TL;DR: A fake certificate of insurance is either a genuine ACORD 25 edited after the agent issued it (dates pushed out, limits inflated) or a certificate generated from a blank template for a policy, carrier, or agent that does not exist. The form itself is "issued as a matter of information only and confers no rights," so the only proof of coverage is the carrier or agent confirming the policy through a contact you sourced yourself. The Coalition Against Insurance Fraud puts U.S. insurance fraud at $308.6 billion a year, including an estimated $25 billion in employers dodging workers' compensation premiums, the pressure behind most forged COIs.
A Certificate of Insurance Is a Snapshot, Not a Policy
A certificate of insurance is a one-page summary, almost always on the ACORD 25 form, that an agent or broker issues to say a policy was in force for a named insured on the day the certificate was printed. It is not the policy. The preprinted disclaimer on the current ACORD 25 (2025/12) edition filed with the New York Department of Financial Services reads: "This certificate is issued as a matter of information only and confers no rights upon the certificate holder." Additional insured status lives in an endorsement to the policy, not on the certificate.
That is why a COI is so easy to fake and so widely relied upon. Vendor onboarding, commercial leases, lending covenants, construction bids, freight brokerage, and fleet onboarding all ask for one and rarely for anything behind it. A fake certificate asserts coverage that has lapsed, exists at lower limits, covers a different entity, or was never bound. Do not confuse it with a certificate of incorporation, which a Secretary of State issues to prove an entity exists; a COI proves nothing about the entity.
Two production paths cover most fakes. Edited-after-creation starts with a real certificate, usually the insured's own expired one, and changes a handful of characters: the expiration date moves forward a year, $1,000,000 becomes $2,000,000, the certificate holder box is retyped. Generated-from-scratch starts with the public blank ACORD 25 PDF and fills in a plausible carrier, a policy number in roughly the right format, and an agency that is real but uninvolved. The California Department of Insurance's case against a Santa Clarita plumbing contractor is the template: ten certificates over two years, each with false coverage information and a licensed agent's forged signature, used to win jobs and permits. The case opened when the real agent saw a certificate in his name that he never issued.
Tells That Still Work, and the Ones That Don't
Layout tells are weak because the layout is standardized and every forger has a real ACORD 25 to copy. The tells that survive connect the certificate to records outside the document.
The strongest tell is who sent the file. A certificate that arrives from the vendor rather than the vendor's agent has passed through the one party with a motive to change it. The Coalition Against Insurance Fraud's workers' compensation task force notes the inverse risk: an agent who diverts premiums "may produce fake policy documents in order to perpetuate the lie," usually including fraudulent certificates of insurance. The California case against an unlicensed agent who collected $1.4 million in premiums and issued falsified certificates for coverage that never existed unraveled when one client asked the insurer for an updated certificate and learned the policy number belonged to another business.
Verify With the Carrier, Not the Certificate
The only confirmation that counts comes from the carrier or the issuing agent, reached through a contact the certificate did not supply. Look up the producer's agency in the state insurance department's license database, take the phone number from that record or the agency's own website, and ask the certificate desk to confirm the policy number, named insured, dates, limits, and whether your organization is endorsed as additional insured. The number printed in the producer box only tests whether the forger answers the phone. An issuer who insists on email only, cannot access the policy, or is unknown to the agency named on the form has answered the question.
Two lookups sit behind that call. The NAIC Consumer Insurance Search resolves a carrier name or NAIC company code to its licensing status, and the state department of insurance confirms the carrier is admitted for that line and the producer holds an active license. Most states run a public workers' compensation coverage lookup. For motor carriers, FMCSA insurance filings can be checked against the certificate; the agency's fraud guidance to brokers and shippers puts it plainly: "Even insurance certificates can be fraudulent."
Verification is a point-in-time event, and so is the certificate. A COI genuine at onboarding says nothing about a policy cancelled three months later, which is why third-party due diligence programs that collect vendor insurance once carry the gap the certificate was meant to close.
How Detection Actually Works
Direct verification scales badly across hundreds of vendors, so the file has to earn a phone call first. Forensic review of the PDF answers six questions that separate edited-after-creation from generated-from-scratch from genuine.
Production method asks how the bytes were made. Certificates issued from agency management systems carry that software's fingerprint; a file that last passed through a desktop PDF editor or a print-to-PDF driver carries a different one. Timestamp trail asks whether the file's creation and modification history matches the date printed in the top-right corner; a creation date that predates the policy it certifies needs an explanation. Issuer matching asks whether the producer named on the form is the producer whose systems made the file, and whether it matches that agency's earlier certificates.
Consistency is the underwriting read: policy periods aligned across coverage lines, aggregates above per-occurrence limits, a workers' compensation carrier admitted where the work happens. Model artifacts asks whether a generative or image pipeline left structural traces, the same question asked of any AI-generated PDF. Recycled patterns asks whether this policy number, agency template, or exact certificate has appeared before under a different insured, which is how one forged COI becomes a serial document across a vendor population.
What to Do With a Suspect Certificate
Hold the onboarding, payment, or site access before raising it with the vendor; confronting the submitter first invites a second, cleaner forgery. Then run the independent confirmation and record who you spoke to, at what number, what they confirmed, and when. If the agent confirms the policy but not the limits or additional insured status, the certificate was edited. If the agent has no record of the insured, it was generated.
Escalate on the finding, not the feeling. "The certificate looked altered" is not a basis for a fraud referral. "The expiration field was modified after the producer's system generated the file, and the agency confirms the policy cancelled in March" is. State insurance departments accept referrals from certificate holders, and some states make the certificate itself the offense: New Jersey's Certificates of Insurance Act made presenting or demanding a certificate with false or misleading information an insurance fraud violation, with civil penalties starting at $5,000. Reject the document, not automatically the vendor, when a clean certificate does not arrive from the agent within policy time.
Break-test the control before a live case does. Check a document in the Watchdoc playground with a certificate whose history you already know. The first file is free, no email required.
Where Sphinx Fits
Sphinx reads the certificate the way a forensic examiner would, then shows the evidence. Watchdoc runs the six checks — production method, timestamp trail, issuer matching, consistency, model artifacts, and recycled patterns — and returns a verdict with the manipulated region highlighted, so the reviewer knows which field moved before calling the agent. Published figures: 94.3% correct verdict, 2.8x more forgeries caught, clean files cleared in under 28 seconds, 1 million documents processed, $0.45 per document with no seats and no platform fee. It sits alongside KYB document fraud detection, where the question for every file a counterparty hands over is the same: was this issued, or was it made? The Watchdoc playground is the same x-ray, free to try.
Frequently Asked Questions
What is a fake certificate of insurance?
A fake certificate of insurance is an ACORD 25 or similar form that misrepresents coverage: a genuine certificate edited after issue to extend dates, raise limits, or add a certificate holder, or a certificate generated from a blank template for a policy, carrier, or agent that does not exist. Because a COI confers no rights, the fraud lies in the reliance it induces.
How do I verify a certificate of insurance is real?
Contact the issuing agent or carrier using a phone number sourced from the state insurance department's license lookup or the agency's own website, never the number printed on the certificate. Ask them to confirm the policy number, named insured, dates, limits, and any additional insured endorsement. Cross-check the carrier's NAIC number in the NAIC Consumer Insurance Search.
Is a certificate of insurance the same as an insurance policy?
No. A certificate of insurance is a summary issued by an agent stating that listed policies were in force on the date shown. The ACORD 25 form states that it is issued as a matter of information only, confers no rights on the certificate holder, and does not amend or extend the policy. Coverage rights, including additional insured status, exist only in the policy and its endorsements.
Is faking a certificate of insurance a crime?
Yes. Forging or altering a certificate of insurance is prosecuted under state forgery, theft by false pretense, and insurance fraud statutes, and the California Department of Insurance has brought felony cases against contractors and unlicensed agents for it. New Jersey's Certificates of Insurance Act separately makes presenting or demanding a certificate with false or misleading information a civil insurance fraud violation.
Can an AI-generated certificate of insurance pass review?
Visually, yes. A generated ACORD 25 can carry a real carrier's name and NAIC number, a plausible policy number, and a real agency's letterhead. It fails on signals the page does not show: the file's production method, timestamp trail, model artifacts, and the agent's confirmation that no such policy exists.

.png)