Mastercard has expanded its In Control virtual card platform with new security mechanisms, controls applied at different payment stages, and a unique Application Programming Interface (API) to connect banks, businesses, and financial platforms. The update aims to integrate corporate payments directly into enterprise resource planning, expense management, and accounts payable systems.
The essentials of Mastercard’s new virtual cards in 30 seconds
- Mastercard introduces mandatory limits that banks can set when creating each virtual card.
- Controls now extend to the settlement phase, following the initial authorization of the payment.
- Commercial Connect API combines card creation and payment initiation into a single integration.
- The network operates in 43 countries and supports transactions in 174 currencies.
- Citi is already using the new controls and plans to expand them internationally in 2026.
Virtual cards generate a different number than the physical card or primary account. They can be configured for a single provider, a specific amount, a limited number of transactions, or a set period. As a result, they are increasingly used for bill payments, corporate travel, and vendor purchases without sharing actual company credentials.
The In Control renewal aims to extend these rules beyond the initial number generation. Mastercard wants banks and companies to be able to verify limits throughout the entire transaction process, including settlement, when the authorized operation is presented for final clearance.
The system currently connects issuers, platforms, and businesses across 43 countries and allows processing payments in 174 currencies, according to Mastercard’s published data. The company has not disclosed the financial volume managed by its virtual card network in this announcement.
Controls that start at virtual card creation
One of the main innovations is called Issuer Enforced Controls. This feature enables the issuing entity to set minimum conditions at the moment the virtual card number is generated.
The bank can establish a maximum spending limit, restrict the amount per transaction, or specify the card’s validity period. These conditions act as a baseline that the user company cannot override when configuring their payment program later.
This separation is useful when multiple parties are involved in the process. For example, a bank can impose general limits, while a company adds more specific rules for its departments, employees, or suppliers.
A virtual card used to pay a €2,000 invoice could be limited to one transaction of that amount within a short period and for a specific type of merchant. Even if the number were exposed, its utility outside those conditions would be limited.
Mastercard states that virtual card fraud accounts for less than a fifth of that seen with non-virtual cards. The rate would be even lower when numbers are generated via In Control. These are Mastercard’s internal figures; the announcement does not detail the methodology, markets analyzed, or categories of fraud included.
Less exposure does not make these cards immune to attacks. Malicious actors could still attempt to use a valid number before expiry, manipulate an invoice, impersonate a vendor, or compromise the creation system’s credentials.
Limits mitigate some risks associated with credentials, but companies still need to verify bank account changes, separate approval functions, and review who can generate new cards.
Extending controls to settlement
The second component is Clearing Controls, introduced last year and now expanded with new capabilities. Its goal is to re-verify payment conditions during settlement, after the operation has received initial authorization.
Authorization and settlement are not exactly the same process. The first phase verifies if the card can make the payment and reserves the amount. Later, the merchant submits the transaction for final settlement.
Differences in amount, date, or details sent by the merchant can occur between these stages. New controls allow blocking transactions that no longer meet rules, refining restrictions and managing when payments are processed.
This additional check can be particularly useful during travel, where hotels, airlines, and car rental companies perform pre-authorizations that may not match the final amount. It can also apply to vendor payments if invoices change after card creation.
Citi already employs Issuer Enforced Controls and Clearing Controls. Mastercard expects it to be the first issuer to deploy both capabilities internationally in 2026, though no specific countries or timelines have been announced.
These controls are supported by tokenization, fraud monitoring, and Mastercard’s network infrastructure. Tokenization replaces a real account number with a different credential, so systems and merchants do not need to handle the original data directly.
An API for card creation and payment initiation
The other part of the announcement concerns Commercial Connect API, Mastercard’s interface designed to minimize the number of integrations needed to deploy a virtual card program.
Previously, a single entity might require different connections to issue the number, set conditions, initiate payment, receive transaction data, and transfer information to accounting systems. Commercial Connect API aims to provide a common entry point for these functions.
The update enables generating the virtual card and initiating the payment within one seamless process. It also supports multiple sets of controls at the token or funding account level, ensuring restrictions apply to all associated virtual credentials without exposing sensitive data.
Mastercard cites a study indicating that 69% of companies face challenges connecting their payment systems with enterprise applications. This data, drawn from marketing materials presenting the platform, has not been detailed further in the announcement.
Integration is important because a virtual card is more valuable when generated within the same environment where the invoice is approved. The number, limit, and provider can be automatically defined using existing data from enterprise resource planning (ERP) systems.
After payment, the card reference can be linked to the corresponding invoice to simplify reconciliation, reducing manual efforts to match bank transactions, purchase orders, and accounting documents.
Integrated payments in SAP and other enterprise platforms
Mastercard launched its integrated virtual card program in March 2025. Since then, it has partnered with specialized providers in ERP, accounts payable, expense management, travel, e-commerce, and healthcare.
SAP has recently enabled its participation in the program. The collaboration aims to incorporate virtual cards into treasury and working capital processes already managed within existing applications, rather than requiring them to operate through a separate payments platform.
Mastercard also collaborates with Emburse for expense management, Juniper Travel, HBX Group, and TravelSoft in the tourism sector, and with HSBC on a solution for the United Arab Emirates that integrates tokenized virtual numbers into mobile wallets.
These partnerships reflect a shift in corporate payments: moving from physical cards assigned to employees to software-generated credentials within automated processes.
A platform can create a card for each hotel reservation, invoice, or purchase order. The limit matches the approved amount, and the number becomes invalid once the transaction is complete. Additionally, companies gain information that can be linked to the vendor, project, and responsible department.
Mastercard’s 2025 annual report already indicated that its virtual card technology is integrated into more than ten international enterprise payment and travel management platforms—more than double the number from the previous year.
The new API and additional controls aim to extend this model without requiring each bank or platform to build all connections from scratch. Adoption will depend on available issuers in each country, service costs, and integration with each company’s existing systems.
Frequently Asked Questions
What is a Mastercard virtual card?
It is a number generated from an existing funding account. It can be limited by amount, provider, number of uses, or validity period without revealing primary credentials.
What changes with Issuer Enforced Controls?
Banks can set mandatory restrictions at the moment the virtual card is created, such as spending limits, maximum amounts per transaction, and validity periods.
What is the purpose of Commercial Connect API?
It enables businesses to connect with Mastercard’s virtual card functions through a unified integration, combining card creation and payment initiation into one process.
Does Citi already offer these features?
Citi is already implementing issuance and settlement controls. Plans are in motion to expand these capabilities internationally in 2026, although specific country or timeline details have not yet been published.

