- Prevent the genuinely damaging, route the ambiguous, review everything else afterwards.
- Per-card limits and vendor-locked virtual cards deliver most of the practical benefit.
- Merchant category rules are blunt instruments — useful, but imprecise.
- Approval fatigue destroys the value of approval workflows.
- Dormant cards are the most common unaddressed weakness.
A hierarchy of controls
Not every risk deserves the same instrument. Ordering controls by cost-of-friction against loss-prevented produces a short, effective list.
- Per-card limits — near-zero friction, bounds every loss. Set these first.
- Vendor-locked virtual cards — no friction after setup, eliminates subscription sprawl.
- Single-use cards — small friction, large benefit with unknown merchants.
- Merchant category rules — moderate friction, blunt but useful for whole classes of spend.
- Approval workflows — highest friction; reserve for genuine judgement calls.
Why merchant category rules disappoint
Category codes are assigned by acquirers, not by you. A merchant selling software might be coded as a computer service, a business service, or something less predictable — and a single marketplace can carry a code that covers dozens of unrelated purchase types.
That makes category rules effective for broad exclusions and unreliable for precise policy. Use them to close off categories you never intend to use, not to enforce nuanced rules.
- Good: blocking categories the company never legitimately uses.
- Poor: distinguishing an allowed subscription from a disallowed one at the same merchant.
- Expect false positives, and give employees a fast route to resolve them.
Approval fatigue
An approver who receives forty requests a week approves them without reading. The control still exists on paper, still appears in the audit trail, and prevents nothing.
Target a handful of approvals per approver per week. If the volume is higher, the threshold is set too low, and lowering it further will only make the control less real.
Sequencing controls as you grow
| Headcount | Controls worth having | Not yet worth the friction |
|---|---|---|
| Under 20 | Per-card limits, virtual card per subscription | Approval workflows, category rules |
| 20–75 | Add one approval threshold, receipt rules | Multi-level approvals |
| 75–250 | Add cost centre budgets, delegated administration | Per-transaction pre-approval |
| 250+ | Add category rules for high-risk classes, access reviews | Anything requiring finance in the daily path |
The control everyone forgets
Dormant cards belonging to people who have left are the most common weakness we see. They are invisible because nothing is happening on them — until something does.
Two habits close the gap: card termination on the offboarding checklist, and a quarterly review of zero-activity cards with closure as the default.
Frequently asked questions
Only categories the company genuinely never uses. Default-deny rules generate constant false positives, and employees learn to route around them, which is worse than the original risk.
One that produces a handful of approvals per approver per week. Set it per cost centre rather than company-wide, since a marketing team's normal purchase is not an engineering team's normal purchase.
They enforce it. The policy still needs to say what people should do and why, particularly for situations no control can express — see writing an expense policy.
Keep reading
Sources and further reading
Every factual statement on this page is checked against primary documentation. Terms change frequently, so confirm details with the provider before acting on them.
- Visa — commercial payment solutions Network-level background on commercial card products and data levels.
- Mastercard — commercial payments Network-level background on commercial card programmes.
- Brex Support Center Official help documentation, including account access and card administration topics.
- Consumer Financial Protection Bureau — credit card resources Background on card terminology, billing cycles and consumer-vs-commercial distinctions.