Vendor Documents Required Before Work Begins

You're three days out from a major project kickoff. The subcontractor is ready, equipment is staged, and your team is scheduled. Then someone in legal asks: "Did we get their certificate of insurance?" Silence. Scrambling. Delays. It's a scenario that plays out constantly across construction sites, healthcare facilities, manufacturing plants, and property management offices — and it's almost always preventable. Understanding which vendor documents are required before starting work is the difference between a smooth project launch and a liability nightmare.

This guide breaks down exactly which documents you need to collect, why each one matters, and how to build a repeatable process that keeps your organization protected.


Why Vendor Documents Required Before Starting Work Actually Matter

Collecting vendor documents isn't a bureaucratic formality. It's a foundational risk management practice. When you bring a vendor, subcontractor, or service provider onto your site or into your workflow, you're taking on a degree of legal and financial exposure. If that vendor injures a worker, causes property damage, or fails to meet regulatory standards, the question isn't just "what happened?" — it's "did you verify they were qualified to be there in the first place?"

Regulators, courts, and insurance carriers all want to see that you exercised due diligence before work began. That means having documentation on file — not in your inbox somewhere — before the first day of work.

Beyond liability, there's a practical efficiency argument. Chasing documents mid-project is disruptive and costly. Building a front-loaded document collection process means fewer work stoppages, cleaner audits, and stronger vendor relationships built on clear expectations.


The Core Vendor Documents Required Before Starting Work

Not every project requires every document on this list, but most organizations managing vendors regularly should be collecting most of these as standard practice.

Certificate of Insurance (COI)

The certificate of insurance is non-negotiable for virtually any vendor doing work on your behalf. It confirms that the vendor carries active coverage — typically general liability, workers' compensation, and sometimes commercial auto or professional liability — and that their policy limits meet your minimum requirements.

What many compliance managers miss: a COI is a snapshot in time. A policy can lapse after you collect the certificate. That's why you also want to be listed as an additional insured on the policy and establish a system to track renewal dates proactively.

Actionable tip: Set a calendar alert or use a compliance management platform to flag COI expirations at least 30 days before they lapse. Don't wait for the vendor to remind you — they often won't.

W-9 Form

If you're paying a vendor $600 or more in a calendar year in the United States, you're required to issue a 1099. To do that, you need a completed W-9 on file before you issue payment. The W-9 confirms the vendor's legal name, business structure, and taxpayer identification number.

Collecting the W-9 at the start of the vendor relationship — not at year end — saves accounting headaches and keeps you compliant with IRS requirements.

Business Licenses and Trade Licenses

Depending on your industry and location, vendors may be required to hold specific licenses to perform certain work. A licensed electrician, a certified HVAC technician, a registered general contractor — these credentials aren't optional. They're legally required, and your organization can face penalties for hiring unlicensed vendors.

Actionable tip: Verify licenses directly through the issuing state or local licensing board when possible, rather than relying solely on a copy the vendor provides. License lookup tools are available through most state government websites and take only minutes to use.

Contractor or Vendor Agreement / Scope of Work

Before work begins, there should be a signed agreement in place that outlines the scope of work, payment terms, performance expectations, indemnification clauses, and termination conditions. A signed contract protects both parties and gives you legal recourse if performance falls short.

Don't let any work begin on a verbal agreement or a vendor's informal quote. Even a simple letter of agreement is better than nothing.

Safety Certifications and Training Records

In industries like construction, manufacturing, utilities, and healthcare, vendors often need to demonstrate that their workers have completed specific safety training. OSHA 10 and OSHA 30 certifications are common requirements on construction projects. Healthcare vendors may need to show proof of HIPAA training. Manufacturers may require PPE compliance documentation.

Actionable tip: Define your minimum safety certification requirements in your vendor onboarding checklist before you ever issue a bid or RFQ. This filters out unqualified vendors early and sets clear expectations upfront.

Background Check and Drug Screening Results

Depending on the nature of the work and the sensitivity of the environment — schools, hospitals, data centers, residential properties — you may need proof that vendor personnel have passed background checks and drug screenings. This is especially critical when vendors will have unsupervised access to vulnerable populations or secure systems.

Be aware that background check requirements vary by jurisdiction, and some states have specific rules about how this information can be used in hiring decisions. Consult your legal team to ensure your requirements are compliant.

Subcontractor or Supplier Diversity Documentation

For government contracts and many large enterprise projects in 2026, prime contractors are often required to demonstrate that they've engaged certified minority-owned, women-owned, or small business vendors. If you operate in this space, collecting supplier diversity certifications — such as SBA 8(a) designation or NMSDC certification — may be a contractual obligation before work begins.


Building Your Vendor Document Checklist: 4 Practical Steps

Knowing which documents you need is step one. Creating a consistent process to collect and manage them is where most organizations struggle.

1. Standardize Your Requirements by Vendor Type

Not all vendors carry the same risk profile. A landscaping company and a cybersecurity consultant both need a W-9, but their other required documents look very different. Build tiered document checklists based on the type of work, the risk level, and the regulatory environment. Trying to apply a one-size-fits-all list creates friction with low-risk vendors and gaps with high-risk ones.

2. Collect Documents Before Onboarding Is Complete

The leverage point in vendor relationships is before the engagement is confirmed. Make document submission a condition of being approved as a vendor. Once work has started, you've lost negotiating power and created a compliance gap. Build your vendor portal or intake form so that document upload is a required step — not an afterthought.

3. Track Expiration Dates Proactively

Documents like certificates of insurance, business licenses, and safety certifications all expire. A document that was valid when you collected it may be worthless six months later. Whether you use a spreadsheet with automated alerts or a dedicated platform like Certadox, the key is having a system that surfaces upcoming expirations before they become compliance gaps.

Actionable tip: Audit your current vendor document library quarterly. Even if you have a great intake process, expired documents accumulate quickly in active vendor relationships.

4. Create a Paper Trail for Every Document Decision

If your organization is ever audited, sued, or subject to a regulatory review, you need to be able to show what you collected, when you collected it, and who approved it. Store documents in a centralized, searchable repository and log any exceptions — cases where work was approved to begin before full documentation was in place, and why.


Industry-Specific Considerations

Different industries have different baseline requirements, and it's worth customizing your checklist accordingly.

General contracting and construction: COI with specific liability minimums, OSHA certifications, contractor's license, lien waiver agreements, and subcontractor agreements are standard. Many general contractors also require proof of workers' comp classification codes that match the work being performed.

Property management: Vendor COI naming the property owner as additional insured, business license, contractor's license, and a signed vendor agreement are typically required before any maintenance or renovation work begins.

Healthcare: Vendors accessing patient care areas or sensitive data may need HIPAA compliance documentation, background check results, immunization records, and credentialing verification depending on their role.

Government contracting: Prevailing wage certifications, SAM.gov registration, small business certifications, and security clearances may all be relevant depending on the contract scope.


How Compliance Platforms Support Document Management

Managing vendor documents manually — via email, shared drives, or spreadsheets — works until it doesn't. As your vendor list grows, the risk of a missed expiration or lost document grows with it. Platforms designed specifically for vendor compliance, like Certadox, centralize document collection, automate expiration tracking, and give compliance teams a single source of truth for audit readiness.

The value isn't just efficiency. It's the ability to demonstrate, at any moment, that your vendor compliance program is functioning — not just documented on paper but actively managed.


Frequently Asked Questions

What happens if a vendor starts work without providing required documents?
You've created a compliance gap and a potential liability exposure. If an incident occurs before documents are collected — especially insurance — you may find that coverage is disputed or that your organization is held responsible for damages. Stop work until documentation is in place, and document the gap and how it was resolved.

How long should you retain vendor documents?
Retention requirements vary by document type and jurisdiction, but a common best practice is to retain vendor documents for at least seven years after the end of the vendor relationship. Tax-related documents like W-9s should follow IRS retention guidelines. Check with your legal counsel for industry-specific rules.

Can you accept digital copies of vendor documents?
Yes, in most cases digital copies are acceptable. What matters is authenticity and legibility. For high-stakes documents like licenses, you may want to verify directly with the issuing authority rather than relying solely on a scanned copy.

What's the difference between a vendor agreement and a purchase order?
A purchase order is a transactional document for a specific order of goods or services. A vendor agreement (or master services agreement) is a broader contract governing the overall relationship, including liability, indemnification, and compliance obligations. For ongoing vendor relationships, you typically want both.


Bottom Line

Getting the right vendor documents required before starting work isn't just about checking boxes — it's about protecting your organization, maintaining regulatory compliance, and setting clear expectations with every vendor you work with. Build a standardized checklist, collect documents before work begins, and create a system to track expirations proactively. A little structure on the front end prevents significant headaches — and potential liability — down the road.

Ready to get vendor compliance under control?

Start your free trial and see how Certadox tracks COIs, licenses, and credentials automatically.