An expense policy written in a PDF is worthless until it is enforced at every transaction. That is exactly what corporate card spending limits are for: turning an internal rule ("no meal over £35, no personal spending") into an automatic decline at the payment terminal. Configuration is what separates a card you merely tolerate from one that genuinely protects the budget. This article breaks down the control levers available on a modern corporate card: amount and period limits, category restrictions (MCC), geo-restrictions, real-time controls, and profile-based rule sets.
- Spending limits are not just a monthly amount: effective configuration combines amount, period, category (MCC) and geography.
- MCC codes allow you to block or allow merchant categories (fuel, hotels, restaurants, gambling…) at transaction time[1].
- The card is only an enforcement tool: without a formalised expense policy, spending limits are just window dressing[2].
Why corporate card spending limits matter
Without a controlled card, expense management happens after the fact: the employee pays, keeps the receipt, fills in an expense report, and the finance team discovers the overspend weeks later — at reconciliation. The damage is done. Spending limits reverse the timeline: the rule applies before money leaves the account. A transaction that exceeds a limit is simply declined at the terminal, or held pending approval from a line manager.
For the finance team, the benefit is twofold. First, budgetary: capping exposure per card, and therefore per individual, makes budgets predictable. Second, operational: no more chasing missing receipts or going back and forth with employees. The card does not eliminate expense reports, but it dramatically reduces the volume of disputes. For employees too, it is a simplification: they know immediately what they can pay for, without having to memorise an abstract grid of rules.
A spending limit is a line of defence, not an emergency brake. Properly configured, it prevents non-compliant spending before it occurs, freeing the finance team from manual oversight.
The four dimensions of a spending limit
On a modern corporate card, a spending limit is not a single figure. It breaks down across four combinable axes, which give your controls their full granularity:
| Axis | What it caps | Example |
|---|---|---|
| Amount | Per transaction, per day, per month | Max €80/transaction, €500/month |
| Period | Rolling or calendar window | Monthly limit reset on the 1st |
| Category (MCC) | Allowed or blocked merchant family | Hotels OK, casinos blocked |
| Geography | Accepted country or region | France only, or Europe + Morocco excluded |
The power comes from combining these axes. A field sales rep on the road might have €1,500/month across all categories in France, but no more than €80 per meal and no ATM withdrawals. A procurement manager, by contrast, might have a higher monthly limit but restricted to a few MCCs (supplies, software subscriptions) with restaurant spending blocked. A single card can therefore carry a radically different policy depending on its holder's profile. That is what distinguishes a true corporate card from a basic business debit card.
The technical pillar: MCC codes
A Merchant Category Code (MCC) is a four-digit code that the card networks (Visa, Mastercard) assign to each merchant to classify their business activity. Category blocks are built on this code: rather than banning "casinos", you block MCCs 7800 to 7802 and 7995. The network returns the MCC at transaction time, and the card accepts or declines according to the configured rule[1].
A few MCCs worth knowing when building an expense policy: restaurants cover MCCs 5811–5814, hotels 3501–3839 and 7011, fuel 5541, ATM withdrawals 6011, and gambling 7995. A modern platform such as Greenway's fuel card or a specialist provider lets you tick these categories directly in the back office, without entering codes one by one. You allow a business perimeter (transport, hotels, tolls) and block everything else, an allowlist approach that is more secure than the reverse.
One limitation to keep in mind: the MCC reflects the merchant's activity, not the specific item purchased. A department store classified as "general retail" will pass through a pen purchase or a television purchase under the same code. That is why MCCs do not replace complementary controls on amounts and receipts — they filter categories, not line items[3].
Geo-restrictions and real-time controls
Geo-restriction addresses a simple risk: a French corporate card has, by default, no reason to be used outside a defined area. You activate France only for an office-based employee, Europe for travelling sales reps, and explicitly exclude high-fraud countries. Configuration is done by country or region, and proves invaluable in preventing a stolen card from being used abroad between the theft and the block.
Real-time controls go further. At every transaction, the back office can trigger an alert (mobile notification to the manager), require hierarchical approval above a threshold, or immediately block an unusual payment — atypical amount, new country, sensitive MCC. The delay between the network authorisation request and the software decision has shrunk to a few hundred milliseconds, making these controls usable without penalising the terminal experience[4].
Tailoring policy by profile and team
This is where configuration really comes into its own. An effective expense policy is not one-size-fits-all: it adapts to each person's role. The standard approach is to define profiles (field sales, procurement, senior executive, office-based employee) and assign each one a coherent set of spending limits and MCCs. A travelling sales rep will have hotels, transport and restaurants enabled with a comfortable monthly limit; a procurement manager will have a perimeter restricted to approved suppliers but higher individual transaction amounts.
This profiling work must be grounded in a formalised expense policy: eligibility criteria (who gets a card), permitted and prohibited uses, limits by category, required documentation, cardholder responsibilities and consequences for non-compliance[2]. Without this reference document, spending limits are arbitrary and become hard to defend if an employee disputes a decline. With it, every parameter points back to an internally validated rule signed by the cardholder, which also protects the company from a legal standpoint.
A sample governed expense policy
To make this concrete, here is what an operational expense policy looks like for an SME of around forty employees. Three profiles coexist: field (sales reps, 12 cards), procurement (purchasing team, 4 cards) and executives (management committee, 5 cards). Each profile carries its own limits × MCC matrix.
| Profile | Limit / month | Active categories (MCC) | Geo |
|---|---|---|---|
| Field | €1,200 | Fuel, hotels, transport, meals | France + EU |
| Procurement | €8,000 | Supplies, software, professional services | France |
| Executives | €5,000 | All except gambling & ATM withdrawals | Worldwide |
This matrix is configured once in the back office and duplicated for every new card issued. The gain is measured not only in avoided overspend, but in management time: disputed expense reports have dropped sharply, accounting reconciliation is mechanical since every transaction arrives pre-categorised, and internal audits amount to checking the consistency between policy and its execution. For organisations looking to push automation further, pairing this with a virtual card dedicated to each cost centre adds another layer of granularity, and a CSR-driven card (see our analysis of the corporate card in service of CSR) adds native sustainability reporting on the same data.
A spending limit does not replace a receipt. Even with well-targeted MCCs, require proof of purchase above a threshold (typically €25): it is mandatory for VAT recovery and essential in the event of a tax or social security audit.
Frequently asked questions
What spending limits can be set on a corporate card?
Corporate card spending limits can be configured across four combinable axes: amount (per transaction, per day, per month), period (calendar or rolling window), merchant category via MCC codes, and geographic area. The company sets these parameters card by card, according to the holder's profile.
How do you block a spending category on a corporate card?
You block a category by acting on the corresponding MCC codes. The Visa or Mastercard network assigns every merchant a four-digit code; by blocking, for example, MCC 7995 (gambling) or 6011 (ATM withdrawals), those payments are declined at the terminal[1].
Can a corporate card be restricted to one country?
Yes, that is geo-restriction. You activate France only, Europe, or a defined set of countries, and explicitly exclude the rest. Useful for office-based employees and effective against fraudulent use of a stolen card abroad.
Do real-time controls slow down the payment?
No, they are transparent to the cardholder. Cross-checking the four axes (amount, period, MCC, geo) and triggering any alert takes place within a few hundred milliseconds, inside the network authorisation window[4].
Is a written expense policy needed in addition to spending limits?
Yes, it is essential. The policy formalises eligibility, permitted uses, responsibilities and sanctions, and every cardholder signs it. Spending limits are simply the technical enforcement of that policy: without it, they are contestable and legally fragile[2].
Are MCC codes enough to categorise a spend?
No. An MCC describes the merchant's activity, not the specific item purchased: a department store will process a pen or a television under the same code. MCCs filter spending categories but must be complemented by amount controls and receipt requirements[3].
Pillar article: this guide to spending limits and expense policy is part of our corporate card and professional payments white paper, which connects spend controls, expense reports and financial oversight.
References
- Finom, Card payments: understanding categories and MCC codes (detailed code table by family: restaurants 5811–5814, hotels 3501–3839, fuel 5541, ATM 6011, gambling 7995). help.finom.co. ↩
- SAP Concur, 7 corporate card policy rules to implement (eligibility, permitted uses, limits, documentation, responsibilities, sanctions, signed agreement). concur.fr. ↩
- Tapix, Why MCC codes are not always enough to categorise a payment (limits of merchant-activity-based MCC). tapix.io. ↩
- CIC, Corporate Cards: real-time spend tracking, personalised limit configuration, alerts and restrictions. cic.fr. ↩