Agentic AI expense audit and AP automation | AppZen

Corporate credit card fraud: Seven patterns and how to catch them

Written by AppZen | Sep 14, 2026, 3:39:34 AM

Corporate credit card fraud is the deliberate misuse of a company-issued payment card for spending outside legitimate business expenses. It differs from expense report fraud in timing, because the cardholder spends company money at the point of sale. Seven recurring patterns account for most internal card misuse, and each one is exposed by a particular level of transaction data.

Key takeaways

  • A card transaction has already settled when it reaches a review queue, so a month-end review produces findings nobody recovers. A team catches the next charge only by testing transactions as they post.
  • Five of the seven patterns are invisible inside a transaction total. Level 3 card data, which lists item descriptions, quantities, and unit prices, is what makes them visible.
  • Merchant category codes describe the type of business and nothing else, so a gift card and a box of pens look identical under one code.
  • The cheapest control on the list is a monthly reconciliation between the card system and human resources termination records. Any charge dated after a termination date is a finding by definition.

An employee with a company card spends company money at the point of sale. That single fact reorders everything about how misuse gets caught. An expense report is a request for money the organization still holds, and a check before payment stops the loss. A card charge is a completed purchase, so the same check afterwards starts a recovery. Seven patterns account for most of what internal card misuse looks like in practice. The level of data attached to each transaction then sets a hard limit on which of them a program ever sees.

The measured cost of corporate credit card fraud

Internal card misuse rarely produces a headline, which is part of the reason it persists.

The Association of Certified Fraud Examiners examined 2,402 cases across 143 countries and territories for Occupational Fraud 2026, its 2026 Report to the Nations. Asset misappropriation, the category that corporate card abuse belongs to, appeared in 90 percent of those cases. Across all 2,402 cases the median loss was $104,000 and the average loss exceeded $1.4 million.

Duration accounts for much of that loss. The 2026 study put the median fraud scheme at 12 months before detection. Schemes caught within the first six months showed a median loss of $40,000, while schemes lasting more than five years caused median losses above $1.1 million.

Detection stays largely accidental. Tips, meaning reports from employees, vendors, or customers, were the most frequently used detection method in the 2026 study, accounting for 43 percent of cases.

External fraud gets treated differently. The FBI Internet Crime Complaint Center recorded 1,008,597 complaints and $20.877 billion in losses in its 2025 IC3 Annual Report. External fraud of that kind usually gets a dedicated security program. Internal card misuse is commonly handled with a spreadsheet and a monthly sample.

Why card transactions are harder to control than expense reports

An expense report is a request for money. A card transaction is a completed purchase.

When an employee submits a report, the money still sits in the company's account. Every control applied before reimbursement therefore prevents a loss rather than recovering one. A reviewer declines the line or returns the report.

A card transaction has already settled by the time it appears in a transaction feed. The merchant has been paid and the meal has been eaten. Getting the money back from a current employee is slow, and the company is left with a payroll deduction, a policy warning, a write-off, or a termination.

A team therefore has to test transactions continuously rather than on a cycle. Auditing transactions as they post is the only window in which a second purchase at the same merchant, by the same cardholder, gets stopped before it happens.

The control also has to work without a receipt. Employees never submit a large share of card spend to the expense system, so no supporting document is attached to read. The transaction record itself is the only available signal. That is the gap behind the argument that corporate card auditing needs AI.

Seven patterns of corporate credit card fraud

Card misuse repeats in a small set of recognizable shapes. Naming them turns a general monitoring goal into testable rules.

1. Personal purchases on a company card

This is the most common pattern and the least sophisticated. Groceries, personal travel, consumer electronics, and household items go on the card, often with no expense report filed. The signal combines merchant identity with timing, such as weekend spend at merchants in residential areas, or charges in the cardholder's home city during a period with no business travel. The usual false positive is the employee who buys a legitimate item at a consumer retailer and intends to report it.

2. Cash advances and cash-equivalent purchases

Cash advances are prohibited under most card policies and carry fees on top of the amount withdrawn. The pattern extends well beyond the cash machine. Gift card purchases, prepaid card loads, money transfers, and cryptocurrency purchases all convert company credit into value that cannot be traced. Advances are identifiable from the transaction type. Cash equivalents are invisible inside ordinary retail purchases, where only line-level data separates a gift card from a stapler.

3. Spend positioned just under an approval threshold

Purchases above $500 might require approval. A run of $487 and $495 charges is then unlikely to be coincidental. Structuring of this kind is the clearest indicator of deliberate rather than careless misuse, because it demonstrates knowledge of the control. Detection depends on the distribution of a cardholder's spend rather than on single transactions. One $487 charge is unremarkable. Fourteen of them across a quarter is a finding.

4. One purchase split across several transactions

Splitting is the companion to threshold structuring. A $1,400 purchase becomes three charges at the same merchant inside a short window, each below the approval limit. The signal combines merchant, cardholder, and a narrow time window. Some splits are innocent, because merchants occasionally settle a large order in parts.

5. A legitimate merchant and a non-business item

This is the hardest pattern to catch from transaction data alone. An office supply retailer sells printer paper and also sells televisions. A hotel folio, meaning the itemized bill for a stay, lists a room rate, a bar tab, a spa charge, and a movie. Only the line items record what was bought, which is why this pattern stays invisible to any program working from merchant name and total.

6. Subscriptions and recurring charges without an owner

Recurring charges accumulate quietly. A company keeps paying for software seats held by departed employees, trial subscriptions that converted to paid plans, duplicate tools bought by two teams, and services renewed years after a project ended. This is rarely fraud and frequently expensive. The signal is a recurring amount at a recurring interval with no named business owner, and the remedy is an ownership record rather than an investigation.

7. Cards still active after an employee leaves

Offboarding fails in a predictable direction. Building access is usually revoked on the last day. The card often stays open, because the finance team that cancels it hears about the departure through a monthly file. Any transaction dated after a termination date is a finding by definition. Catching it requires only that the card system and the human resources system agree on who works there.

What merchant category codes omit, and what L2 and L3 data add

The level of data attached to a transaction sets a hard ceiling on what any card program detects.

Basic transaction data provides the merchant name, the date, the amount, and the merchant category code (MCC). An MCC describes the type of business the merchant operates, and nothing more. A retailer that sells stationery, electronics, gift cards, and furniture carries one MCC across all of them. A restaurant MCC does not separate a client dinner from a family birthday. Acquirers, the banks that process card payments for merchants, assign the codes, so the codes are occasionally wrong and rarely updated when a business changes what it sells.

Level 2 (L2) card data adds the fields a finance team needs for tax and matching. Those are the sales tax amount, a purchase order or customer reference code, a merchant tax identification number, and freight or duty amounts. L2 data makes a transaction reconcilable and links spend to a requisition, which supports value-added tax (VAT) recovery and general ledger accuracy.

Level 3 (L3) card data adds the line items. Item descriptions, quantities, unit prices, product codes, and tax calculated at the line level all appear at this level. L3 data turns a $312 charge at an office retailer into four reams of paper, two toner cartridges, and a $180 gift card.

That distinction matters because five of the seven patterns above need line-level detail. Cash equivalents, non-business items at approved merchants, hidden folio charges, duplicated subscriptions, and split purchases are all invisible inside a total. Not every merchant transmits L3 data, so finance teams have to confirm with their card issuer which of their merchants provide it.

Where corporate card programs commonly fall short

Most programs are not badly designed. They are sampled.

Finance teams typically review 10 to 20 percent of transactions, a gap examined in our analysis of 100 percent audit coverage. That leaves four out of five charges unexamined. The unreviewed fraction is where repeat patterns go unnoticed, so the sample rate sets the detection rate.

Rules-only monitoring is the second gap. A fixed threshold rule catches the transaction above the limit and misses the fourteen just below it. Most of the patterns described above appear only across a series of transactions.

The third gap is the separation of card spend from expense spend. Many organizations audit expense reports in one system and monitor card transactions in another. A charge that appears on the card feed and again as an out-of-pocket claim then gets paid twice.

The fourth gap is timing. A review that happens after the statement closes produces a report rather than a control.

How we approach corporate credit card fraud

Our platform audits 100 percent of card transactions as purchases post, rather than sampling a statement afterward. The timing is the substance of the approach, because catching the pattern on the second transaction prevents the third.

Our AI reads L2 and L3 card data where merchants provide it, so the audit tests line items rather than totals. A gift card inside an office supply purchase is visible at the line level and invisible above it, as is a spa charge buried in a hotel folio. Where line detail is missing, the audit falls back on cardholder-level pattern analysis, meaning threshold clustering, split purchases, and merchant frequency.

Card Audit and Expense Audit run against the same data, which closes the double-payment gap between a card charge and an out-of-pocket claim for the same purchase. The platform routes exceptions to a reviewer with the evidence attached, and clean transactions clear without human handling. Our corporate card expense management overview sets out how the coverage works.

An automated finding does not establish intent. It reports that a transaction failed a named check and shows the evidence. Whether the cause was an error, a habit, or something more serious stays a judgment for the finance team.

The bottom line

Corporate credit card fraud is a timing problem before it is a detection problem. The change that matters most is running the check as a transaction posts rather than at month-end. Work out what share of card spend receives review before the statement closes, then reconcile the cardholder list against termination records, which is the least expensive control on the list. Our post-authorization view of corporate card management covers the rest of the program.

Frequently asked questions

What is corporate credit card fraud?

Corporate credit card fraud is the deliberate misuse of a company-issued card for spending outside legitimate business expenses. It includes personal purchases, cash advances and cash equivalents, purchases structured to avoid approval limits, and continued card use after an employee leaves.

How is corporate credit card fraud different from expense report fraud?

Expense report fraud is a request for money the company still holds, so a check performed before payment prevents the loss. Card fraud has already settled when the transaction posts, which turns the process into recovery. That is why a team has to test card transactions continuously.

What are L2 and L3 card data?

Level 2 (L2) card data adds fields such as the sales tax amount, a purchase order reference, and the merchant tax identification number. Level 3 (L3) card data adds line items, meaning descriptions, quantities, unit prices, and line-level tax. L3 data shows what was actually purchased.

Why are merchant category codes not enough?

A merchant category code describes the type of business rather than the contents of the purchase. One code covers every product a retailer sells, so a gift card and a box of pens look identical. Acquirers assign the codes, and the codes are sometimes inaccurate or outdated.