Finance Index

An employee's corporate card was compromised - what do you do first, and who eats the loss?

Reference guide to corporate card fraud response, including card controls, policy design, employee spend workflows, receipt capture, and reconciliation.

Freeze the card immediately - most platforms allow instant freeze by the cardholder or finance - then dispute the fraudulent charges with the issuer, reissue the card, and migrate any legitimate recurring charges. Book disputed amounts to a suspense/receivable account while the dispute is open, not to expense. Speed matters: dispute windows are finite, and commercial card protections are generally narrower than consumer ones.

At a Glance

Aspect Short Answer Why It Matters
Corporate card policy Freeze the card immediately - most platforms allow instant freeze by the cardholder or finance - then dispute the fraudulent charges with the issuer, reissue the card, and migrate any legitimate recurring charges. Keeps spend tied to policy, ownership, and review.
Risk check Report to the issuer immediately (phone plus written confirmation), provide the cardholder's attestation, and expect provisional credit handling and final resolution to take weeks, sometimes a full billing cycle or two. Keeps spend tied to policy, ownership, and review.
Who eats the loss For true third-party fraud reported promptly, the issuer typically absorbs it under network zero-liability policies, but commercial card agreements often condition protection on prompt reporting and reasonable controls - read yours before you need it. Keeps evidence clear and reduces control risk.
How do we reduce Virtual cards by default, merchant locks on recurring relationships, low default limits with fast raise paths, MCC blocks, instant freeze capability, and real-time posting so anomalies surface in days. Keeps vendor records and payment decisions reliable.
An employee gave card It's murkier than card-number theft: when someone with authority voluntarily initiates or enables the payment, issuers may treat it as authorized, shifting loss to the company. Reduces payment errors, timing issues, and reconciliation cleanup.

How do I dispute fraudulent charges and what's the realistic recovery timeline?

Report to the issuer immediately (phone plus written confirmation), provide the cardholder's attestation, and expect provisional credit handling and final resolution to take weeks, sometimes a full billing cycle or two. Document everything - recovery quality tracks documentation quality.

Who eats the loss - issuer, company, or employee?

For true third-party fraud reported promptly, the issuer typically absorbs it under network zero-liability policies, but commercial card agreements often condition protection on prompt reporting and reasonable controls - read yours before you need it. The employee should essentially never eat third-party fraud; employee-perpetrated misuse is a different category entirely.

How do we reduce fraud exposure structurally?

Virtual cards by default, merchant locks on recurring relationships, low default limits with fast raise paths, MCC blocks, instant freeze capability, and real-time posting so anomalies surface in days. Structural controls beat vigilance - they work on the transactions nobody was watching.

An employee gave card details to a fake vendor in a phishing scam - fraud or our loss?

It's murkier than card-number theft: when someone with authority voluntarily initiates or enables the payment, issuers may treat it as authorized, shifting loss to the company. Report and dispute anyway, but treat this class of loss as a controls lesson - payment-detail changes and new-vendor requests need out-of-band verification, on cards as much as in AP.

What internal card fraud patterns should we watch for?

Fake or colluding merchants (often newly registered, single-customer), refund abuse (purchase on company card, refund to a personal card), personal spend disguised with plausible business merchants, and split transactions under review thresholds. Internal fraud hides in the gap between card data and business context - which is the argument for purpose attached at spend.

What should a card fraud runbook contain before fraud happens?

Who can freeze (cardholder and finance, 24/7), who owns disputes, the issuer's reporting channel and deadline, the GL treatment for disputed amounts, the comms template for affected cardholders, and the post-incident review step that asks what control would have stopped it.

How do we account for disputed charges across month-end?

Hold them in a suspense or receivable account, not expense, while disputed; recognize expense only if the dispute fails. Materially large disputes that straddle a close deserve a note in the close file so reviewers aren't re-deriving the story.

Stampli perspective

Stampli Card is built to shrink the fraud blast radius before fraud happens: virtual cards, vendor and merchant-category locks, and per-cardholder limits mean a compromised number has structurally little it can authorize. Real-time transaction posting means anomalous charges surface in the workflow as they occur rather than on a statement weeks later, and cardholders can suspend a card themselves the moment something looks wrong.