Corporate card fraud looks nothing like consumer card fraud. There is almost never a stolen plastic card in the street: the risk comes from a compromised online payment, an impersonated supplier, an employee bypassing a spending category, or a card number recycled on a high-risk site. The good news is that corporate card security against fraud is configured before an incident occurs, not after. Spending limits, merchant category code (MCC) blocking, geo-restrictions, 3-D Secure, single-use virtual cards: these are settings, and they make the difference between a controlled card programme and a silent cash leak.
- Card fraud in France is at its historic low (0.048% of amounts paid in H1 2025), but the risk has shifted towards social engineering (+37%), which primarily targets businesses[1].
- Controls go beyond spending limits: MCC blocking, geo-restrictions and single-use virtual cards absorb most of the risk before it becomes a loss.
- Network "Zero Liability" is not automatic on commercial cards: the guarantee depends on the issuer and requires prompt reporting[2].
B2B fraud looks different from B2C fraud
Public figures from France's Payment Security Observatory (Banque de France) tell a two-sided story. In the first half of 2025, card fraud fell to €211 million, approximately €48 frauded per €100,000 paid, its lowest level ever recorded[3]. At the same time, social engineering fraud (phishing, fake supplier scams, CEO fraud) rose 37%, reaching €245 million[1]. Translated for a finance team: the card itself holds up well — it is the people around it who are being targeted.
A corporate card compounds this risk for two reasons. First, it carries spending limits far higher than a personal card, a fraudulent debit of €5,000 goes unnoticed where it would immediately alert a consumer. Second, traceability is diluted: the same card number may be used by multiple employees, shared for a recurring purchase, or stored with five different SaaS vendors. Card configuration is therefore not a compliance detail — it is the first line of defence.
Five settings that do the heavy lifting
The majority of incidents are preventable with five controls configurable from any decent back-office. None require custom development, and all can be applied in minutes per card or per spending profile.
| Control | What it blocks | Example rule |
|---|---|---|
| Spending limits (amount / period) | Overspending, abnormal purchases | €2,000 / transaction, €10,000 / month |
| MCC blocking | Prohibited merchant categories | Casinos (7995), crypto, dating blocked |
| Geo-restriction | Countries outside business scope | Decline outside EU, or outside France |
| 3-D Secure (SCA) | Unauthenticated online payments | 3DS enforced on high-risk e-commerce merchants |
| Virtual cards | Reuse of a stolen card number | Disposable number, short limit and expiry date |
The principle is the same throughout: deny by default, allow by exception. The merchant category code (MCC) is the core building block. It is the four-digit code that classifies every merchant and determines authorisation. Expense management platforms use it to block or permit categories per cardholder[4]. A travelling sales rep has no business in a casino; a procurement officer has no need to pay an online gambling service. The MCC knows this, the setting enforces it, and the cardholder receives an immediate decline.
Spending limits and expense policy: the first layer
A poorly calibrated limit either lets fraud through or leaves employees stranded at a restaurant. The right approach is to break limits down into three dimensions, per transaction, per period (daily, weekly, monthly) and per MCC category, rather than setting a single global amount. A manager authorised to spend €2,000 on client entertainment does not need a single-transaction ceiling of €2,000. For a full methodology, our guide on spending limits and expense policy walks through the complete approach.
3-D Secure and virtual cards: the online anti-fraud duo
"Card not present" transactions, online payments where the card number is entered without the physical card, account for most of the residual risk. Two mechanisms contain it.
Strong customer authentication (SCA) via 3-D Secure 2. Stemming from the European PSD2 directive, it mandates two-factor authentication on most online payments, with defined exemptions (trusted beneficiaries, transaction risk analysis)[5]. On a corporate programme, 3DS can be enforced on high-risk e-commerce merchants and relaxed for trusted recurring suppliers, so legitimate purchasing is not penalised.
Single-use virtual cards. Rather than storing a permanent card number with every supplier, a dedicated number is generated, with its own limit, its own expiry date and sometimes its own authorised MCC, for a specific payment or project. If the number leaks, it is already expired. This is the most effective defence against fraudulent reuse, and the subject of our in-depth page on virtual cards for business.
Real-time alerts: detect before you suffer
Perfect configuration is not enough; you also need visibility over what is happening. Real-time alerts, push notifications or emails on every transaction, or only on out-of-policy transactions, turn the back-office into a monitoring station. Approaching a spending limit, a payment in an unusual country, repeated declines at the same merchant, two simultaneous payments 2,000 km apart: these are signals an automated system detects in a few hundred milliseconds that a human controller would take days to spot in a monthly statement.
The right alert threshold is not "notify everything" — that is a recipe for alert fatigue. Notifications should be reserved for transactions that breach a programme rule: a threshold exceeded, a sensitive MCC, a geography outside scope. Everything else can be reviewed after the fact, within the accounting workflow.
Prevention is configured, detection is automated. Block by default (MCC, countries, limits), enforce 3-D Secure on high-risk e-commerce, and never leave a permanent card number anywhere a single-use virtual card would suffice.
"Zero Liability" and "Zero Fraud": what they actually cover
Card networks promote anti-fraud guarantees (Zero Liability), and many issuers add their own "Zero Fraud" promises. Reading the brochure, one might assume full coverage in every scenario. The reality is more nuanced — and the gap is widest on commercial cards.
Visa's Zero Liability Policy, for example, explicitly excludes certain transactions on commercial cards and anonymous prepaid cards[2]. Mastercard's protection covers unauthorised fraudulent transactions, but only on condition of prompt reporting[6]. In short: the guarantee is neither universal nor automatic on a B2B programme, and depends largely on what your issuer has negotiated and contracted.
The practical implication: ask your issuer for the exact wording of the guarantee, the reporting deadlines (often very short), the exclusion clauses and the reimbursement process. And never confuse Zero Liability with the absence of risk: the guarantee kicks in after a loss — configuration prevents it from happening in the first place. The two are complementary, not interchangeable.
Best practices for prevention on a corporate card programme
Once controls are in place, security depends on routine. A few habits distinguish a robust programme from a porous one:
One cardholder, one use. Avoid cards shared between employees: they make traceability impossible and render per-profile limit assignment meaningless. Prefer one card per employee, or one virtual card per project.
Short, regular awareness training. Social engineering fraud is up 37% in a single half-year[1]. No configuration can withstand it if an employee clicks a malicious link. A ten-minute quarterly reminder on phishing and fake supplier scams is more effective than a lengthy annual training session that gets forgotten.
Audit the controls, not just the spend. Expense reports are reviewed regularly; what is reviewed less often is whether blocked MCCs are still blocked, whether limits raised as a temporary workaround were ever brought back down, and whether authorised countries still match the actual business scope. A quarterly audit of the configuration itself is what keeps defences current.
Suspend quickly, reactivate slowly. At the slightest suspicion about a card number, freeze the card from the back-office with a single click and issue a replacement virtual card to avoid disrupting legitimate activity. The cost of an over-cautious block is always negligible compared to the cost of uninterrupted fraud.
The Greenway corporate card, configurable by default
The Greenway corporate card includes these controls as standard: per-transaction and per-period spending limits, MCC blocking, geo-restrictions, real-time alerts and on-the-fly virtual card issuance. The goal is not to stack up security features for show, but to make fraud structurally difficult, so the card serves its purpose of enabling payments, rather than keeping the finance team up at night.
Frequently asked questions
What are the essential controls against corporate card fraud?
Five: spending limits (per transaction and per period), merchant category code (MCC) blocking, geo-restrictions, 3-D Secure enforced on high-risk e-commerce, and single-use virtual cards. Combined, they absorb most of the risk before an incident occurs.
Does Visa / Mastercard "Zero Liability" cover corporate cards?
Not automatically. Visa's Zero Liability Policy explicitly excludes certain transactions on commercial cards, and Mastercard's requires prompt reporting[2][6]. The actual coverage depends on your issuer and your contract. Verify the exact wording before relying on it.
What is the purpose of merchant category code (MCC) blocking?
An MCC is the four-digit code that classifies every merchant. Blocking by cardholder profile allows certain categories (gambling, crypto, dating...) to be denied by default, and only the categories relevant to the employee's role to be permitted[4].
Is 3-D Secure mandatory for corporate online payments?
Strong customer authentication (SCA), mandated by PSD2, applies to most online payments in the EU, with defined exemptions (trusted beneficiaries, risk analysis)[5]. On a corporate programme, 3DS is typically enforced on high-risk merchants and relaxed for trusted recurring suppliers.
Do virtual cards genuinely reduce fraud?
Yes, significantly. A single-use virtual card carries its own limit, its own expiry date and sometimes its own authorised MCC; if the number leaks at a supplier, it is already unusable. It is one of the most effective defences against fraudulent reuse of a stolen card number.
What should you do if you suspect fraud on a corporate card?
Suspend the card immediately from the back-office, issue a replacement virtual card to avoid disrupting legitimate activity, report the incident to the issuer within the contractual deadline (often very short) to preserve the guarantee, then audit recent transactions. An over-cautious block always costs less than uninterrupted fraud.
Pillar article: this guide is part of our corporate card and professional payments white paper, which connects security, spending limits, virtual cards and corporate expense management.
References
- BFMTV / Observatoire de la sécurité des moyens de paiement (Banque de France), Social engineering fraud: +37% in H1 2025, reaching €245m. bfmtv.com. ↩
- Visa, Zero Liability Policy: exclusions (commercial cards, anonymous prepaid cards). visa.com. ↩
- BFMTV, Card fraud at historic low: €211m in H1 2025, €48 frauded per €100,000 paid. bfmtv.com. ↩
- Corpay, Merchant Category Codes (MCC): how they control corporate card programs. corpay.com. ↩
- France Num (gouv.fr), Online payments: strong customer authentication under PSD2 (SCA) and exemptions. francenum.gouv.fr. ↩
- Mastercard, Zero Liability Protection: conditions (prompt reporting of unauthorised transactions). mastercard.com. ↩