Gartner® report CFO Guide to Governing Agentic AI Read now

Corporate travel card programs: A finance controls buyer guide

A corporate travel card is a payment card issued to employees for business travel, charged to an account the company or the employee holds. Evaluated properly it is a control surface rather than a rewards product, because it commits company money before anyone reviews the purchase. Check liability, card data depth, and review cadence to see whether it is auditable.

Key takeaways

  • Under a card program, finance checks the purchase after payment rather than at a gate before it. Everything else in the program follows from that shift.
  • Four models place liability and data differently, namely individual liability, corporate liability, a central travel account, and virtual cards. Most enterprises run a mix.
  • Merchant category codes describe the merchant rather than the purchase. Level 3 card data is what separates a room rate from a minibar charge on the same folio.
  • Review cadence is the weak point in most programs rather than the card itself. Reconciling at month-end means a reviewer sees a problem roughly a month late, if at all.

Comparisons of these cards usually rank rewards rates and sign-up bonuses, a framing inherited from consumer credit. At enterprise scale the more consequential questions are who carries the liability, how much detail the card data returns, and what a provider can answer before a contract is signed.

Why a corporate travel card is a controls decision

A corporate travel card changes the moment a company becomes exposed to a purchase. Under a reimbursement model, an employee spends personal money and finance reviews the claim before paying it. Under a card program, the charge posts against a company account first.

The shift matters because travel spend is high in volume, small in individual value, and hard to verify from a bank feed alone. Most policies set thresholds against a published benchmark rather than deriving one from scratch. The GSA per diem bulletin FTR 26-01 set the FY2026 standard continental United States (CONUS) lodging rate at $110 per night. Standard meals and incidental expenses (M&IE) are $68, with tiers from $68 to $92. Those rates took effect October 1, 2025, run through September 30, 2026, and were held level with FY2025.

Cap lodging at the standard CONUS rate, with an adjustment for high-cost cities, and the program has to show which hotel charges cleared that line. A posting record with a merchant name, a date, and a total does not answer the question. It also does not separate a room rate from parking, resort fees, or in-room dining billed on the same folio. A policy threshold is only as enforceable as the data the card program returns to finance.

Four models for a corporate travel card program

Four models dominate enterprise travel, and each places the liability, the data, and the review burden somewhere different.

  • Individual liability. The employee holds the account, pays the issuer, and then claims reimbursement. Delinquency exposure stays with the employee, and finance keeps a review gate before payment. Spend stays invisible until a report is filed.
  • Corporate liability. The company holds the account and pays the issuer directly. Transaction data arrives whether or not a report is filed, and the company takes on delinquency exposure. Review always happens after the fact.
  • Central travel account. A lodged account pays for air and rail, meaning a single account held centrally with no plastic issued to travelers. Booking data and payment data arrive together, which usually makes air the cleanest category in the program.
  • Virtual cards. A single-use card number is generated for a booking, a supplier, or a traveler over a fixed window. Amount limits, date ranges, and merchant restrictions are set when the number is issued, so an out-of-policy charge fails at authorization rather than surfacing in an audit six weeks later.

Most enterprise programs run a mix, placing air and hotel on a central account or on virtual cards while using corporate liability cards for unplanned spend. That mix determines both your exposure and the quality of your data, which is why it gets settled before providers are shortlisted.

What to evaluate in a corporate travel card program

Rewards and fees are the simplest part of a comparison. The dimensions below determine whether the program is auditable.

Liability, delinquency, and offboarding

The first dimension is who carries the balance and what happens as it ages. Under corporate liability, the company absorbs delinquency risk, so write-off policy, dispute handling, and cardholder escalation belong in process design. Individual liability leaves employees exposed to their own credit, and employees under payment pressure tend to file reports faster and to inflate claims more. Offboarding is a separate test, measured by how quickly a card is suspended once a termination is recorded in the human resources system.

Card data quality, Level 2 and Level 3 detail

Card networks return purchase data at three levels of detail. Level 1 covers the basics, meaning merchant name, date, and total. Level 2 (L2) card data adds tax amounts, customer codes, and cleaner merchant identifiers. Level 3 (L3) card data adds line-item detail, including item descriptions, quantities, and unit prices.

With L3 detail, a reviewer can split a $312 hotel charge into a room rate, a parking line, and a minibar line, then apply the policy to each. Coverage varies by merchant, so ask a provider what share of transaction volume delivers L2 and L3 detail, broken out by merchant category. Programs that return L3 on airfare and little else are common, and controls built on the assumption of line-item detail fail where that detail is absent.

Why merchant category codes are not enough

A merchant category code (MCC) describes the merchant rather than the purchase, and it stays fixed regardless of what is bought. A restaurant MCC does not distinguish a client dinner from a team lunch or a bar tab. An airline MCC does not record the cabin class, or whether a ticket was refunded and rebooked.

MCC blocking still earns a place as a blunt front-end control. Blocking gambling, jewelry, and cash-advance codes prevents obvious misuse at authorization. It works as a floor rather than as a detection strategy, a point our piece on corporate card auditing develops further.

Reconciliation and the receipt-matching gap

Every card program creates a gap between the transaction record and the evidence supporting it. The card feed posts on the issuer's cycle. The receipt arrives when the employee remembers it, or never, since most policies waive receipts below a threshold. Matching on amount and date breaks in ordinary cases, including tips added after authorization, partial refunds, split folios, currency conversion, and one booking charged as several transactions.

Two details are worth confirming with a provider. The first is how the feed handles credits and reversals, and in particular whether the original transaction identifier survives a partial refund. The second is how quickly an authorization converts to a posted record.

Personal use, cash access, and misuse patterns

Personal use is the most common card problem and the least dramatic. It appears as weekend transactions with no matching trip record, or as charges in the cardholder's home city. Recurring subscriptions billed to a travel card and cash advances drawn against a corporate account belong in the same category. None of it is visible in a monthly total, and all of it becomes visible when a reviewer compares transactions against travel bookings, calendars, and prior behavior. The patterns behind corporate card fraud are consistent enough to support written rules.

Control questions to put to a provider

  • Ask what share of transaction volume returns Level 2 and Level 3 data, by merchant category.
  • Ask how long a transaction takes to move from authorization to a posted record in the feed.
  • Ask which limits are settable per cardholder, including single-transaction caps, daily velocity, MCC blocks, and geographic restrictions.
  • Ask what happens to the transaction record when a charge is refunded, partially credited, or rebilled.
  • Ask how the platform ties a virtual card or central account charge back to the original booking.
  • Ask what the automated path is from a termination record to a suspended card.

Where corporate travel card programs fall short

Almost every program reconciles on a monthly cycle and reviews a sample of what it finds. That design sets a floor on how quickly a problem can be detected, and the floor is expensive. The Association of Certified Fraud Examiners (ACFE) examined 2,402 cases for Occupational Fraud 2026. The median scheme lasted 12 months before detection. The median loss was $40,000 in schemes caught within six months, against more than $1.1 million in schemes that lasted five years or longer.

Duration is the one variable a finance function controls directly. Reconciling at month-end means a reviewer sees a problem roughly a month late, if at all, and sampling extends that further, because most enterprises review only 10 to 20 percent of expense transactions. The weak point is the review cadence rather than the card program.

How we approach corporate travel card controls

We built Card Audit for the interval between a transaction posting and anyone examining it. Our AI audits 100 percent of card transactions as purchases post, and it reads Level 2 and Level 3 card data rather than treating the merchant category code as the whole record. Those audits cover 42 languages across 97 countries, which matters for a travel program handling regional tax documents and receipts in several scripts.

Continuous review changes what the controls are for. In place of a monthly reconciliation that surfaces a problem after the quarter closes, exceptions surface while the trip is current and the cardholder still remembers the purchase. Our AI Agents resolve routine issues on their own, Smart Workflows route the remainder to a reviewer, and Team Insights shows managers how their own teams spend. Our corporate card expense management approach uses the card feed you already receive.

The bottom line

Select a corporate travel card program on the data it returns and the liability it assigns, then set the review cadence to match how quickly that data arrives. For a controller, line-item detail and same-cycle visibility carry more weight than any rewards rate. The six questions above give a vendor conversation a controls agenda rather than a perks agenda.

Frequently asked questions

What is a corporate travel card?

A corporate travel card is a payment card issued to employees for business travel spend, such as airfare, lodging, ground transport, and meals. The account may be held by the company or by the employee, and that choice sets who carries the balance and when finance reviews the purchase.

What is the difference between corporate liability and individual liability cards?

Under corporate liability, the company holds the account and pays the issuer directly, so transaction data arrives whether or not an expense report is filed. Under individual liability, the employee pays the issuer and claims reimbursement, which preserves a review before payment and hides spend until a report is submitted.

What is a central travel account?

A central travel account is a lodged account that pays for air and rail centrally, with no cards issued to travelers. Booking data and payment data land in the same place, so air spend reconciles more cleanly than any other travel category.

Why are merchant category codes not enough for card controls?

A merchant category code describes the merchant rather than the purchase, so it stays the same regardless of what an employee buys. Level 2 and Level 3 card data add tax and line-item detail, which is what separates a room rate from a minibar charge on the same folio.

How often should corporate travel card transactions be reviewed?

Review them as they post, rather than at month-end. ACFE research published in 2026 found a median loss of $40,000 in schemes caught within six months, against more than $1.1 million in schemes that lasted five years or longer. Shortening the time to detection is the control that changes the loss.