Card Lock & Lost Replacement
Card lock within 30 seconds of report
Card is lost, stolen, or compromised. Employee reports it to IT / finance, waits days for the block to happen, meanwhile potentially fraudulent charges accrue. Getting the replacement issued means another sequence of tickets, courier delays, and often flying blind for a week before the new card arrives. Every minute of delay is real money at risk.
An hour-by-hour walkthrough.
Step by step.
- 01
Detect lost / stolen / compromised card report
User message (Slack, email, app), card-provider fraud alert, or security team notification. Immediate action — no ticket queue.
Slack · Card provider fraud API · Security alerting - 02
Lock the physical card immediately
Provider API call to lock. Confirmed within 5 seconds. Prevents further physical-card charges.
Ramp · Brex · Amex · Airbase · Divvy - 03
Issue continuity virtual card
Virtual card with same limits + categories issued immediately. Secure delivery to user (in-app or encrypted DM). Continues business function during physical replacement.
Card provider virtual issuance · Secure delivery - 04
Review recent charges + flag suspicious
30-day charge review. Anything anomalous (unusual merchants, out-of-pattern locations, unusual amounts) flagged for user confirmation.
Fraud pattern detection · User confirmation - 05
Order replacement + close the loop
Replacement physical card shipped to user's address (verified). Delivery tracking; on activation, virtual card retired. Case closed with audit record.
Card provider shipping · Address verification · Tracking
What you connect to make this run.
Ramp · Brex · Amex · Airbase · Divvy
read+writeCard lifecycle: lock, issue virtual, order replacement, activate. All via provider APIs.
Slack · Teams · Secure DM
read+writeReport intake + secure delivery of virtual card details. Never sends card numbers over standard email.
Address service · HRIS
readShipping address verification to prevent misdirected replacements.
Fraud detection · Security alerting
read+writeSuspicious-charge patterns feed alerts; compromise-investigation coordination with security team.
Before and after, honestly.
Playbooks that pair with this one.
Answers about this playbook.
What if the user isn't sure whether the card is lost or misplaced?
Lock the card immediately; unlock is one-click when user finds it. Better to inconvenience for 20 minutes than absorb fraudulent charges.
How does it handle international travel where user needs local currency withdrawals?
Some cards support ATM PIN; virtual replacements support the same PIN. Card provider dependent; specific flows per provider.
What about corporate-card programs where card and identity are joined?
Compromised card + potential identity compromise triggers full security-incident flow, not just card replacement.
Can users lock their own card via app?
Yes — user-side app locks are always supported. Fin flow is for cases where user needs help or the report path is different.
How does it handle cards issued to service accounts (shared cards)?
Shared cards get different flow: lock + notify all users of the shared card + coordinate on continuity. Prefer per-user cards where possible.
See it run on your data.
Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.