Connect with us

Technology

illumend CEO: Manual COI Tracking Can Create Hidden Vendor Approval Risk

Published

on

Kristen Nunery says spreadsheets, inboxes, reminders, and manual reviews may keep vendors moving, but they often fail to show why vendors were approved, delayed, escalated, or rejected

Key Takeaways

Manual COI tracking may seem to work, but it often does not give teams real control.Spreadsheets, inboxes, reminders, and manual reviews can hide the context behind vendor decisions.The biggest risk is inconsistent vendor approval. Teams may struggle to explain what was checked, what was missed, and why a vendor moved forward.Modern COI compliance requires more than document tracking. Teams need a process that highlights issues, records decisions, and guides consistent approvals.AI-native COI compliance decisioning helps teams apply requirements consistently, document outcomes clearly, and maintain human oversight when exceptions, audits, re-reviews, or changes to decisions are needed.

INDIANAPOLIS, June 24, 2026 /PRNewswire/ — Kristen Nunery, CEO of illumend™, the AI-native platform redefining how businesses manage third-party insurance compliance and risk, is encouraging businesses to reassess manual Certificate of Insurance (COI) tracking workarounds that appear to keep vendors moving but may create hidden approval risk.

In her new article, “The Manual COI Tracking Workaround Everyone Knows Is Risky, But No One Wants to Replace,” Nunery argues that spreadsheet-based COI tracking often survives because it appears functional. Vendors send certificates, reviews happen, and contracts move forward. But behind that activity, teams may be relying on scattered records, hidden exceptions, and the memory of one or two people who know what the system cannot show.

“The hardest COI workarounds to replace are the ones that seem to be working,” said Kristen Nunery, CEO of illumend. “They help teams get through the day, but they do not always give the organization real control. Manual tracking can show that a certificate was received, but it may not show what was checked, what was missed, or why a vendor was allowed to move forward.”

Nunery says the problem is not spreadsheets themselves. The problem is using spreadsheets, inboxes, reminders, and company knowledge as if they were a full compliance system. A certificate may look current while the real requirement lives in a buried email. A vendor may have an undocumented exception. A project may require an endorsement that was never added to the spreadsheet.

Manual COI tracking becomes risky, Nunery says, when vendor approval decisions become inconsistent, hard to back up, or difficult to explain later.

“Tracking documents is not the same as managing compliance,” Nunery said. “A team can collect a certificate and still miss a requirement. A current document may not include the needed coverage. A renewal can be tracked while a gap remains unresolved.”

COI compliance requires teams to answer questions that document storage alone cannot resolve: Does the coverage meet the requirement? Is the policy type correct? Is the required endorsement included? Does the vendor satisfy the contract for this project, location, or scope of work? Who needs to act next?

Those questions, according to Nunery, require interpretation, not storage.

She says the challenge is especially acute for administrative, operations, finance, HR, project, and risk-adjacent teams that are expected to keep vendors moving even though they are not insurance specialists. These teams may have to decide whether a certificate is acceptable, whether a missing endorsement matters, whether a renewal creates risk, or whether a vendor can start work while someone else checks the details.

Nunery points to a common scenario: a subcontractor needs to start work, but the usual insurance reviewer is out. The certificate shows active coverage, but the contract requires an additional insured endorsement. One person remembers seeing the requirement in an email. Another checks the spreadsheet and finds only “COI received.” The project manager wants to approve the vendor, but no one can confirm whether the endorsement is required, missing, waived, or already reviewed.

In that situation, the team did not fail. The process relied on one person’s memory as the main control.

Nunery identifies five warning signs that a COI compliance workaround has reached its limit:

Too much depends on one or two peopleThe same information is entered in too many placesCompliance questions take too long to answerSimilar issues lead to different decisionsFollow-up work crowds out actual risk work

Once those signs appear, Nunery says the real question is not whether the workaround still functions. The question is whether it gives the organization enough accuracy, consistency, and control to continue doing the job well.

A better process moves from tracking documents to tracking decisions: what was submitted, what was reviewed, what does not match, who needs to respond, and whether the vendor can move forward.

That shift, Nunery says, is where AI-native COI compliance decisioning changes the workflow.

“AI only matters if it helps with the part of compliance that document tracking cannot solve: interpretation,” Nunery said. “Teams are not just trying to find documents faster. They need to apply requirements consistently, document outcomes clearly, and keep the process moving with the right controls in place.”

At illumend, that AI-native approach is powered by Lumie, illumend’s built-in AI guide that automates every third-party vendor compliance, from contract upload to final approval. Lumie evaluates certificate of insurance documentation against an organization’s requirements and determines whether a vendor is compliant, deficient, or requires exception handling.

Lumie makes the compliance decision, not merely organizing information for someone else to interpret. It evaluates submitted documents against applicable requirements, identifies whether coverage meets the standard, determines whether a vendor is compliant or deficient, and preserves the reasoning behind the decision.

For example, a claims-made policy submitted in response to an occurrence-based requirement can be flagged as non-compliant. A missing additional insured endorsement can trigger a request for corrected documentation. A coverage issue that requires business judgment can be routed for exception review with the underlying context already documented.

With illumend, vendor records, submitted certificates, project requirements, prior exceptions, expiration status, deficiency history, and review activity are brought together into a single connected workflow. If a project requires an additional insured endorsement and the submitted documentation does not satisfy that requirement, Lumie determines the compliance status, documents the reason, and advances the next step: request corrected documentation, route an exception for approval, or record the decision if an exception has already been approved.

The illumend workflow changes the work from “find the answer” to “manage the outcome with the right decision, context, and controls.”

Built on 16 years of insurance compliance expertise from myCOI, illumend combines institutional knowledge with an AI-native platform that supports the compliance lifecycle. The platform connects vendor records, submitted documents, insurance requirements, deficiency alerts, renewal monitoring, exception handling, and resolution activity, so teams can see not only whether a document exists, but also whether the vendor is ready for approval.

“Companies do not outgrow spreadsheets because they are tired of them,” Nunery said. “They outgrow them because the risk becomes too important to manage from memory. The goal is to stop asking people who are not insurance experts to make insurance compliance decisions through scattered tools, memory, and guesswork. A better process gives those people what they need most: consistent compliance decisions, documented reasoning, and auditable outcomes.”

To read Nunery’s full article, visit https://www.linkedin.com/pulse/manual-coi-tracking-workaround-everyone-knows-risky-one-nunery-lmfie/.

Organizations considering a switch to AI-powered COI process management software can learn more about illumend’s approach to third-party insurance compliance at https://www.illumend.ai.

Frequently Asked Questions

When should a company replace a manual COI tracking workaround?
A company should replace a manual COI tracking workaround before it fails under pressure. Warning signs include overreliance on one or two people, duplicate data entry, slow responses to basic compliance questions, inconsistent decisions on similar issues, and excessive follow-up work that crowds out actual risk work.

Why is spreadsheet COI tracking risky?
Spreadsheet COI tracking can show that a certificate was received without showing whether coverage was reviewed against the right requirement, whether an endorsement was missing, whether an exception was approved, or why a vendor was allowed to move forward.

What does AI-native COI compliance decisioning mean?
AI-native COI compliance decisioning means using AI to evaluate submitted insurance documentation against applicable requirements, determine whether a vendor is compliant or deficient, document the reason for the outcome, and route the workflow to the appropriate next step.

How does Lumie help with COI compliance?
Lumie is illumend’s built-in AI guide that automates every third-party vendor compliance step from contract upload to final approval. Lumie evaluates COI documentation against an organization’s requirements, determines whether a vendor is compliant, deficient, or requires exception handling, and preserves the reasoning behind the decision.

About illumend
Founded in 2025, illumend™ is the AI-powered platform redefining how businesses manage third-party insurance compliance and risk. Backed by myCOI, the leader in third-party insurance compliance management with more than 16 years of expertise, illumend reimagines compliance by guiding every step of the process—from document review and expiration tracking to risk flagging, communication, and resolution—within one intuitive system. Built on myCOI’s institutional foundation—having processed more than 45 million documents, managed over 1.2 million agreements, cleared more than 750,000 third-party partners, and identified more than two million coverage gaps before claims—illumend brings this depth of compliance intelligence into an AI-native platform. At its core is Lumie, illumend’s conversational AI guide that reads complex insurance documents, flags issues in real time, and explains them in language anyone can act on. To learn more, visit https://www.illumend.ai.

Media contact:
Michael Tebo
Gabriel Marketing Group (for illumend)
Phone: 571-835-8775
Email: michaelt@gabrielmarketing.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/illumend-ceo-manual-coi-tracking-can-create-hidden-vendor-approval-risk-302808464.html

SOURCE illumend

Continue Reading

Technology

Baidu Announces Inclusion of Its Class A Ordinary Shares in the Shenzhen-Hong Kong Stock Connect and Shanghai-Hong Kong Stock Connect Programs

Published

on

By

BEIJING, Sept. 6, 2026 /PRNewswire/ — Baidu, Inc. (“Baidu” or the “Company”) (Nasdaq: BIDU; HKEX: 9888 (HKD Counter) and 89888 (RMB Counter)), a leading AI company with strong Internet foundation, today announced that the Company’s Class A ordinary shares traded on The Stock Exchange of Hong Kong Limited (the “Hong Kong Stock Exchange”) have been included in the Shenzhen-Hong Kong Stock Connect program, effective today, September 7, 2026 (Beijing time). The previously announced inclusion of the Company’s Class A ordinary shares in the Shanghai-Hong Kong Stock Connect program also became effective today. Eligible investors in the Chinese Mainland now have direct access to the trading of Baidu’s Class A ordinary shares through both programs.

The inclusion of Baidu’s Class A ordinary shares in the Shenzhen-Hong Kong Stock Connect program is pursuant to the Announcement on Adjustment of the List of the Eligible Stocks in Hong Kong Stock Connect under the Shenzhen-Hong Kong Stock Connect issued by the Shenzhen Stock Exchange on September 7, 2026.

Taken together, the inclusion in the Shanghai-Hong Kong Stock Connect and the Shenzhen-Hong Kong Stock Connect marks an important step toward expanding the Company’s reach among Chinese Mainland investors and is expected to further diversify its investor base and enhance the liquidity of its shares.

Baidu appreciates the continued support of its shareholders and investors and remains committed to driving sustainable growth and creating long-term value for shareholders.

About the Shenzhen-Hong Kong Stock Connect

The Shenzhen-Hong Kong Stock Connect is a mutual stock market access mechanism between the Chinese Mainland and Hong Kong under which the Shenzhen Stock Exchange and the Hong Kong Stock Exchange have established technical connectivity to enable investors in the Chinese Mainland and Hong Kong to trade eligible shares listed on the other’s market through their local securities companies or brokers.

About the Shanghai-Hong Kong Stock Connect

The Shanghai-Hong Kong Stock Connect established a two-way trading link between the Shanghai Stock Exchange and the Hong Kong Stock Exchange. The stock connect allows qualified Chinese Mainland investors to access eligible Hong Kong shares (Southbound) as well as Hong Kong and overseas investors to trade eligible A-shares (Northbound), subject to a certain amount of daily quota.

About Baidu

Founded in 2000, Baidu’s mission is to make the complicated world simpler through technology. Baidu is a leading AI company with strong Internet foundation, trading on Nasdaq under “BIDU” and HKEX under “9888”. One Baidu ADS represents eight Class A ordinary shares.

Safe Harbor Statement

This announcement contains forward-looking statements. These statements are made under the “safe harbor” provisions of the U.S. Private Securities Litigation Reform Act of 1995. These forward-looking statements can be identified by terminology such as “will,” “expects,” “anticipates,” “future,” “intends,” “plans,” “believes,” “estimates,” “confident” and similar statements. Among other things, Baidu’s and other parties’ strategic and operational plans, contain forward-looking statements. Baidu may also make written or oral forward-looking statements in its periodic reports to the U.S. Securities and Exchange Commission, in announcements made on the website of the Hong Kong Stock Exchange, in its annual report to shareholders, in press releases and other written materials and in oral statements made by its officers, directors or employees to third parties. Statements that are not historical facts, including but not limited to statements about Baidu’s beliefs and expectations, are forward-looking statements. Forward-looking statements involve inherent risks and uncertainties. A number of factors could cause actual results to differ materially from those contained in any forward-looking statement, including but not limited to the following: Baidu’s growth strategies; its future business development, including development of new products and services; its ability to attract and retain users and customers; competition in the Chinese Internet search and newsfeed market; competition for online marketing customers; changes in the Company’s revenues and certain cost or expense items as a percentage of its revenues; the outcome of ongoing, or any future, litigation or arbitration, including those relating to intellectual property rights; the expected growth of the Chinese-language Internet search and newsfeed market and the number of Internet and broadband users in China; Chinese governmental policies relating to the Internet and Internet search providers, and general economic conditions in China and elsewhere. Further information regarding these and other risks is included in the Company’s annual report on Form 20-F and other documents filed with the Securities and Exchange Commission, and announcements on the website of the Hong Kong Stock Exchange. Baidu does not undertake any obligation to update any forward-looking statement, except as required under applicable law. All information provided in this press release and in the attachments is as of the date of the press release, and Baidu undertakes no duty to update such information, except as required under applicable law.

View original content:https://www.prnewswire.com/news-releases/baidu-announces-inclusion-of-its-class-a-ordinary-shares-in-the-shenzhen-hong-kong-stock-connect-and-shanghai-hong-kong-stock-connect-programs-302870913.html

SOURCE Baidu, Inc.

Continue Reading

Technology

People See One Brand. The Internet May Show Them Hundreds More.

Published

on

By

The gap between what organisations control and what people trust may be larger than many realise.

SINGAPORE, Sept. 7, 2026 /PRNewswire/ — Every day, consumers decide whether to trust a website, email, link or digital service. What they rarely see is where an organisation’s official digital presence ends and similar-looking identities begin.

For most people, trust is not determined by ownership records or technical boundaries. It is shaped by what appears familiar, legitimate and connected to the organisation they believe they are engaging with. As digital interactions continue to grow, the gap between what organisations control and what people trust may become increasingly important.

The inaugural ONESECURE’s The State of Digital Trust in Singapore 2026 found that each reference organisation domain was associated with a median of 151 similar-looking domains across the public internet. The study analysed 120,702 distinct lookalike domains associated with 448 reference organisation domains and found that 82% had observable internet or email infrastructure, or both. While this does not indicate malicious activity, it demonstrates how external identities can possess the technical characteristics needed to establish an online presence that people may encounter and interact with.

While organisations typically have visibility over the websites, systems and accounts they own, customers, employees and members of the public make trust decisions based on what they encounter online. Similar-looking identities can exist beyond those organisational boundaries, creating a broader challenge around how trust is recognised, monitored and governed.

“People don’t experience organisations through asset inventories or security diagrams. They experience them through names, emails, websites and links,” said Edmund How, Managing Director of ONESECURE Asia. “The findings suggest organisations may need to think differently about trust. The challenge is no longer just securing what belongs to you. It’s understanding what exists around you, recognising when an external identity becomes relevant, and having a consistent way to determine when action is needed.”

The report found external identity exposure across multiple sectors, including financial services, healthcare, education, public services, transportation and information services, suggesting the issue is not confined to any single industry.

While the findings are drawn from a Singapore-focused dataset, the underlying question is relevant wherever people rely on digital identities to access services, conduct transactions and engage with organisations online regardless of geography.

Understanding and monitoring that broader identity landscape may become an important part of how organisations safeguard trust, protect reputation and fulfil their responsibilities to the people they serve.

If Singapore’s benchmark is 151 distinct lookalike domains per organisation, what could yours be? The question is not simply what your organisation owns, but whether you understand the wider identity landscape that exists around it.

Download the full ONESECURE’s The State of Digital Trust in Singapore 2026 report.

About ONESECURE Asia

ONESECURE Asia, headquartered in Singapore, is a managed security services provider helping organisations strengthen security and resilience as digital risks evolve. Its capabilities span managed security operations and Webyith, a digital trust platform designed to protect the integrity and authenticity of digital environments. Bringing together technology, intelligence and human expertise, we serve as a trusted and accountable partner in addressing critical security gaps across Asia.

Visit www.onesecureasia.com

About This Report

The State of Digital Trust in Singapore 2026 examines observable external digital identity exposure across 448 Singapore-focused reference organisation domains as of August 2026.

The analysis covers 144,134 observed domain records, representing 120,702 distinct lookalike domains after exact self-domain records were excluded. It assesses domain registration, DNS resolution, mail-routing configuration and supporting infrastructure patterns.

The research distinguishes exposure from investigative or operational relevance. A lookalike domain is not automatically malicious, and observable infrastructure or registration characteristics do not by themselves indicate phishing, abuse or malicious intent. They provide context for understanding which external identities may warrant closer examination.

The findings represent a Singapore-focused, point-in-time baseline, not a population-wide survey or measure of confirmed malicious activity. Lookalike volumes may be influenced by reference-domain characteristics and study methodology; comparisons should not be interpreted as rankings of malicious activity or security performance.

The study provides a basis for organisations to better understand, prioritise and govern external digital identity exposure beyond environments they directly control.

View original content to download multimedia:https://www.prnewswire.com/apac/news-releases/people-see-one-brand-the-internet-may-show-them-hundreds-more-302870890.html

SOURCE ONESECURE Asia

Continue Reading

Technology

Asia Fintech Forum 2026 to Convene Regulators, Bankers and Fintech Leaders in Kuala Lumpur on 2 October

Published

on

By

Inaugural forum from Singapore’s Responsible Fintech Institute, title-sponsored by Remi Technology, puts AI, stablecoins and financial inclusion on a single agenda

KUALA LUMPUR, Malaysia and SINGAPORE, Sept. 7, 2026 /PRNewswire/ — The Responsible Fintech Institute (RFI) today opened registration for the inaugural Asia Fintech Forum 2026, a one-day summit on Friday, 2 October at the World Trade Centre Kuala Lumpur.

The forum will bring together 40 speakers from regulators, banks and fintech firms across Asia, and is expected to draw 1,000 delegates. Remi Technology, the Singapore-headquartered cross-border settlement provider, joins as title sponsor.

Convening under the theme “Architecting Asia’s Financial Frontier: AI, Digital Assets, and Inclusive Banking,” the forum is RFI’s first flagship event outside Singapore. The choice of Kuala Lumpur is deliberate: Malaysia is licensing a new generation of digital banks while ASEAN member states negotiate the Digital Economy Framework Agreement (DEFA), and the forum’s regulatory track is built around that gap between national rulemaking and regional interoperability.

Confirmed speakers include Mohammad Ridzuan Abdul Aziz, Chief Executive Officer of Aeon Bank; Aaron Tang, General Manager of Luno Malaysia; Kenneth Chan, Chief Executive Officer of Webull Malaysia; Victoria Wymark of PwC South East Asia; and Affendi Rashdi, Director-General, and Ja’afar Rihan, Head of Islamic Business Development at Labuan Financial Services Authority. The full roster of the speakers is published at https://asiafintech.org/#speakers.

“Asia is writing the rules for digital finance faster than any other region, and it is writing them in several places at once — a stablecoin framework in Hong Kong, digital banking licences in Malaysia, payment corridors out of Singapore,” said Chia Hock Lai, Chairman of RFI. “The risk is not that innovation outpaces regulation. The risk is that a dozen regulators solve the same problem a dozen different ways, and the cost of that lands on consumers and on any firm trying to operate across borders. We chose Kuala Lumpur for our first forum because that conversation has to happen where the market is growing, not only where the rules are already written.”

Main-stage sessions, hands-on workshops, and closed-door roundtables span:

ASEAN fintech and the Digital Economy Framework Agreement (DEFA)Agentic AI in financial servicesStablecoin clearing, settlement and cross-border paymentsIslamic fintech and digital bankingReal-world asset (RWA) tokenisation and its legal frameworksPost-Quantum Cryptography (PQC) migration and defense strategies for banksStrategic fintech branding, positioning, and market communicationGovernance standards and institutional frameworks for permissionless blockchains in APAC (Project Pigeon)Digital banks and financial inclusion

“Banks do not need another payment rail that routes around them. They need settlement infrastructure that runs inside their own compliance perimeter,” said Sam Su, Chief Executive Officer and Co-Founder of Remi Technology. “That argument only gets properly tested in a room that has regulators and bank treasurers in it, not just builders. That is why we are title sponsor: this is one of the few forums in the region that puts all three on the same agenda on the same day.”

“Malaysia has long flown under the radar in regional fintech, and hosting this forum in Kuala Lumpur—with the backing of regional regulators and industry leaders—signals its coming of age,” said Farah Jaafar, Co-Chair of the organising committee, Independent Non-Executive Director of Webull Securities (Malaysia), and Co-Chair of the Women in Fintech group within the Asia Fintech Alliance. “We built this agenda for practitioners, not the conference circuit. Malaysia brings critical pillars the regional dialogue needs: a mature Islamic finance ecosystem and proactive regulators willing to give digital models room to scale.”

“Real-world asset tokenisation and next-generation capital markets cannot scale in silos; they require shared liquidity, robust custody, and cross-border regulatory clarity,” said Calvin Ng, Chairman of NexStox. “As both strategic partner and venue sponsor, NexStox is proud to anchor this dialogue at the World Trade Centre Kuala Lumpur. The Asia Fintech Forum provides the institutional bridge APAC needs to transition tokenised assets and digital market infrastructure from pilot concepts into live capital deployment.”

NexStox, RegTank, Sumsub and VerifyVASP join as sponsors.

Supporting partners include the Labuan Financial Services Authority (LFSA), International Digital Economics Association (IDEA), the Digital Assets Association (DAA), Thailand Fintech Association (TFA), Fintech Philippines Association (FPA), Hong Kong Fintech Industry Association (HKFTA), Unified Fintech Forum (India), ACCESS Malaysia, Fintech Association of Malaysia (FAOM) and Taiwan Fintech Space.

Registration is now open at https://asiafintech.org/. Exhibition packages and speaker nomination forms are available on the same site.

Media accreditation: Journalists may request onsite access, interview slots with RFI and sponsor spokespeople, and the full press kit (logos, speaker headshots, agenda) from the contact below.

About Responsible Fintech Institute

The Responsible Fintech Institute (RFI) is a global nonprofit organisation based in Singapore. Its goal is to create a safe, trustworthy and reliable future for digital finance by building the digital utilities that support responsible innovation. RFI brings together public and private sector stakeholders to help build the rules and technology needed for new digital financial tools, and to make the digital asset sector sustainable and inclusive. Learn more at responsiblefintech.org.

About Remi Technology

Remi Technology is a Singapore-based fintech company that delivers stablecoin clearing and settlement infrastructures for banks and financial institutions worldwide. Find us at www.remitech.ai or www.linkedin.com/company/remi-tech.

View original content to download multimedia:https://www.prnewswire.com/apac/news-releases/asia-fintech-forum-2026-to-convene-regulators-bankers-and-fintech-leaders-in-kuala-lumpur-on-2-october-302870789.html

SOURCE Responsible Fintech Institute (RFI)

Continue Reading

Trending