Modern corporate cards ship with dozens of controls, integrations, and dashboards. Most of it is polish. Five controls do the real work of preventing fraud and making a card program safe enough to hand to a 30-person team.
1. Per-card spend limits
The simplest, most effective control ever invented. Set a monthly cap on every card the day it's issued and forget it. If a card is compromised, your worst-case loss is capped at the limit — not the balance of the account.
2. Merchant category locks
Every transaction carries an MCC — a code that identifies the merchant type. Restrict the ad-buying card to marketing MCCs and it becomes useless the second it's stolen. Block cash withdrawals globally and you cut off the fastest route to loss.
3. Country restrictions
The single highest-leverage rule in card fraud prevention. Lock each card to the two or three countries where the cardholder actually spends. This alone stops the vast majority of card-testing attacks, which almost always originate from a country your team doesn't operate in.
4. Time-of-day and recurring windows
Business cards should transact during business hours. Subscription cards should only transact on the day of the month the subscription renews. Anything outside the window is an anomaly worth reviewing.
5. Instant freeze
One tap, on any device. Freezing a card must be the fastest action in your entire finance stack. Investigate later.
"Everything else is polish. Get these five right and you've eliminated 95% of card-fraud risk before it happens."




