Skip to content
Case studiesPricingSecurityCompareBlog

Europe

Americas

Oceania

Compliance12 min read

Fake Certificates of Insurance: How US Firms Detect Fraud

How US general contractors detect fake certificates of insurance from subcontractors, from forged ACORD 25 forms and cloned agent emails to fake policy numbers.

CheckFile Team
CheckFile Teamยท
Illustration for Fake Certificates of Insurance: How US Firms Detect Fraud โ€” Compliance

Summarize this article with

A certificate of insurance โ€” almost always the industry-standard ACORD 25 form โ€” is one page, produced by an agent in minutes, and it is the single document most general contractors treat as sufficient proof that a subcontractor carries the required coverage. That trust is exactly what makes it a soft target: no public database lets a project owner check a certificate's policy number and limits against the carrier's own records in real time. This article covers the certificate itself โ€” how the carrier name, policy number, limits, expiration date and agent letterhead get fabricated or altered on an ACORD 25, and how a risk team catches it โ€” not vendor tax and licensing paperwork, which our guide to forged compliance certificates in supplier onboarding already covers, or the wider subcontractor documentation obligations in our subcontractor compliance guide.

What a Genuine Certificate of Insurance Actually Proves

A certificate of insurance confirms that a policy existed, with stated limits, at the moment the agent issued the ACORD 25 form โ€” nothing more. The International Risk Management Institute defines a certificate of insurance as evidence that certain coverages and limits have been purchased, explicitly not a contract in itself and no guarantee that the underlying policy will still be in force when a claim arises (IRMI, Certificate of Insurance), a limitation ACORD's own form states directly by disclaiming any rights beyond what the actual policy provides. That distinction matters for fraud detection: a certificate can be entirely genuine on the day a general contractor files it and still misrepresent the subcontractor's position months later if the policy lapses, is cancelled for non-payment, or is amended without a new certificate being sent. Forgery is a different problem again โ€” a document that misrepresents the carrier, the policy, or the limits from the outset, produced to pass an onboarding check rather than to summarize a real placement.

Six Ways Fraudsters Forge an ACORD 25 Certificate

Forged certificates fall into a small number of recurring patterns because the goal is passing a document review, not producing a legally binding record. A fabricated carrier name is the crudest version โ€” an invented company, or a genuine carrier's name misspelled just enough to survive a quick read but fail a search of the state Department of Insurance's licensed-company lookup. A fake or reused policy number follows the same logic: it looks plausible but returns no match, or matches a different policyholder, when the carrier is asked to confirm it against its own book of business.

Altered coverage limits and expiration dates are the most common edits because they require changing only a few characters in an otherwise real-looking layout โ€” a $1 million general liability limit typed over as $2 million, or an expiration date pushed back six months on a certificate that actually lapsed at renewal. Cloned agent letterhead and spoofed sender domains extend the same tactic to the document's provenance: a logo copied from a genuine agency, sent from an email domain one character removed from the real one, so a distracted reviewer reads the name and not the address. A missing or fabricated "additional insured" endorsement is a sixth pattern specific to construction: the certificate lists the general contractor as an additional insured, but no endorsement was ever filed with the carrier, so the protection the GC believes it has does not exist. The last category is the doctored PDF itself โ€” text layers edited directly, which is why mismatched fonts, inconsistent kerning, or a certificate that looks like a rescanned photocopy of an edited file are frequently the first visible tell.

Manual document review across all fraud types catches only around 37% of cases, with a median detection delay of 87 days, according to the ACFE's 2024 Report to the Nations (ACFE, 2024 Report to the Nations) โ€” long enough for a forged certificate to sit unchallenged through an entire bidding cycle and well into an active jobsite before anyone checks it against the carrier.

Red Flags in a Suspect Certificate of Insurance

The strongest indicators sit in fields a fraudster edits under time pressure, not in the document's overall visual polish, since a competent forger can make a certificate look professional while still leaving inconsistencies in the details that matter.

Field What forgers typically alter How to check it
Carrier name Invented company, or a real carrier's name misspelled slightly Search the exact name on the state Department of Insurance's licensed-company database
Policy number Fabricated format, or a number reused from a different policyholder Call the carrier directly and ask it to confirm the number against the named insured
Coverage limits Inflated general liability or workers' compensation limits typed over the original figure Request the policy's declarations page from the carrier, not a re-sent certificate
Additional insured status GC listed as additional insured with no matching endorsement actually on file Ask the carrier to confirm the endorsement number, not just the certificate's holder line
Expiration date Pushed back to appear current when the real policy has lapsed Cross-check against the carrier's own renewal records, not the certificate date
Agent/broker letterhead Cloned logo and layout, sender domain one character off the genuine agency Call the agency using a number sourced independently, never one printed on the certificate
Document formatting Mismatched fonts, inconsistent kerning, or scan artifacts on an edited PDF Compare against a previous certificate from the same agency for the same subcontractor

Ready to automate your checks?

Free pilot with your own documents. Results in 48h.

Request a free pilot

How to Verify a Certificate Rather Than Trust It

Verification means confirming the certificate's contents with a party who has no reason to lie about them, not re-reading the document more carefully. Three channels are commonly available, and they differ sharply in speed and how well they scale across a large subcontractor base.

Verification method Speed Reliability Best suited to
Call the carrier directly (using an independently sourced number, not the agent) Minutes High, if the contact number is verified independently first Occasional onboarding, high-value subcontracts
Written confirmation or a declarations page from the carrier 1โ€“3 days High, and provides an auditable record Formal prequalification files, audit trail requirements
Third-party COI tracking or verification platform Near real-time once integrated High for renewal and lapse monitoring; still requires an initial source-verified upload Portfolios of dozens to hundreds of subcontractors

Every state maintains its own Department of Insurance, and the NAIC's directory covers licensed regulators across all 50 states plus DC and several US territories, giving a general contractor a starting point to confirm which office to call (NAIC, State Insurance Departments). A phone number printed on the certificate itself proves nothing: a fraudster who fabricates the document can just as easily staff the number that appears on it.

Regulatory Exposure: A State-by-State System, Not a Single Federal Regulator

Accepting a forged certificate does not just leave a general contractor exposed on paper โ€” it can trigger fraud statutes and licensing consequences that vary by state, because unlike the United Kingdom's single Financial Conduct Authority, the United States has no federal insurance regulator at all.

The McCarran-Ferguson Act of 1945 assigned insurance regulation to the states rather than the federal government, so each state's Department of Insurance licenses carriers, investigates fraud, and enforces its own insurance code, with no national equivalent to a single FCA a contractor can check (Congressional Research Service, Introduction to Financial Services: Insurance). The NAIC coordinates the state regulators and maintains model laws such as the Insurance Fraud Prevention Model Act, but it has no enforcement power of its own โ€” investigating and prosecuting a specific certificate sits entirely with the state where the fraud occurred (NAIC, Insurance Fraud).

New Jersey illustrates how far state statutes reach: under its Insurance Fraud Prevention Act, presenting a certificate containing false or misleading information carries civil and administrative penalties of up to $5,000 for a first violation and $15,000 for each violation after the second, written specifically because contractors so routinely present certificates as proof of coverage on bids (New Jersey Department of Banking and Insurance). Criminal exposure runs alongside the civil route elsewhere: California's Department of Insurance has prosecuted contractors under state forgery and theft statutes for fabricating certificates to win jobs, arraigning one Santa Clarita-area contractor on 21 felony counts (California Department of Insurance, news release). A separate, often overlooked exposure sits in workers' compensation: if a subcontractor's coverage has lapsed or was never real, liability for an on-site injury in most states flows up to the general contractor, treated as the statutory employer and made to cover costs the forged certificate implied were already insured.

Where Certificate Checks Fit Into Wider Vendor Prequalification

Certificate verification rarely happens in isolation on well-run construction and industrial contracts โ€” it sits inside a broader prequalification standard a subcontractor must pass before it is invited to bid at all. ISNetworld and Avetta, the two largest contractor-prequalification networks used across North American construction, oil and gas, and industrial facilities, collect a subcontractor's certificates alongside safety and financial records and check them against the hiring client's specific insurance requirements before granting approved-vendor status (Billy, Billy vs. ISNetworld vs. Avetta). Approval at onboarding is not sufficient on its own, though: it is a point-in-time assessment, and a certificate submitted months later for a specific project still needs its own check against the carrier, particularly on long-running agreements where the original approval may have lapsed.

What to Do When a Certificate Looks Wrong

Pause onboarding or payment for that subcontractor before raising the concern with them, since an early confrontation can prompt evidence destruction or a hastily produced second forgery that is harder to disprove. Contractors on trade forums often ask whether calling the number printed on a certificate counts as verification โ€” it does not, since that number is exactly what a fraudster controls; the only reliable route is a carrier contact sourced independently, through the NAIC's state directory or a previous, trusted communication. A related question is what happens if a certificate was genuine when submitted but the policy lapsed mid-project unnoticed โ€” periodic re-verification, not a one-off check at onboarding, is what catches that gap.

Preserve the original file and its metadata rather than a screenshot or re-saved copy, since edit history is often the clearest evidence a PDF's text layer was altered after issue. Report confirmed forgery to the relevant state's insurance fraud bureau, reachable through that state's Department of Insurance, and notify the carrier or agency whose identity was cloned.

Building Systematic Verification Into Onboarding

Manual checking does not scale once a general contractor is managing renewals across dozens or hundreds of subcontractors, since every expiration date and every new subcontractor is another certificate needing an independent call rather than a five-second read. Platforms such as CheckFile apply structural, metadata and cross-document analysis to submitted certificates, flagging inconsistent fonts, edited PDF layers, and mismatches against previously seen agency templates. CheckFile's methodology combines structural, metadata and cross-document analysis, described as high detection coverage rather than a fixed percentage, and contextual scoring keeps false-positive handling low, distinguishing an agency's legitimate template changes from genuine signs of tampering.

An additional AI-generation signal layer is deployed as a complement to those structural checks, depending on client configuration, not a replacement for verifying the policy directly with the carrier โ€” a forged policy number still has to be confirmed against the carrier's own records. For document sets where AI-generated fraud is a specific concern, see CheckFile's AI-generated document detection, used alongside the checks above rather than instead of them.

For the construction and industrial sector specifically, see CheckFile's solutions for construction and BTP. Teams can review CheckFile's security architecture or get in touch to discuss a subcontractor base, and the document compliance guide sets out the wider framework this fits into.

Frequently Asked Questions

How can I tell if a certificate of insurance is forged without contacting the carrier?

Visual checks alone are unreliable: mismatched fonts, inconsistent formatting, or a certificate that looks like a rescanned copy are useful clues but not proof. The only conclusive check is confirming the carrier, policy number and limits directly, through a number sourced independently rather than one printed on the document.

Does a certificate of insurance guarantee the coverage is still active?

No. A certificate reflects the policy's status at the moment it was issued and carries no guarantee that the policy remains in force, according to IRMI's definition of the document. A policy can lapse, be cancelled for non-payment, or be amended after the certificate was sent, which is why periodic re-verification matters as much as the initial check.

What penalty applies for issuing a false certificate of insurance?

Penalties vary by state, since there is no federal insurance fraud statute covering certificates. New Jersey's Insurance Fraud Prevention Act sets civil penalties of up to $5,000 for a first violation and $15,000 for repeat violations, while other states pursue certificate forgery as felony fraud or theft.

Should a single red flag on a certificate be enough to reject a subcontractor?

Not automatically, but it should always trigger direct verification with the carrier before onboarding continues. Two or more inconsistencies on the same certificate โ€” a mismatched font alongside an unverifiable policy number, for example โ€” is reasonable grounds to pause the relationship pending confirmation from the issuing carrier.


This article is for informational purposes only and does not constitute legal, insurance, or regulatory advice. Consult an attorney or licensed insurance agent for guidance specific to your organization and state. Laws, regulations, and guidance referenced are current as of 30 July 2026 and vary by state.

Stay informed

Get our compliance insights and practical guides delivered to your inbox.

Ready to automate your checks?

Free pilot with your own documents. Results in 48h.