Corporate card management is the full set of activities that make up a company card program, meaning issuance, spend limits, policy, reconciliation, receipt collection, transaction review, and offboarding. Half of the work starts after authorization. Card network data alone cannot complete it, because a merchant category code describes the business rather than the purchase.
The published advice concentrates on issuing cards and setting limits. It treats what happens next as a routine transfer into the accounting system. The activities that follow authorization, meaning the moment the card network approves a purchase, form a distinct half of the discipline. How much leakage a program actually recovers depends on that half, and it needs evidence the card network does not supply.
Card programs are large and growing. GSA SmartPay, the charge card program of the United States federal government, publishes GSA SmartPay program statistics. For fiscal year 2025 it reported $39.4 billion in program spend, an average of $480 spent per transaction, and $471 million in refunds earned by agencies. Private programs share that shape, meaning high transaction volume at low average value. That distribution is where manual review performs worst.
Most control in a card program happens before the purchase. A swipe is approved or declined against spending limits, blocks on particular merchant category codes (MCC), caps on single transactions, and preferred supplier lists. An MCC is the code card networks assign to classify a business by the kind of trade it does. These controls work, and they are deliberately coarse.
A merchant category code identifies the type of business, not the purchase. The card network clears a business dinner and a family dinner under the same restaurant code. It clears the room charge and the pet boarding charge on one hotel bill under a hotel code. It clears a laptop bought for a spouse under an office supply code. Each of those transactions is authorized, categorized, and posted correctly, and each is a control failure.
That difference separates card spend from expense report spend. An expense report is a claim an employee makes before money moves, so a review before payment stops it. A card transaction is money that has already moved. Control over card spend is therefore largely detective, meaning it identifies problems after they occur rather than preventing them. The corporate credit card fraud patterns follow from that fact.
Reconciliation is commonly described as a synchronization between the card feed and the accounting system. A more useful frame is that a reviewer has to answer three questions about every posted transaction, which a synchronization does not supply.
The first question is whether the transaction was real. A receipt has to exist, correspond to this transaction, and name a merchant that exists and trades where it claims to. Missing receipts are the visible form of this problem. Receipts present but unverified are the larger one.
The second is whether the purchase was allowed. What matters is not whether the merchant category code was permitted. It is whether what was bought falls inside policy at the level of individual line items. That covers alcohol, upgrades, personal items, and spend split across several transactions to stay under an approval threshold.
The third is whether the cost was already paid. The same charge may also appear in the expense system, another employee's report, or a supplier invoice. This question gets examined least often, because the card feed and the expense system are usually reviewed by different people at different times.
A team that answers all three for every transaction is managing the program. A team that answers them for a sample is only producing reports.
There are three levels of card data detail, and the level available limits what gets checked.
Level 1 includes the basics, meaning the merchant name, the date, and the total. That is enough to reconcile a balance and no more.
Level 2 adds the tax amount, a customer code, and the merchant's postal code. It supports tax recovery and simple policy checks based on location.
Level 3 adds line-item detail, including item descriptions, quantities, unit prices, and product codes. At that level a card transaction becomes auditable rather than merely categorized.
Availability of Level 3 detail depends on the merchant and on the acquirer, the bank that processes card payments for the merchant. It does not depend on the organization holding the cards. Large suppliers, travel providers, and technology and office vendors commonly supply it. A neighborhood restaurant does not. A program that assumes Level 3 detail is always available will have blind spots exactly where discretionary spending concentrates.
Receipt images close that gap. Reading the receipt recovers the line-item detail the card network never transmitted, which is why receipt collection is a control requirement rather than a bookkeeping formality.
Entitlement records who holds a card, at what limit, and on whose approval. A quarterly review of the cardholder population beats an annual one, because a card that outlives the role justifying it keeps spending authority in the wrong hands.
Offboarding, the closing out of an employee's access when employment ends, works best when cancellation falls on the last working day rather than the next statement cycle. Dormant cards, meaning accounts with no activity for several months, warrant separate attention. A dormant card is an open credential nobody is watching.
Purchasing cards (P-Cards), used for routine supplier buying, and ghost cards, meaning account numbers assigned to a supplier or department rather than an individual, behave differently from employee travel cards. They often carry higher limits, more than one person uses them, and the record of who authorized what is thinner. They merit their own review cadence and thresholds.
Track the share of transactions with no receipt attached, by department, as a program metric. A rising rate usually points to a process problem rather than a discipline problem, and it tends to precede other control failures.
A single finding means little. The same finding against the same cardholder across successive quarters is the strongest evidence a program produces. It exists only where findings are logged consistently, including those resolved in the cardholder's favor. Duration is what makes such patterns expensive. The Association of Certified Fraud Examiners examined 2,402 cases across 143 countries and territories for Occupational Fraud 2026 and found a median of 12 months before detection. The median loss was $104,000 per case.
Most guidance on this subject is published by companies that issue cards, which shapes what it covers. Issuance, limits, virtual cards, and real-time visibility get detailed treatment, because those are the product. Reconciliation appears as a single line promising that transactions will synchronize with the accounting system.
Two consequences follow. Controls get presented almost entirely as pre-spend blocking, which leaves the post-authorization share of leakage unaddressed. Duplicate spend across the card feed and the expense system goes unmentioned. An itemized receipt and a card line covering the same dinner is among the most common findings in programs that look for it.
A team cannot keep up with that volume by hand. Reviewing card transactions by hand meets the same capacity limit that holds expense audit at 10 to 20 percent of transactions. Our analysis of 100 percent audit coverage examines that gap. Card programs also produce more transactions at lower average values than expense reports.
Our platform audits 100 percent of card transactions as purchases post, through connections to bank and card networks, so review does not wait for the statement cycle. Checks run against Level 2 and Level 3 card data where the merchant supplies it, and against the receipt image where it does not. Web and social sources confirm that a merchant exists.
The cross-check is the component that is hard to build internally. Each card transaction is compared against expense reports, other cardholders, and historical spending, which is what surfaces duplicate charges, unauthorized purchases, out-of-policy spending, and repeat violators. Card Audit covers corporate cards, purchasing cards, and ghost cards, and it is issuer-agnostic, so an existing program stays in place.
Automated review does not determine intent. A finding states that a transaction failed a named check and presents the evidence. Whether the cause is an error, a habit, or something more serious stays a judgment for the finance team.
Take a recent month of card transactions and establish three figures. Count how many had a verified receipt attached, how many were checked against policy at the line-item level, and how many were compared against the expense system for duplicates. Where those figures are unknown, the program is being reconciled rather than managed, and the gap is entirely after authorization. Our companion guide to corporate travel card programs covers the design decisions upstream of it.
Corporate card management is the full set of activities that make up a company card program. Those are issuance and entitlement, spend limits and controls, policy, reconciliation, receipt collection, transaction review, and offboarding. The review half of that work takes place after transactions post.
Level 2 data adds the tax amount, a customer code, and the merchant's postal code to the basic transaction record. Level 3 adds line-item detail such as item descriptions, quantities, and unit prices. Level 3 makes policy checks at the line-item level possible, and its availability depends on the merchant.
Merchant category codes will not reveal it, because the merchant is usually a legitimate business. Detection comes from reading the receipt or the Level 3 line items, then comparing the purchase against the cardholder's business context. Patterns such as weekend activity at merchants unrelated to travel also point to it.
Yes, and it happens often. An employee attaches an itemized receipt to a report while the card feed brings in the same charge. The two often differ in amount and date once a tip or currency conversion is applied. Identifying it means comparing the two systems against each other.
Transaction review works best continuously, as charges post. The cardholder population, spend limits, and dormant accounts warrant a quarterly review, and the policy itself an annual one, or a review whenever the card program's structure changes.