Can AI Verify Every Franchisee's Coverage Against Your FDD Item 8?
- By the Rikor team
- Jul 9
- 13 min read

In my world, AI has always meant one thing: Additional Insured. It is the endorsement that puts your brand's name inside a franchisee's policy so their coverage defends you when a customer sues. So the first time someone asked me if "AI" could verify a franchisee's insurance, my brain went to the wrong place. Now it means both. Artificial intelligence, checking whether the Additional Insured is actually there. That is a funny place to end up, and it is also the whole point of this article.
Here is the question every franchisor should be asking and almost none are: do you actually know that each franchisee carries the coverage your FDD Item 8 requires? Not that they have a policy. Not that a certificate showed up. That the coverage matches. Most brands cannot answer that, because the way they check has been broken for years, and the way they wrote the requirement was broken before that.
A certificate of insurance tells you a franchisee bought something. It does not tell you what they bought. Your Item 8 is supposed to be the standard you measure them against, and franchise insurance verification is supposed to be the act of holding the policy up to that standard. In most systems, neither one is doing its job. The requirement is vague, and the check is a person glancing at a one-page form and typing an expiration date into a spreadsheet. That is not verification. That is filing.
This is the part that changed. For the first time, a machine can read a franchisee's certificate at close to perfect accuracy and compare it to what you required, at scale, across your whole system, in the time it takes a person to check one. That is real, it is here, and it also has hard limits you need to understand before you trust it. Below are the failures that hide inside the old way, what the technology actually fixes, and where it still falls short.
Key Takeaways
A certificate is a receipt, not the coverage. It shows a franchisee bought a policy on the day it was printed. It says nothing about the exclusions, limits, and endorsements that decide whether the policy pays. Collecting certificates feels like compliance and transfers almost no risk.
People are the weak link, and it gets worse with every franchisee. A human checking a handful of certificates is fine. A human checking hundreds is a data-entry error rate stacking up on itself. The machine does not get tired at 4pm.
Verification is not "do they have a policy." It is "does the policy match Item 8." Confirming a franchisee is insured is step zero. Confirming the coverage meets or exceeds what you required, with the right limits, the right Additional Insured status, and the right endorsements, is the actual job.
Your Item 8 is probably the reason verification fails. If the requirement is a blanket number copied to every franchisee, the machine can verify against it perfectly and you are still exposed. A clean check against a bad standard is still a bad answer.
The gap lives inside the policy, not on the certificate. Subcontractor exclusions, classification limits, and coverage carve-outs like a telemedicine exclusion never show up on a certificate. The next stage of verification reads the policy itself.
Real-time is coming, and the carriers are the holdup. We are close to a world where coverage verifies against your requirement automatically and continuously. The technology is ready. The insurance companies holding the data are the ones slowing it down.
What does AI even mean here, artificial intelligence or Additional Insured?
In this article, AI means artificial intelligence, the software reading and checking the coverage. Everywhere else in your franchise system, AI means Additional Insured, the endorsement that names your brand on a franchisee's policy. Keep them straight, because the machine's most important job is checking whether the Additional Insured is real, which makes the AI verify the AI. I know. It is a lot.
The reason the distinction matters is that most franchisors think they already have the second one handled. A franchisee sends a certificate with a box checked that says Additional Insured, and everyone moves on. But a checkbox on a certificate is a claim, not proof. The Additional Insured status only exists if a specific endorsement was added to the actual policy, and the certificate is not the policy. It is a summary an agent typed up.
So when I talk about a machine verifying coverage, the highest-value thing it does is close the gap between what the certificate claims and what the policy actually contains. It reads the requirement, reads the proof, and tells you where they do not line up. A person can do that too. The difference is what happens when you ask a person to do it 1,700 times.
How did we go from typing certificates by hand to a machine reading them?
The technology to pull data off an insurance document went through three ugly stages before it got good, and understanding that arc tells you why you can finally trust it. It did not start with anything anyone would call intelligent. It started with software staring at fixed spots on a page.
The oldest approach was basically coordinate reading. The system looked at a specific location on the document, a longitude and latitude, and grabbed whatever text sat there. That works right up until the document moves. And insurance documents always move. The certificate is a standard form, the ACORD 25, but there are different versions of it, and the same version comes through scanned, faxed, exported from ten different systems, each one shifted a few pixels. The machine looking for the limit in the top corner grabs a phone number instead. The failure rate was brutal.
Then came OCR, optical character recognition, bolted together with two other tools: natural language processing, which lets software understand what words mean in context, and machine learning, which lets it improve from correction. Instead of reading a spot, you trained it. You fed it a stack of certificates, labeled each field, occurrence limit here, policy number there, and did it again, twenty, fifty, a hundred times, until the model learned the pattern. This bundle is what the industry calls intelligent document processing. Structured forms got easy. Free-flowing text like a policy or an endorsement stayed hard, because a PDF looks organized to your eye but is unstructured data underneath, and pulling clean data out of it is a fight.
Then the large language models showed up, and at first they were terrible at this. I tested them. Early on, extraction off a certificate was a mess. But the completeness got better with every release, one model to the next, until a standard model could pull the data off a certificate at close to perfect accuracy right out of the gate. Purpose-built tools got there too. Documented insurance implementations of intelligent document processing have moved extraction accuracy from around 75 percent to over 99 percent while cutting processing time by roughly 85 percent. That is not a small upgrade. That is the difference between a process you cannot trust and one you can.
Why can't a person just check the certificates?

A person can check certificates. A person cannot check certificates at franchise scale without an error rate that steadily wrecks your compliance picture. This is not an insult to your team. It is how human data entry works, and the research on it is old and consistent.
Skilled operators under good conditions run a data-entry error rate somewhere between 1 and 4 percent per field. Robert Panko's long-running work on human error puts simple keystroke and transcription mistakes in that low-single-digit range, and it climbs from there. The same person who hits half a percent at 9am is over 3 percent by 4pm. The same team that nails a clean standardized form falls apart on varied documents. Now multiply that across a certificate that has a dozen fields that all matter, times every franchisee, times every renewal.
Look at what an ACORD 25 actually asks a person to key. The limits are stacked right on top of each other in a tight column: each occurrence, general aggregate, products and completed operations, personal and advertising injury, medical expense. Miss which line you are on and you record the wrong number. The policy number is a long alphanumeric string that is easy to fat-finger. The Additional Insured boxes are small and easy to skim past. The description of operations is a free-text field where the real requirements, waiver of subrogation, primary and non-contributory, the specific language protecting your brand, either live or do not, and a person scanning fast will see what they expect to see.
Here is the second-order problem. It is not just that a person mis-keys a field. It is that verification is a comparison, and a person has to do three things at once: read the requirement, read the certificate, and hold both in their head while deciding if they match. Do that for a few franchisees and it is fine. Do it for hundreds and you are into the realm of 10, 20, 30 percent of your checks being wrong somewhere, and you will not know which ones. A machine doing the same comparison does not drift, does not get bored, and flags the mismatch instead of glossing over it.
Isn't checking the certificate the same as verifying the coverage?
No, and this is the single most expensive misunderstanding in franchise insurance. Most franchisors think verification means confirming a franchisee has a policy and noting when it expires. That is not verification. That is attendance. Real verification asks whether the coverage on that policy meets or exceeds what your Item 8 requires, at the right limits, with your brand named the right way, and the right endorsements attached.
There is a maturity ladder here, and almost every brand is stuck on the bottom rung. The first rung is "do they have insurance and when does it lapse." A lot of systems live their whole lives there and call it a program. The next rung is real compliance checking: does every required coverage exist, are the limits at or above your minimums, is the Additional Insured status actually endorsed, is the waiver of subrogation there, is the primary and non-contributory language there. That is where verification starts to mean something, because that is where you find out a franchisee who "passed" for three years never had the endorsement you required.
The rung above that, the one the technology is climbing toward now, is verifying the policy is active and reading the full policy, not just the certificate. A certificate is a snapshot from the day it printed. It does not know the policy lapsed last Tuesday. It does not show the exclusions. Moving up this ladder is the entire game, because each rung transfers more real risk off your balance sheet and onto the coverage where it belongs. Collecting certificates transfers almost none. Checking coverage against Item 8 transfers a lot. Reading the policy transfers the most.
Why does verifying against your Item 8 fall apart if the Item 8 is wrong?
Because verification is only as good as the standard you verify against, and most Item 8 requirements are a bad standard. A machine can hold a franchisee's policy up to your Item 8 and confirm a flawless match, and you can still be wide open, because the thing it matched against did not ask for the right coverage in the first place. A clean check against a weak requirement gives you false confidence, which is worse than no confidence.
I will say something I have said in front of a lot of franchisors. Almost every Item 8 I read is done wrong. They are vague. They do not ask for specifics. And the biggest flaw, the one that shows up over and over, is that they treat risk as static across every franchisee. They write one blanket requirement, usually a million each occurrence and two million aggregate, and apply it to everyone. But franchisees are not the same size and do not carry the same risk. Risk scales with exposure basis, the real drivers underneath the business: revenue, payroll, subcontractor spend, number of units. A brand-new single unit and a ten-unit operator with a fleet of crews are not the same exposure, and one flat number cannot be right for both. It over-insures the little guy and badly under-requires the big one. Both are findings.
The vague Item 8 also skips the language that makes the coverage actually protect the brand. It leaves out waiver of subrogation and primary and non-contributory, the two endorsements that decide whether the franchisee's policy pays before yours or comes after your carrier writes the check and then chases the franchisee. It skips ancillary coverages that have become table stakes, like employment practices liability and cyber. And it almost never does the most important thing, which is tell the franchisee what they are not allowed to buy. That last gap is where the real money hides, and it is the next section.
What does a machine catch inside the policy that a certificate never shows?

The exclusions, limitations, and warranties buried in the policy, none of which appear on a certificate, are where coverage disappears. This is the frontier of verification and the reason reading the full policy matters. A franchisee can hand you a certificate that looks perfect, carry the exact limits your Item 8 demanded, and still have a policy that will not pay for the thing their business actually does, because of a form you never saw.
Take subcontractors, which is most of the home-services and trades world. A general liability policy can carry a subcontractor exclusion, the CG 22 94 form, that strips coverage for damage tied to work a sub performed. It can carry a subcontractor warranty endorsement that voids coverage entirely unless every sub carried its own insurance at set minimums, which the franchisee almost never tracks. It can carry a classification limitation that ties coverage to specific ISO class codes, so the work only counts if it matches the code on the policy. There is a real case where a painting contractor's policy was limited to interior work, they did an exterior job, and the carrier had no duty to defend. Same idea shows up in franchising constantly: a pizza brand adds wings, the class code never gets updated, and a claim on the new operation falls outside the coverage.
Here is one I actually reviewed. A functional medicine brand, men's hormone therapy, required medical malpractice in their Item 8. Good so far. But the brand was also doing telemedicine, and nowhere did the requirement tell the franchisee to carry telemedicine coverage. That matters, because a lot of traditional medical malpractice policies exclude telehealth or need a specific endorsement to cover it, and technology-driven failures like a dropped video visit leading to a bad call often are not covered at all. So you have franchisees delivering a core part of the service with a malpractice policy that walks away the moment a telemedicine claim hits. Telemedicine was a real slice of revenue across a system with a lot of locations, and the exposure sitting under that one oversight is a 175,000 dollar claim the franchisee's malpractice policy walks away from.
A certificate will never show you any of that. The exclusion is a form number deep in a forty-page document. This is why the ceiling on verification keeps rising: the machine that reads certificates today is learning to read the policy, and franchisors are going to start asking their verification partner to confirm the right coverages, the right classifications, the right forms and endorsements, and the absence of the bad exclusions, limitations, and warranties. That is where this goes.
So can AI actually verify every franchisee against your Item 8 today?

Partly, and the honest answer is more useful than the hype. Today, a machine can extract a franchisee's certificate at close to perfect accuracy and compare it to your Item 8 far faster and more consistently than any person, across your entire system at once. That part is real and available now. If your requirement is written well, automated verification against it is no longer a someday thing.
Where it is still climbing is the full policy. Reading the whole document, catching the exclusions and classification limits and warranty endorsements, is harder than reading a structured certificate, because the policy is long, unstructured, and every carrier formats it differently. The tools are getting there fast, and this is exactly the direction the good ones are moving. But if a vendor tells you they perfectly verify every franchisee's complete policy today with zero human review, be careful, and ask them how they handle the free-text and form-level stuff, because that is where accuracy still splits between forms and text.
The bigger unlock is real-time, and the holdup is not the software. It is the carriers. Right now this whole process still leans on documents, a PDF changing hands, which is a little crazy when you think about it. The moment insurance companies open up their data so coverage can be checked at the source instead of off a certificate, verification stops being a snapshot and becomes continuous. You would know the day a policy lapsed, not at the next renewal. I think we are inside five years of that, and the pace depends almost entirely on how fast carriers adopt. The technology is ready and waiting on them.
So the real answer to the title is this. Can AI verify every franchisee's coverage against your Item 8? It can verify the certificate against your requirement right now, better than people can. It is learning to verify the full policy. And it can only be as good as the Item 8 you point it at. Fix the requirement first, then let the machine do what people never could at scale.
Frequently Asked Questions
Is a certificate of insurance proof that a franchisee is compliant? No. A certificate is a summary an agent prints on a given day. It is explicitly for information only and does not change or prove what the policy contains. A franchisee can send a clean certificate and still be missing the Additional Insured endorsement, the waiver of subrogation, or the coverage your Item 8 required. Compliance is confirmed by checking the policy against the requirement, not by collecting the form.
What is the difference between verifying insurance and monitoring compliance? Verifying that a franchisee has insurance answers "is there a policy and when does it expire." Monitoring compliance answers "does every required coverage exist, at the right limits, with the right endorsements and Additional Insured status, and does it still hold at renewal." The first is a calendar. The second is risk transfer.
Can automated verification replace our people entirely? Not today, and not for everything. Machines now extract and compare certificate data at close to perfect accuracy, which is where human error stacks up worst. Full-policy review, catching exclusions and classification limits, still benefits from expert oversight while the technology matures. The right setup uses the machine for scale and speed and people for judgment on the hard edges.
Why does our Item 8 need to change if the software is this good? Because software verifies against the standard you give it. If your Item 8 uses one blanket limit for every franchisee and skips required language and coverages, the machine will confirm a perfect match to a weak requirement. Set the requirement to the franchisee's real exposure first, then automated verification becomes worth something.
What coverage gaps hide inside a policy that a certificate never shows? Subcontractor exclusions like the CG 22 94 form, subcontractor warranty endorsements that void coverage unless subs are insured, classification limitations tied to ISO codes, and service-specific carve-outs like a telemedicine exclusion on a malpractice policy. None of these appear on an ACORD 25 certificate. They live in the full policy, which is why the next stage of verification reads the policy itself.
Conclusion
For years, the reason franchisors could not really verify coverage was that a person had to read a shifting one-page form, compare it to a requirement, and do it hundreds of times without slipping. That was never going to work, and the error rate proved it every day. The machine changes the math. It reads the certificate at close to perfect accuracy, checks it against the standard, and never gets tired at 4pm. What it cannot do is fix an Item 8 that asked for the wrong thing, and what it is still learning to do is read the whole policy where the real gaps hide. We went from a person verifying coverage to a machine verifying the same coverage, and the machine is only getting better. The carriers are the last ones holding the door.
About the Author Wade Millward is the founder and CEO of Rikor, a technology-enabled insurance and risk management company focused on the franchising industry. He has spent his career working with franchisors, franchisees, and private-equity-backed platforms to uncover hidden risk, design scalable compliance systems, and align insurance strategy with how franchise systems actually operate. Wade writes from direct experience building systems, navigating claims, and helping brands scale without losing visibility into risk.




Comments