---
title: "Fake COIs Are a Growth Industry. Here Is How to Actually Verify Carrier Insurance"
description: "A certificate of insurance is a document, not a verification. How forged and doctored COIs get past onboarding, what federal filings do and do not tell you, and the checks that catch what a PDF cannot prove."
author: John Nowlan
published: 2026-08-07
updated: 2026-08-07
category: Compliance
canonical: https://www.cipherandrow.com/blog/fake-coi-verify-carrier-insurance
---

# Fake COIs Are a Growth Industry. Here Is How to Actually Verify Carrier Insurance

By John Nowlan · Published 2026-08-07 · Cipher & Row Blog

A certificate of insurance is one of the most trusted documents in freight onboarding and one of the easiest to fake. That mismatch is not an accident. Fraudsters go where the trust is high and the verification is low, and a PDF that gets a carrier onboarded is worth forging.

### Key takeaways

- A COI is a snapshot document produced by an insurance producer. It is evidence that coverage existed at issuance, not proof that it exists today, and it is trivially editable by anyone with a PDF tool.

- The common forgeries are mundane: a real COI with an edited expiration date, an inflated limit, or a swapped named insured. The document looks perfect because most of it is real.

- Federal filings are an independent signal for the coverage types carriers must file, but they are not a complete picture of a carrier's insurance, so the honest approach combines filings, document forensics, and confirmation with the insurer or producer.

- Insurance is the fastest-moving credential a carrier has. Coverage that was real at onboarding can lapse the same month, which is why monitoring matters more for insurance than for almost anything else.

## What a COI actually is, and is not

A certificate of insurance is an informational snapshot issued by an insurance producer summarizing a policy: insurer, policy number, limits, effective and expiration dates, named insured. It is not the policy, it confers no rights by itself, and nothing about the document format prevents editing. Treating a COI as verification is treating a claim as a fact because it arrived as a PDF.

## How the forgeries actually look

The forgeries that work are boring. Almost everything on the document is real, because the easiest convincing fake is a genuine COI with one field changed:

- **The edited date.** A lapsed policy's certificate with the expiration pushed out a year. Everything else checks out because everything else is real.

- **The inflated limit.** Real policy, real dates, and a cargo limit raised to whatever the broker's requirement is.

- **The borrowed identity.** A real carrier's real COI with the named insured swapped, often part of the broader identity-theft pattern we covered in [carrier identity theft](https://www.cipherandrow.com/blog/carrier-identity-theft-freight).

Document-level forensics catch a meaningful share of these: inconsistent fonts and spacing where a field was replaced, editing artifacts in the file's structure, dates that disagree between the human-readable text and the document's internals. This is exactly what the document analysis in our [packet scanner](https://www.cipherandrow.com/blog/cipher-row-packet-scanner-how-it-works) looks for when a COI arrives in an onboarding packet.

## What federal filings tell you, and what they cannot

For the coverage types carriers are required to file with FMCSA, primarily public liability, the federal filing record is an independent signal that does not depend on the document the carrier handed you: which insurer filed, and whether the filing is active. If the COI in front of you disagrees with the filing record, believe the filing record and start asking questions.

The limits of that signal matter just as much. Most carriers are not required to file cargo coverage federally, so a filing check alone says little about the cargo policy a broker actually cares about. That gap is why the honest method is layered: filings where they exist, document forensics on the COI itself, and direct confirmation with the insurer or producer for anything that matters. We covered the broker-side filing requirements in [FMCSA insurance requirements](https://www.cipherandrow.com/blog/freight-broker-fmcsa-insurance-requirements).

## Insurance moves faster than any other credential

Here is the part onboarding-only vetting misses entirely: insurance is the fastest-moving credential a carrier has. Policies cancel for non-payment weeks after they were verified. A carrier who was genuinely covered at onboarding can be genuinely uncovered by the time your load is on their truck, and no COI in a folder will tell you that.

This is why coverage status belongs in continuous monitoring rather than a checklist: when a carrier's filed coverage lapses or is restored, that change should reach you as an alert, not wait to be discovered in the aftermath of a claim. Cipher & Row watches insurance status on monitored carriers and alerts on changes, alongside authority and safety status, and each verification produces a sealed record of what the data showed at the time, which is precisely the artifact you want in the file if a coverage dispute ever surfaces.

## A practical order of operations

- Check the federal filing record for the coverage types that file. Active filing, matching insurer.

- Run the COI itself through document scrutiny: edited-field artifacts, internal dates disagreeing with printed dates, producer details that do not resolve to a real agency.

- For coverage that matters and does not file federally, confirm with the producer or insurer directly, using contact details you resolved independently rather than the ones printed on the document you are trying to verify.

- Put the carrier on monitoring so a lapse reaches you as an alert.

- Keep the record of what you checked and when. [If diligence is ever questioned](https://www.cipherandrow.com/blog/broker-negligent-selection-documented-diligence), the record is the answer.

## Frequently asked questions

**Is a certificate of insurance proof that a carrier is insured?**

No. A COI is an informational snapshot issued by a producer at a point in time. It is evidence coverage existed at issuance, not proof it exists today, and the document itself is easy to edit.

**What are the most common COI forgeries?**

Mostly single-field edits to otherwise genuine certificates: a pushed-out expiration date, an inflated limit, or a swapped named insured. They look convincing because most of the document is real.

**Can I verify carrier insurance through FMCSA filings alone?**

Filings are a strong independent signal for the coverage types carriers must file federally, primarily liability. Most carriers are not required to file cargo coverage, so filings alone do not tell you about the cargo policy; that requires the document plus direct confirmation.

**How do doctored COIs get caught?**

Document forensics: fonts and spacing that break where a field was replaced, editing artifacts in the file structure, internal metadata dates that disagree with the printed dates, and producer details that do not resolve to a real agency. Cross-checking against the federal filing record catches the cases where the paperwork and the filings disagree.

**Why does insurance need continuous monitoring?**

Because it is the fastest-changing credential a carrier has. Policies cancel for non-payment mid-relationship, and a carrier verified at onboarding can be uncovered weeks later. An alert on a filing lapse reaches you before a claim does.

---

Read this article in your browser: https://www.cipherandrow.com/blog/fake-coi-verify-carrier-insurance

Cipher & Row verifies US and Canadian carriers and brokers, monitors them for changes, and seals every vetting decision into a verifiable record. Try a free lookup, no signup: https://www.cipherandrow.com/verify
