Vendor Contracts: Indemnity, Insurance Certificates and Back-to-Back Risk
How Indian SMEs should use indemnity clauses and certificates of insurance in vendor contracts to push risk back to the party best placed to control it.
Indemnity clauses only protect a business if the vendor giving the promise can actually pay - which is why certificates of insurance and back-to-back risk transfer matter as much as the contract wording itself.
Key facts at a glance
- An indemnity clause shifts financial responsibility for a defined loss from one contracting party to the other.
- A certificate of insurance is the only reliable proof that a vendor's stated coverage is actually active and adequate.
- Back-to-back risk transfer means passing liability down the chain so the business is not left holding a loss it can recover from the party who caused it.
- Indemnity clauses are typically capped, often tied to contract value or a fixed monetary limit.
- Being named an additional insured on a vendor's liability policy gives a stronger, more direct claim right than indemnity wording alone.
- Certificates of insurance should be re-verified at each policy renewal, not just once at contract signing.
- Indemnity and insurance are complementary, not interchangeable - one is a legal promise, the other is the financial backing that makes the promise real.
Why indemnity clauses need insurance behind them
An indemnity clause is a legal promise: if the vendor's negligence causes you a loss, they will make you whole. But a promise is only as strong as the ability to pay it. A small vendor with limited assets can sign an indemnity clause with no realistic way to honour it if something goes wrong at scale - a fire caused by faulty electrical work, a data breach from a poorly secured vendor system, or property damage during on-site work.
This is why serious vendor contracts pair indemnity language with an insurance requirement: the vendor must carry specific types and limits of insurance, and must prove it with a certificate of insurance before work begins and at each renewal.
What to actually check on a certificate of insurance
A certificate should show the type of policy (general liability, professional indemnity, workmen's compensation, or cyber liability depending on the vendor's role), the coverage limits, the policy period, and ideally confirm your business is named as an additional insured or certificate holder where the relationship warrants it. A certificate that is expired, unsigned, or vague about coverage type is not worth relying on.
Back-to-back risk transfer in practice
The idea behind back-to-back risk transfer is simple: whatever risk you take on with your own customer or landlord, you try to pass an equivalent risk down to the vendor or subcontractor actually doing the work. If your lease makes you liable for fire damage caused by your contractor's work, your contract with that contractor should make them liable to you for the same, backed by their own insurance. Gaps appear when the terms do not match - for example, your customer contract has an uncapped indemnity, but your vendor contract caps the vendor's liability at a much lower figure. That mismatch becomes a cost you absorb.
Comparing the three risk-transfer tools
| Tool | What it provides | Main limitation |
|---|---|---|
| Indemnity clause | Contractual right to recover a defined loss from the vendor | Only as good as the vendor's ability to pay |
| Certificate of insurance | Evidence the vendor's promise is financially backed | Only a point-in-time snapshot; must be re-verified |
| Additional insured status | Direct right to claim under the vendor's own policy | Not always offered; usually needs to be negotiated |
Setting sensible limits and caps
Businesses sometimes accept a low liability cap in a vendor contract just to close the deal faster, without checking whether the cap would actually cover a realistic loss scenario. A reasonable starting point is to size the required insurance and indemnity cap against the worst plausible outcome of that specific vendor relationship - not against the contract's fee value, which is often far smaller than the potential loss.
Building this into your vendor onboarding process
The most effective fix is procedural: make certificate of insurance collection a mandatory step before any vendor is activated, track renewal dates the same way you track contract renewal dates, and flag any vendor whose coverage has lapsed for follow-up before further work is assigned. Treating this as a recurring compliance task, rather than a one-time contract negotiation, is what keeps the protection real.
If you are not sure where your business stands on vendor and statutory compliance risk more broadly, ComplianceCheck's statutory health assessment gives you a clear picture in a few minutes.
Sources
- IRDAI - irdai.gov.in
- Ministry of Corporate Affairs - mca.gov.in
- General Insurance Council - gicouncil.in
This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.
Frequently Asked Questions
- What does an indemnity clause do in a vendor contract?
- It shifts financial responsibility for a defined loss from one party to the other, so that if the vendor's negligence causes a loss, the vendor - not the business that hired them - bears the cost, up to whatever limits the clause sets.
- What is a certificate of insurance and why should I ask vendors for one?
- A certificate of insurance is proof issued by a vendor's insurer confirming their policy is active, naming the coverage type and limits, and it lets you verify the vendor actually has the insurance the contract requires before relying on their indemnity promise.
- What is back-to-back risk transfer?
- It means passing a risk down the contracting chain in matching terms, so a business is only on the hook for a loss to the extent it cannot recover the same amount from the vendor or contractor who actually caused it.
- Is an indemnity clause useless if the vendor has no insurance?
- An indemnity clause without matching insurance is only as good as the vendor's own balance sheet, so for anything beyond a small vendor with limited assets, insisting on a certificate of insurance is what makes the indemnity practically enforceable.
- Should indemnity clauses have a cap on liability?
- Most commercial contracts do cap indemnity liability, often tied to contract value or a fixed sum, and businesses should check that any cap is not set so low that it is meaningless against a realistic worst-case loss.
- Do I need to be named as an additional insured on a vendor's policy?
- For higher-risk vendor relationships, such as contractors working on your premises, being named as an additional insured on their liability policy gives you a direct right to claim under their policy, which is stronger protection than an indemnity clause alone.
- How often should I re-verify a vendor's insurance certificate?
- At minimum every time their policy is due for renewal, since certificates of insurance only confirm coverage as of the date issued and a lapsed renewal can leave you unknowingly uninsured against that vendor's risk.
Check your status
Statutory Health Check
A 12-question health check of PF, ESI, Professional Tax, Gratuity and Bonus compliance for Indian employers.