Forged Certificates of Insurance: How UK Firms Detect Fraud
How UK procurement teams detect forged certificates of insurance from contractors and vendors, from fake policy numbers to cloned broker letterheads and PDFs.

Summarize this article with
A certificate of insurance is one page, produced by a broker in minutes, and it is the single document most procurement teams treat as sufficient proof that a contractor is covered. That trust is exactly what makes it a soft target: unlike a Companies House filing or an HMRC verification number, nobody outside the insurer or broker can check a certificate's contents against a public register in real time. This article covers the certificate itself โ how the insurer name, policy number, coverage limits, expiry date and broker letterhead get fabricated or altered, and how a risk team catches it โ not vendor tax and licensing paperwork, which our guide to forged compliance certificates in supplier onboarding already covers, or the wider CIS and CDM 2015 obligations in our subcontractor compliance guide.
What a Genuine Certificate of Insurance Actually Proves
A certificate of insurance confirms that a policy existed, with stated limits, at the moment the broker issued it โ nothing more. The International Risk Management Institute defines it as evidence that certain coverages and limits have been purchased, explicitly not a contract in itself and no guarantee that the underlying policy will still be in force when a claim arises (IRMI, Certificate of Insurance). That distinction matters for fraud detection: a certificate can be entirely genuine on the day it is issued and still misrepresent the contractor's position three months later if the policy lapses, is cancelled for non-payment, or is amended without a new certificate being sent. Forgery is a different problem again โ a document that misrepresents the insurer, the policy, or the limits from the outset, produced to pass an onboarding check rather than to summarise a real placement.
Six Ways Fraudsters Forge a Certificate of Insurance
Forged certificates fall into a small number of recurring patterns because the goal is passing a document review, not producing a legally binding record. A fabricated insurer name is the crudest version โ an invented company, or a genuine insurer's name misspelled just enough to survive a quick read but fail a search of the Financial Services Register. A fake or reused policy number follows the same logic: it looks plausible in format but returns no match, or matches a different policyholder entirely, when the broker or insurer is asked to confirm it directly.
Altered coverage limits and expiry dates are the most common edits because they require changing only a few characters in an otherwise real-looking layout โ a ยฃ2 million public liability limit typed over as ยฃ5 million, or an expiry date pushed back six months on a certificate that actually lapsed at renewal. Cloned broker letterhead and spoofed sender domains extend the same tactic to the document's provenance: a logo and layout copied from a genuine brokerage, sent from an email domain one character removed from the real one, so a distracted reviewer reads the name and not the address. The last category is the doctored PDF itself โ text layers edited directly rather than the document being recreated from scratch, which is why mismatched fonts, inconsistent kerning, or a certificate that looks like a rescanned photocopy of an edited file are frequently the first visible tell.
Manual document review across all fraud types catches only around 37% of cases, with a median detection delay of 87 days, according to the ACFE's 2024 Report to the Nations (ACFE, 2024 Report to the Nations) โ long enough for a forged certificate to sit unchallenged through an entire onboarding cycle and well into an active contract before anyone checks it against the insurer.
Red Flags in a Suspect Certificate of Insurance
The strongest indicators sit in fields a fraudster edits under time pressure rather than in the overall visual polish of the document, since a competent forger can make a certificate look professional while still leaving inconsistencies in the details that matter.
| Field | What forgers typically alter | How to check it |
|---|---|---|
| Insurer name | Invented company, or a real insurer's name misspelled slightly | Search the exact name on the FCA's Financial Services Register |
| Policy number | Fabricated format, or a number reused from a different policyholder | Ask the insurer or broker to confirm the number against the named policyholder |
| Coverage limits | Inflated public/employers' liability limits typed over the original figure | Request written confirmation from the broker, not a re-sent PDF |
| Expiry date | Pushed back to appear current when the real policy has lapsed | Cross-check against the broker's own renewal records, not the certificate date |
| Broker letterhead/contact | Cloned logo and layout, sender domain one character off the genuine broker | Call the broker using a number sourced independently, never one printed on the certificate |
| Document formatting | Mismatched fonts, inconsistent kerning, or scan artefacts on an edited PDF | Compare against a previous certificate from the same broker for the same client |
Ready to automate your checks?
Free pilot with your own documents. Results in 48h.
Request a free pilotHow to Verify a Certificate Rather Than Trust It
Verification means confirming the certificate's contents with a party who has no reason to lie about them, not re-reading the document more carefully. Three channels are commonly available, and they differ sharply in speed, reliability, and how well they scale across a large supplier base.
| Verification method | Speed | Reliability | Best suited to |
|---|---|---|---|
| Call the broker or insurer directly (using an independently sourced number) | Minutes | High, if the contact number is verified independently first | Occasional onboarding, high-value contracts |
| Written confirmation letter from the insurer | 1โ3 days | High, and provides an auditable record | Formal pre-qualification files, audit trail requirements |
| Third-party COI tracking or verification platform | Near real-time once integrated | High for renewal and lapse monitoring; still requires an initial source-verified upload | Portfolios of dozens to hundreds of subcontractors |
Before calling any number, confirm the broker or insurer's authorisation on the FCA's Financial Services Register, since the FCA explicitly recommends checking a firm there before relying on anything it has issued (FCA, How to check a firm or individual is authorised). A phone number printed on the certificate itself proves nothing, because a fraudster who fabricates the document can just as easily staff the number that appears on it.
Legal Exposure for Accepting a Forged Certificate
Accepting a forged certificate does not just leave a business uninsured on paper โ it can trigger separate statutory penalties tied to the type of cover being misrepresented. Employers' liability insurance is the clearest example in the UK, because display and production of the certificate are legal obligations in their own right, not just good practice.
Under the Employers' Liability (Compulsory Insurance) Act 1969, an employer operating without the required cover can be fined up to ยฃ2,500 for every day it goes uninsured, and up to ยฃ1,000 separately for failing to display the certificate or produce it to an HSE inspector on request (HSE, Employers' Liability (Compulsory Insurance) Act 1969: a brief guide). Those penalties attach to the party required to hold the cover, but a contractor who unknowingly engaged an uninsured subcontractor on the strength of a forged certificate can still face the underlying liability if a workplace injury occurs and no genuine policy responds. Separately, whoever produced the forged document is exposed under Section 1 of the Forgery and Counterfeiting Act 1981, making a false instrument with intent that it be accepted as genuine, which carries a maximum sentence of ten years' imprisonment on indictment (legislation.gov.uk, Forgery and Counterfeiting Act 1981).
Where Certificate Checks Fit Into Wider Vendor Pre-Qualification
Certificate verification rarely happens in isolation on well-run construction and facilities contracts โ it sits inside a broader pre-qualification standard that a supplier must pass before it is invited to tender at all. The Common Assessment Standard, developed by Build UK with Constructionline, replaced the earlier PAS 91 questionnaire in 2023 and assesses insurance alongside health and safety, financial standing and environmental management as part of a single supplier accreditation (Constructionline, What is PAS 91 and is it still used as a construction PQQ?). Relying solely on accreditation at onboarding is not sufficient on its own, though: an accreditation is a point-in-time assessment, and a certificate submitted for a specific contract months later still needs its own check against the insurer, particularly on longer framework agreements where the original accreditation may have lapsed or the subcontractor's cover may have changed.
What to Do When a Certificate Looks Wrong
Pause onboarding or payment for that supplier before raising the concern with them, since an early confrontation can prompt evidence destruction or a hastily produced second forgery that is harder to disprove. Contractors on trade and small-business forums often ask whether calling the number printed on a certificate counts as verification โ it does not, because that number is exactly what a fraudster controls; the only reliable route is a broker or insurer contact sourced independently, through the FCA register or a previous, trusted communication. A related question that comes up just as often is what happens if a certificate was genuine when submitted but the policy lapsed mid-contract without anyone noticing โ the answer is that periodic re-verification, not a one-off check at onboarding, is what catches that gap.
Preserve the original file and its metadata rather than a screenshot or re-saved copy, since creation and edit history is often the clearest evidence a PDF's text layer was altered after issue. Report confirmed forgery to Action Fraud and notify the broker or insurer whose identity was cloned, since they have both a commercial and regulatory interest in a fraudster using their name.
Building Systematic Verification Into Onboarding
Manual checking does not scale once a business is managing renewals across dozens or hundreds of subcontractors, since every expiry date and every new supplier is another certificate that needs an independent call or letter rather than a five-second read. Platforms such as CheckFile apply structural, metadata and cross-document analysis to submitted certificates, flagging inconsistent fonts, edited PDF layers, and mismatches against previously seen broker templates. CheckFile's methodology combines structural, metadata and cross-document analysis, described as high detection coverage rather than a fixed percentage, and contextual scoring keeps false-positive handling low, distinguishing a broker's legitimate template changes from genuine signs of tampering.
An additional AI-generation signal layer is deployed as a complement to those structural checks, depending on client configuration, not a replacement for verifying the policy directly with the insurer โ a forged policy number still has to be confirmed against the insurer's own records, and an inflated coverage limit still has to be checked against the broker's file. For document sets where AI-generated fraud is a specific concern, see CheckFile's AI-generated document detection, used alongside the checks above rather than instead of them.
For the construction and facilities sector specifically, see CheckFile's solutions for construction and BTP. Teams evaluating a platform can review CheckFile's security architecture or get in touch to discuss a specific supplier base, and the document compliance guide sets out the wider framework this fits into.
Frequently Asked Questions
How can I tell if a certificate of insurance is forged without contacting the insurer?
Visual checks alone are unreliable: mismatched fonts, inconsistent formatting between sections, or a certificate that looks like a rescanned copy are useful clues but not proof. The only conclusive check is confirming the insurer, policy number and limits directly with the broker or insurer, contacted through a number sourced independently rather than one printed on the document.
Does a certificate of insurance guarantee the coverage is still active?
No. A certificate reflects the policy's status at the moment it was issued and carries no guarantee that the policy remains in force, according to IRMI's definition of the document. A policy can lapse, be cancelled for non-payment, or be amended after the certificate was sent, which is why periodic re-verification matters as much as the initial check.
What penalty applies for not displaying an employers' liability insurance certificate?
Under the Employers' Liability (Compulsory Insurance) Act 1969, failing to display the certificate or produce it to an HSE inspector on request can result in a fine of up to ยฃ1,000, separate from the up to ยฃ2,500 per day fine for operating without the required cover at all.
Is calling the phone number on the certificate a valid way to verify it?
No. A fraudster who fabricates a certificate can just as easily list a phone number they control, so calling that number only confirms whoever answers agrees with the document. Verification requires sourcing the broker or insurer's contact details independently, for example through the FCA's Financial Services Register.
Should a single red flag on a certificate be enough to reject a supplier?
Not automatically, but it should always trigger direct verification with the insurer or broker before onboarding continues. Two or more inconsistencies on the same certificate โ such as a mismatched font alongside an unverifiable policy number โ is a reasonable basis to pause the relationship pending confirmation from the issuing insurer.
This article is for informational purposes only and does not constitute legal, insurance, or regulatory advice. Consult a solicitor or insurance broker for guidance specific to your organisation. Legislation and guidance referenced are current as of 30 July 2026.
Stay informed
Get our compliance insights and practical guides delivered to your inbox.