The data belongs to whoever holds top-of-wallet
Industry commentary on card portfolios makes the relationship point more sharply than the revenue one. As one banker put it in a 2026 discussion of build-versus-buy for card programs, a card is a relationship tool: if a customer uses another institution's card every day, that institution gains the insight into spending behaviour, digital engagement and financial needs, and losing top-of-wallet status weakens the broader relationship over time.
That is the strategic frame worth holding. The spend file is not a byproduct of the card program. For a business customer, it is the highest-frequency, most current record the institution has, and it arrives without asking the customer for anything. Sector guidance for community banks and credit unions in 2026 has been making the same argument, pointing at transaction signals that reveal inactive cards, declining spend and business card opportunities sitting unused inside portfolios institutions already own.
The competitive pressure is real too. Digital-native challengers built integrated corporate cards with embedded expense management and took share from traditional commercial banking in the small business segment. They did not win on credit terms. They won on the reporting and control experience wrapped around the card, which is a software problem rather than a balance sheet one.
So there are three distinct things an institution can do with commercial card spend, and they carry very different risk. Keeping them separate is the whole discipline here.
Three uses, three different risk profiles
These get discussed as one capability and should not be. The first is low risk and underused. The second is genuinely useful and regulated. The third is a document problem wearing a data costume.
| Use | What it draws on | Risk and what it is good for |
|---|---|---|
| Relationship and portfolio signals | Spend trend by customer, category mix, dormancy, share-of-wallet erosion, seasonality, merchant concentration | Low risk. This is marketing and relationship management using your own customer data. Agents can surface the accounts worth a call this month rather than leaving it to whoever opens the report |
| Early warning on existing credit | Spend contraction, category shifts, sudden concentration changes, payment behaviour on the card itself | Moderate. Useful as a monitoring input alongside covenant and financial reporting. Treat it as a prompt to look rather than as a rating action in itself |
| Input to a credit decision | Card spend as a forward-looking supplement to financial statements and bureau data in underwriting | Highest. Genuinely valuable, because statements and filings are backward-looking, but the moment spend informs an approval or a decline it carries adverse action and fair lending obligations |
| Expense, receipt and statement documents | Receipts, expense reports, reconciliation packets, statements the customer sends back | Document processing, not analytics. High volume, low value per item, and where a lot of the servicing cost in a card program actually sits |
| Customer-facing reporting | The spend visibility and controls the business customer sees | Product, not insight. This is where challengers competed and won, and it is a build decision rather than an analytics one |
The first two rows are where most institutions have unused capacity. The card portfolio already generates the signals; almost nobody has anyone reading them systematically, because doing so by hand across a portfolio is not a job anyone has time for.
The third row is where the governance conversation belongs, and it is covered further down. The general case for forward-looking cash flow data in credit is in cash flow-based credit scoring; this article is specifically about the card-derived slice of it and what owning the issuing relationship adds.
Four things that make this work rather than generate noise
Spend analytics programmes usually fail the same way: they produce a dashboard nobody opens. These are the differences in the ones that get used.
Output an action, not a metric
A dashboard showing spend down 22% at forty accounts is a reporting artefact. A short weekly list naming the six accounts where the change is large enough, sustained enough and unusual enough for that customer to warrant a call is a workflow. The second gets used because it fits inside somebody's morning.
Baseline against the customer, not the portfolio
Seasonality is the whole problem. A landscaping business and a tax practice have opposite cash years, and a portfolio-wide threshold will flag both wrongly. Comparison against the same customer's own prior periods is what makes an alert mean anything.
Keep it a prompt, not a conclusion
Spend movement has innocent explanations far more often than not: a supplier changed terms, a project ended, the owner switched cards for points. The signal is worth a conversation. It is not worth an automated action, and treating it as one is how an institution damages a good relationship.
Decide the use before you build it
Relationship management and credit decisioning look like the same analysis and are not the same activity. One is marketing on your own customer data. The other triggers regulatory obligations from the moment it influences an approval. Build them as separate paths with separate approvals, or the easier one will quietly become the harder one.
The fourth is the one worth writing down before any work starts, because the drift is subtle. A relationship model that starts recommending which customers to call becomes, over a few quarters, a model that shapes who gets offered credit and on what terms. That is a different regulated activity, and the documentation trail needs to have been built from the beginning rather than reconstructed afterwards.
Five obligations that come attached to the spend file
This is the section most treatments of the topic omit. What follows describes the landscape as of September 2026 and is not legal or compliance advice; how any of it applies depends on the institution, the product and the jurisdiction.
It is customer financial data, with the privacy rules that implies
Commercial card transaction data sits inside the institution's privacy framework. Permissible use, sharing with affiliates and third parties, retention, and what the customer was told at account opening all govern what can be done with it. The relevant question before a new analytical use is not whether the data is available but whether this particular use is within what has been disclosed and agreed.
Using it in credit creates adverse action obligations
Regulation B requires specific and accurate reasons for adverse action, and it applies to business credit as well as consumer. If card spend contributes to a decline or a reduction in a line, the institution has to be able to state the reason accurately and trace it. A signal that cannot be explained in a sentence to a customer is a signal that should not be driving the decision.
Proxy risk is real in category data
Merchant category and spend pattern data can correlate with characteristics that must not influence a credit decision. This is not an argument against using the data; it is an argument for testing the outcomes rather than assuming neutrality because no prohibited characteristic was an input. Fair lending testing of any spend-derived credit model belongs in the plan from the start.
Model governance now has a gap you have to fill yourself
The revised interagency model risk guidance issued on April 17, 2026 as SR 26-2 replaced SR 11-7 and explicitly places generative and agentic AI outside its scope, directing institutions to their own risk management. A traditional scoring model built on spend data is covered; an agent summarising portfolio signals and drafting recommendations is not. The wider version is in AI agents for financial services.
The vendor questions are the same ones as everywhere else
Where the data is processed, what is retained, whether your customers' transaction data trains anyone's models, which model version produced a given recommendation and whether that is retrievable later. Card data is more sensitive than most, so the answers matter more. The list in SOC 2 Type II for commercial lending AI applies unchanged.
What stays with people
The useful division is the same as everywhere else in this category. Preparation and pattern-spotting can be automated. Anything that reaches the customer, or changes their credit, does not.
- The call itself. A spend signal produces a conversation, and the conversation is the point. What has changed in the business, whether it is temporary, and what the customer needs are things only a relationship manager finds out.
- Any credit action. Reducing a line, declining an increase, changing terms. These reach the customer and carry notice obligations, and they need a named decision-maker.
- The judgment on what is unusual. Thresholds should be set by people who know the portfolio, reviewed when they produce noise, and documented. An alert rule nobody owns becomes an alert rule nobody reads.
- Everything logged with its reason. Which signal fired, on what data, what the recommendation was, what the human did about it. This is the record that makes the programme defensible if it ever influences credit.
- The decision not to act. Worth recording explicitly. A reviewed-and-dismissed alert is evidence of a working process; a silently ignored one is evidence of nothing.
Where Uptiq fits
Uptiq is not a card analytics platform, and this article is not a pitch for one. Where Uptiq's agents fit a card programme is the document layer and the credit workflow either side of it: receipts, expense reports, reconciliation packets and statements classified and extracted at volume, and the borrower documents that sit alongside a spend signal when a relationship manager escalates something into a credit conversation. Every extracted value carries a citation back to its source page, adjustments are surfaced for a person to accept or reject rather than applied silently, and every override is retained with its reason and user. The agents run alongside the existing core, card platform and origination systems through 100+ integrations.
A sequence that does not start with a model
The temptation is to begin with scoring. The better order begins with something nobody has to approve.
Start with dormancy and share-of-wallet erosion
The lowest-risk, highest-certainty use in the whole list. Which business cards have gone quiet, which customers have shifted spend elsewhere, which relationships are thinner than they were a year ago. This is relationship management on your own data and it needs no credit governance at all.
Add per-customer baselining before adding more signals
Comparison against the same customer's own history rather than a portfolio threshold. Getting this right is what stops the second phase producing noise, and it is worth doing before anything else is layered on.
Automate the document side in parallel
Receipts, expense reports and reconciliation packets are a volume problem with no analytical risk attached. It runs independently of the analytics track and usually pays back sooner.
Only then consider credit use, with compliance in the room from the start
If spend data is going to inform underwriting or line management, involve credit, compliance and fair lending before the build rather than at review. Decide how a reason will be stated to a customer, how outcomes will be tested, and what documentation the model risk function receives.
Measure whether anyone acted
Not alerts generated. Calls made, conversations that surfaced something, retention or expansion that followed. An alerting system with no measured downstream action is a cost centre that looks like a capability.
The document-processing side of this is covered in document processing for banking operations, and the review discipline for anything an agent produces in how to review AI-generated output.
Frequently asked questions
What are corporate card spend insights?
Analysis of the transaction data a commercial card programme generates: spend trends by customer, merchant category mix, seasonality, dormancy, share-of-wallet movement and payment behaviour. For the business holding the card it is an expense management feature. For the institution issuing it, it is a continuously updating record of how a business customer actually operates, which is useful for relationship management, portfolio monitoring and, with more care, credit.
Can AI agents use card spend data in credit decisions?
Technically yes, and it is genuinely valuable because financial statements and filings are backward-looking while spend is current. But it is not a free input. Regulation B requires specific and accurate adverse action reasons, and it applies to business credit, so any spend-derived factor contributing to a decline has to be explainable and traceable. Merchant category data can also correlate with characteristics that must not influence credit, so outcome testing belongs in the plan. Involve compliance before the build, not at review.
What is the lowest-risk place to start?
Dormancy and share-of-wallet erosion. Identifying which business cards have gone quiet and which customers have moved spend elsewhere is relationship management on data the institution already owns, with no credit governance attached. It also builds the per-customer baselining that everything more ambitious depends on.
Why does per-customer baselining matter so much?
Because seasonality dominates. A landscaping business and an accounting practice have opposite cash years, so any portfolio-wide threshold will flag both incorrectly and the alerts will be ignored within a month. Comparing a customer against their own prior periods is what makes a change meaningful, and it is the difference between a system people use and a dashboard nobody opens.
Does the revised model risk guidance cover this?
Partly. SR 26-2, issued April 17, 2026, replaced SR 11-7 and covers traditional models, so a conventional scoring model built on spend data falls inside it. The guidance explicitly places generative and agentic AI outside its scope, so an agent that summarises portfolio signals and drafts recommendations does not, and the institution's own framework governs it. Confirm the position with your own compliance and model risk functions.
Should an institution build card spend analytics or buy it?
That depends on whether the target is customer-facing reporting or internal insight. Customer-facing spend controls and reporting are a product decision, and the segment where digital-native challengers competed most effectively. Internal relationship and portfolio signals are usually better approached as a workflow layered over data you already hold than as a platform purchase, because the hard part is producing an action someone takes rather than producing the analysis.
Market and industry observations reflect publicly available commentary and sector reporting as of September 2026, including 2026 discussions of card portfolio strategy and community institution banking priorities; these are directional rather than measured findings. Regulatory references include Regulation B adverse action requirements and the revised interagency model risk management guidance issued in April 2026. Nothing here is legal, compliance, fair lending or supervisory advice; how these obligations apply to your institution and products should be confirmed with your own counsel and compliance, credit and fair lending functions.
Start with the document side
The receipts, expense reports and reconciliation packets your card servicing team is keying by hand. We will run them on your own files and show you where every value came from.
