Managing corporate credit cards: how the process runs

Corporate card management runs from policy to cancellation. Finance sets the rules and limits, a manager approves each request, the card administrator orders and maintains the card with the issuing bank, and the same administrator closes it when the holder leaves or no longer needs it.

The steps in order

  1. Set the card policy and approval limits. The finance lead or controller drafts it, and the CFO signs it off. The policy says who qualifies for a card and what it may be used for. It lists blocked merchant categories and default limits by role. It also names who can approve a request, a limit increase or an exception.
  1. Raise a card request. An employee or their manager fills in the request form. It needs a business reason, a cost centre and the limit being asked for. In many organisations onboarding triggers this automatically for certain job titles.
  1. Approve the request. The line manager confirms the business need. The card administrator then checks eligibility against policy. Any limit above the role default goes to finance for a second approval.
  1. Sign the cardholder agreement. The employee accepts personal responsibility for the card and completes any required training. The administrator keeps the signed agreement on file. No card is ordered without it.
  1. Order the card from the issuer. The administrator creates the account in the bank portal. Setup covers the spending limit, merchant restrictions and the billing hierarchy. The card is then mapped to the right cost centre and general ledger codes in the expense system.
  1. Deliver and activate. The bank ships the card to the holder or to a central address. The holder activates it. The administrator confirms that transactions flow into the expense tool before closing the request.
  1. Run the account day to day. This is where most of the work sits. The administrator handles lost or stolen cards, declined transactions, fraud alerts and changes of address. The expense or accounts payable team matches statement lines to submitted claims, chases missing receipts and flags spend that breaks policy. Persistent offenders are reported to their manager.
  1. Approve or change a credit limit. The holder asks for the change with a reason. Their manager approves it. Finance approves anything above the threshold in the policy. The administrator makes the change in the portal. Temporary increases for travel or events should be set to revert on their own, since manual reversals are easily forgotten.
  1. Cancel or deactivate the card. Triggers include a leaver notice from HR, a move to a role that no longer needs a card, misuse, or long inactivity. The administrator deactivates the card in the portal. Pending charges are allowed to settle, then the account is closed. Outstanding receipts are collected before the holder's last day, and the physical card is destroyed or returned.

Who owns what

Finance owns the policy and approves exceptions. Line managers own the business case for each card and review their team's spend. The card administrator, often sitting in accounts payable or treasury, is the single point of contact with the bank. HR owns the leaver and mover signals that drive cancellation. When HR does not notify the administrator, cards outlive their holders.

Where practice tends to drift

The written process usually assumes clean handoffs. In practice, managers approve requests without reading them, limits creep upward through temporary increases that never revert, and cancellations depend on someone remembering to send an email. Reconciliation is often the step most out of date in the documentation. Teams build their own workarounds in spreadsheets, and those workarounds become the real process.

Questions to ask the people who run it

  • Who actually decides whether someone gets a card, and does the policy match how that decision is made?
  • How does the administrator learn that a cardholder has left or changed roles? What happens when that notice never arrives?
  • Are there cards in use that nobody can tie to a current employee or cost centre?
  • When a temporary limit increase ends, what returns the limit to normal?
  • Which approvals get waived when someone senior is in a hurry?
  • How are missing receipts chased, and what happens after a holder ignores the reminders?
  • Does anyone review blocked merchant categories, or were they set once at implementation?
  • Where does reconciliation happen outside the expense system, and why?
  • What do the bank's own reports show that internal reports do not?
  • Which part of the process generates the most complaints from cardholders, and which from finance?

Sources

APQC's Process Classification Framework® (PCF) is an open standard developed by APQC, a nonprofit that promotes benchmarking and best practices worldwide. To download the full PCF or to view definitions and measures, please visit www.apqc.org/pcf.