Controlling employee business debit cards safely
How UK businesses can issue staff cards without losing control of spending, evidence, merchant use or account security.
Give each employee their own card or controlled spending profile rather than sharing a director’s card. Set limits that match the role, restrict cash or overseas use where the provider allows it, and require receipts promptly. Review cardholders when staff change jobs or leave. A card limit is only one control: the business still needs approval rules, transaction review and a clear process for freezing a card quickly.
Do not solve staff spending by sharing one card
Shared cards weaken accountability because it becomes harder to prove who made a transaction and who approved it. They also encourage unsafe sharing of PINs or security information. If the bank offers employee cards or separate user profiles, give each person an individual credential and only the access their job requires.
Keep cardholder authority separate from wider account authority. An employee who needs to buy supplies does not necessarily need to create bank transfers or become a signatory. Our guide to business account signatories explains that distinction.
Set limits around the job, not around trust alone
A sensible limit reflects what the employee normally needs to spend in a day or transaction. Where the provider supports it, consider separate controls for cash withdrawals, online purchases, contactless use, foreign spending or specific merchant types. The aim is not to make normal work difficult; it is to make an unusual transaction stand out quickly.
For teams with different responsibilities, create different spending profiles rather than one generous company-wide limit. A field engineer, office manager and sales director may all need cards, but their normal spending patterns are not the same.
Receipts and transaction review should happen quickly
Card controls work best when accounting evidence follows the transaction while memories are fresh. Require the employee to attach a receipt, invoice or short business purpose and reconcile transactions frequently. A missing receipt is easier to resolve after two days than after the year-end accounts are being prepared.
Connected expense apps can reduce manual work, but the accounting feed is not evidence by itself. Keep the source document and make sure personal spending, tips, refunds and split transactions are handled consistently.
Build a fast freeze-and-replace process
Employees should know exactly who to contact if a card is lost, stolen or used unexpectedly. If the banking app allows a temporary freeze, use it while the facts are checked, then cancel and replace the card if compromise is likely. Do not wait for a monthly statement when a suspicious transaction is already visible.
If card details are stolen but the physical card is still present, follow the bank’s fraud-reporting route and preserve evidence of the disputed transactions. Limit changes are not a substitute for reporting a compromised card.
Offboarding is part of card control
When an employee leaves or changes role, cancel or reassign their card access promptly and recover any physical card. Also remove related app access, expense-platform permissions and saved payment credentials. A clean leaver process matters most when the person had authority to spend without pre-approval.
Review the remaining cardholders after each staff change. A growing business can accumulate old cards and forgotten users surprisingly quickly if access is never reconciled against the employee list.
Watch for supplier and invoice fraud as well as card misuse
Employee cards are only one business-payment risk. Staff who can buy goods are also common targets for fake invoices, urgent payment requests and changed supplier details. Train cardholders and finance staff to treat unusual urgency, secrecy or bank-detail changes as warning signs.
Our guide to invoice-redirection scams covers the checks to use when a supplier asks for new bank details. Strong card controls and strong supplier-payment controls should sit in the same finance policy.
Frequently asked questions
Should employees share the director’s business debit card?
No. Individual cards or controlled user profiles create a clearer audit trail and avoid sharing PINs or credentials.
How low should an employee card limit be?
There is no universal figure. Set the limit around the employee’s normal business need and review it when the role changes.
What should happen to a card when an employee leaves?
Freeze or cancel it promptly, recover the physical card and remove connected banking or expense-app access.
Review permissions as staff roles change
Employee-card controls should not be treated as a one-time setup. Review who still needs a card, whether spending limits still match the person's role, and whether online, cash or international use should remain enabled. When someone changes job or leaves the business, remove or amend access promptly and keep a record of the change. This makes reconciliation easier and reduces the chance that an old permission remains active long after the operational need has disappeared.
Sources and verification
- Business.gov.uk — Getting a business bank account
- Charity Commission — Internal financial controls for charities
Oliver Grant — Markets & Regulation Writer
I would treat employee cards as delegated authority, not as miniature personal bank cards. The business is giving someone the ability to commit company money, so the control should be designed around the role. I prefer named cards, realistic limits and frequent transaction review over one high-limit card passed around a team. I would also make receipt capture part of the payment process rather than a month-end chase. The most important control is speed: suspicious spending should be visible quickly, and the person responsible should know how to freeze or cancel the card without searching for instructions. When staff leave, card cancellation belongs on the same checklist as removing email, accounting and online-banking access. I would review the full cardholder list at least periodically and ask whether each person still needs the same limit and permissions. Finally, employee spending controls should connect to the wider fraud process. A perfectly controlled card does not protect a business from a fake supplier or a compromised invoice. The finance policy should cover cards, transfers and bank-detail changes together, with clear escalation when a transaction falls outside the normal pattern.
MyBankAnswers uses official provider and UK regulatory sources wherever practical. Information is general and does not constitute financial advice.