DEV Community

Payneteasy
Payneteasy

Posted on

Mastercard adds new controls to virtual card platform, Setting New Integration Standard for PSPs and Merchants

Mastercard has added Issuer Enforced Controls and upgraded Clearing Controls to its In Control virtual card platform, along with a new Commercial Connect API, with Citi as the first issuer to deploy the full set — a move that sets a new standard for the integration and risk controls PSPs and merchants need to support as virtual card use grows across countries and currencies.

The Commercial Connect API gives customers one integration point to manage virtual cards, addressing what Mastercard calls a common problem. The update also lets companies apply one set of controls across multiple linked virtual cards without exposing card details, and combines card creation with payment initiation in a single step. Issuer Enforced Controls **let issuers set spend limits, transaction caps, and validity periods at the moment a virtual card is created, before it's ever used. **Clearing Controls, upgraded from a 2025 launch, now let corporates and platforms block invalid transactions, apply more detailed rules, and manage payment timing after authorization.

For PSPs and acquiring partners, this is a signal that competitive differentiation in B2B card issuing is shifting toward control granularity and API-first integration rather than the card product itself. Issuer Enforced Controls and upgraded Clearing Controls raise the bar on what issuing/processing partners are expected to offer — pre-authorization risk parameters and post-auth clearing-stage blocking are becoming baseline expectations, not premium features. PSPs working with corporate/B2B card programs should watch whether their own risk and control stack (spend limits, validity periods, granular clearing rules) can match this, since large issuers like Citi are setting the bar.

For merchants, particularly those receiving B2B payments or operating supplier/procurement flows, the embedded VCN expansion (procurement, AP, travel, healthcare) means more of their B2B counterparties will pay via virtual cards embedded directly in ERP/procurement platforms rather than through separate payment steps. Merchants and platforms integrated with PayNetEasy should anticipate more embedded VCN traffic and may need acceptance/reconciliation flows tuned for virtual-card-specific data (dynamic card numbers, controls tied to specific transactions) rather than static card acceptance.

Top comments (0)