mixed-use assets, it is far broader than its name suggests, and it is a proprietary carrier endorsement rather than an ISO standard form, so the form number varies. As described by the Big "I" Virtual University, one carrier version of it, the CG 77 44 02 15, excludes liability arising from construction operations involving housing tracts or multi-unit residential buildings, and defines construction operations to include "pre-construction, construction, post-construction, reconstruction, renovation, remodeling, conversion of the building to a condominium, townhouse, cooperative building or any other type of multiple unit residential structure, maintenance or repair." Maintenance and repair sit inside that definition. A contractor carrying it can be fully compliant with a requirement set on paper and excluded from the routine unit turnover work it was hired to do.
Injury to employee and action-over endorsements. The standard employer's liability exclusion carries its own insured contract exception, so the standard form does not bar an upstream party's indemnity claim arising from an injury to the vendor's employee. What bars it is a broadened action-over or employee injury endorsement, or wording that strips the exception out. On New York work this is the exclusion that most often decides whether the coverage sitting behind an indemnity clause is real, because Labor Law Sec. 240 and Sec. 241 impose non-delegable duties on owners and general contractors for elevation-related work and enumerated safety violations, so liability can attach without fault on their part, and Workers' Compensation Law Sec. 11 then bars the resulting third-party claim against the employer unless the injury is a grave injury or the employer signed a written indemnification agreement before the accident.
Subcontractor warranty endorsements set minimum insurance the vendor's own subcontractors must carry and can reduce or eliminate the vendor's coverage for work where that was not met. This matters most where the vendor subcontracts routinely, which in property management means snow, specialty trades and much of turnover work.
Classification limitation endorsements restrict coverage to the operations described in the policy classifications, so work outside the classification may be uncovered. A vendor classified for janitorial work that also does light maintenance is the everyday version of this.
Contractual limitation endorsements remove the contractual liability coverage that makes an assumed indemnity obligation insurable, which can hollow out the indemnity clause the requirement set was built around.
Abuse and molestation exclusions are worth a specific check for any vendor whose staff enter occupied residential units or work around minors. The perpetrator need not be an insured for the exclusion to apply, and the CG 21 46 form reaches negligent employment, investigation, supervision, retention, and reporting to the proper authorities or failure to report.
Checking for these is endorsement-level and sometimes policy-level work. It is not proportionate across an entire vendor population, and it is clearly proportionate for the categories where the exclusion maps directly onto what the vendor was hired to do.
Where does state law limit what a property manager can require?
Requirements are contract terms, and contract terms are subject to state law. Three areas come up repeatedly on property portfolios.
Snow and ice removal indemnity is void in some states, in both directions. Illinois is the clearest. Under 815 ILCS 675/10, a provision in a snow removal and ice control services contract is "against public policy and void" if it requires the service provider to indemnify the service receiver for damages resulting from the receiver's acts or omissions, and equally if it requires the service receiver to indemnify the service provider for the provider's own. The same section voids hold harmless and defense provisions running each way. Connecticut reaches a narrower result at Sec. 21a-433, voiding a provision requiring the provider to indemnify the receiver for acts the provider was not required to perform or was instructed not to perform, or to hold the receiver harmless for tort liability resulting from the receiver's own acts or omissions, in each case only where the contract prohibits the provider from mitigating a specific snow, ice or other mixed-precipitation event or risk, and excepting contracts performed on municipal or state-owned roadways or property. Colorado, at C.R.S. 13-21-129, voids indemnity, hold harmless and defense provisions in both directions on the same mitigation condition Connecticut applies, and other states have taken up the question. A requirement set that assumes a snow contractor's indemnity will hold, everywhere, is assuming something several states have expressly legislated against.
Anti-indemnity statutes reach building maintenance and repair, not only new construction. New York's General Obligations Law Sec. 5-322.1 voids an agreement, in connection with construction, alteration, repair or maintenance of a building, purporting to indemnify the promisee against liability "contributed to, caused by or resulting from the negligence of the promisee, his agents or employees, or indemnitee, whether such negligence be in whole or in part." The word maintenance is what makes this a property management issue rather than a capital projects issue. Enforceability of broad form, intermediate form and limited form indemnity varies substantially by state, and the requirement set should reflect the jurisdictions the portfolio actually sits in.
Workers compensation works differently in four states. Ohio, North Dakota, Washington and Wyoming are monopolistic: employers obtain workers compensation through the state fund, and the state fund does not provide employers liability coverage. Employers liability there comes from a stop gap endorsement, attached to the general liability policy where the employer operates only within the monopolistic state, or to the workers compensation policy where it also operates elsewhere. A requirement set asking for "workers compensation and employers liability" and a reviewer looking for both on the certificate in the usual place will produce a false deficiency in those states, or worse, accept a submission with no employers liability at all.
None of this is legal advice, and application turns on the specific contract, the facts and the jurisdiction. It is a reason for the requirement set to be reviewed against the states the portfolio operates in, rather than inherited from a template written for somewhere else.
What does the certificate establish, and where does it stop?
The certificate reports. It does not prove.
The ACORD 25 states on its face that it is issued as a matter of information only, confers no rights upon the certificate holder, and does not amend, extend or alter the coverage afforded by the policies listed. The IMPORTANT paragraph is explicit that where the holder is an additional insured, the policies must have additional insured provisions or be endorsed, and that "A statement on this certificate does not confer rights to the certificate holder in lieu of such endorsement(s)." The ADDL INSD and SUBR WVD columns are representations about what the producer understands the policy to contain.
The current 2025/12 edition also changed what the limits column can be read to establish. The certification block above the coverage grid now carries an asterisked passage stating that limits shown "MAY HAVE BEEN REDUCED BY PAID CLAIMS" and are "INCLUSIVE OF AMOUNTS REQUESTED BY THE CERTIFICATE HOLDER AND MAY NOT REFLECT POLICY LIMIT AMOUNTS IN EXCESS OF THOSE REQUESTED." If a requirement is $1,000,000 and the certificate shows $1,000,000, the form itself now discloses that this may be a reflection of the request rather than the policy. The asterisk carries a footnote marking that passage not applicable in Wyoming.
This is not an argument against certificates. Certificate review is the right level of review across a large share of a vendor population, where the approved requirements and the inherent exposure do not call for deeper analysis, and doing it properly is real work. The question is whether the depth of review matches the requirements and the exposure. Where scope, jurisdiction, completed-operations exposure or potential liability warrants closer scrutiny, the certificate may not reveal exclusions or endorsement language that matters at claim time, and the endorsement pages or the policy become the proportionate next step. Our guides on reading and verifying a certificate, the ACORD 25 itself and the endorsements that carry risk transfer go through each in detail.
What does this look like as an operation across a portfolio?
Requirements only work if something repeats them at scale, across properties, across entities, and across renewal cycles.
Requirement sets are built per vendor category rather than per vendor or per portfolio, and they name endorsement forms rather than describing outcomes, because "additional insured including completed operations" is not a document anyone can send. Collection asks for the endorsement pages alongside the certificate at first submission, since asking afterward means asking twice and waiting through a second broker cycle. Review confirms the named insured against the contracting entity exactly, and confirms that every entity the contract requires appears in the endorsement schedule rather than in the certificate holder box. Monitoring re-confirms at renewal and whenever scope, entity structure or the requirement set changes. And the record is retained, because completed operations claims at a property arrive years after the vendor finished and left.
Shared vendors are where a portfolio either gains or loses. The same landscaping company working at eleven properties owned by four entities should not generate eleven unconnected reviews, and it should not generate one review that quietly ignores the fact that four different entities need to appear in the endorsement schedule.
That is the work Docutrax does on behalf of its clients. Licensed insurance professionals and CRIS-certified Account Managers review what was submitted, coordinate remediation through the vendor's broker or agent, and maintain the record across the portfolio, with more than 300,000 forensic policy reviews completed since 2017. Docutrax surfaces what the documents establish and what they do not, and escalates within the rules the client has approved. The client sets the requirements and makes the decisions.
FAQs
Quick answers
Should the owner or the property manager be the additional insured?
Both, along with any other party the management agreement or loan documents require, each named as a distinct entity. The scheduled endorsements require the names to appear in the schedule, so a certificate listing "owner and manager" generically is not evidence that either has status. Where an upstream owner also needs to be covered, an automatic form written to reach parties the vendor is required to add, such as the CG 20 38 12 19, is one route, and reading the specific endorsement is the only way to confirm it.
Does a certificate showing additional insured status mean the vendor's policy actually has it?
No. The ACORD 25 states that where the certificate holder is an additional insured, the policies must have additional insured provisions or be endorsed, and that a statement on the certificate does not confer rights in lieu of the endorsement. The tick in the ADDL INSD column tells you what the producer understands the policy to contain. The endorsement page tells you which form was issued and what it grants.
Why would requiring higher limits from a vendor matter if they already carry more?
Because the additional insured endorsements from the 04 13 editions forward pay the lesser of the amount required by the contract or the amount available under the policy. If the contract requires less than the vendor carries, the recovery available to the additional insured is capped at the required amount. The limit in the requirement set is a recovery ceiling, not only a screening threshold.
Do vendor insurance requirements still matter after the vendor finishes and leaves?
For some categories, yes, and that is exactly where requirement sets tend to be thin. Ongoing operations additional insured status under the CG 20 10 stops applying once all work on the project has been completed, a trigger that expressly excludes service, maintenance and repairs, or once that portion of the work has been put to its intended use. Completed operations status is a separate endorsement, the CG 20 37, covering injury within the products-completed operations hazard. Roofing, mechanical, elevator and renovation work all produce claims that surface after the vendor is gone.
Can a property manager require a snow removal contractor to indemnify the property?
It depends on the state. Illinois voids indemnity, hold harmless and defense provisions in snow removal and ice control contracts running in both directions. Colorado voids the same provisions in both directions where the contract prohibits the provider from mitigating a specific event, and Connecticut voids a narrower category of them on the same condition. This is one to confirm against the jurisdictions in the portfolio rather than to assume, and it is a question for counsel on any specific contract.
How much of this can be checked from a certificate alone?
The coverage lines, the policy dates, the limits as reported, and the producer's representation about additional insured status and waiver of subrogation. Not which endorsement form was issued, not what it grants, not whether an exclusion sits on the policy, and not what an umbrella attaches over. Depth should follow the exposure: certificate review across most of the population, endorsement review where the risk transfer mechanisms have to be real, and forensic policy review where scope, jurisdiction or potential liability justifies it.
Get in touch with Docutrax
Related Articles

Builders Risk Insurance: What General Contractors and Subcontractors Need to Verify
Builders risk covers the project while it is being built. Whether it also covers the subcontractor standing next to it, and when it stops, is decided elsewhere.

Waiver of Subrogation: What It Means and When It Applies
A waiver of subrogation sits on the third party's policy, not yours, and gives up their insurer's right to come after you. What it does not do is stop the injured employee from suing.

Compliance Depot Alternatives: How RealPage Vendor Credentialing Works and What Else Is Available
Compliance Depot became RealPage Vendor Credentialing in 2011. The category now holds three models that work differently, and the fastest way to tell them apart is asking who pays.

