A pricing model that rewards a fraud partner based on approved transactions or other outcome measures instead of flat service delivery. It aligns commercial incentives with merchant revenue goals, discourages unnecessary declines, and supports a more accountable operating model for fraud management.
Expanded Definition
A performance-based fee structure is a commercial arrangement in which a fraud or risk partner is paid for measured outcomes, such as approved transactions, conversion uplift, or agreed service results, rather than for hours worked or a flat monthly retainer. In payments and fraud operations, the model is designed to align the provider’s incentives with merchant revenue and customer experience, but the exact metric matters more than the label. If the wrong outcome is chosen, the structure can reward volume over quality, or tolerance over control.
The term is often used alongside fraud management, chargeback reduction, and decisioning services, but it is not the same as guaranteed loss reduction. Guidance-vs-consensus note: there is no single industry standard for the “best” performance metric, so contract design usually depends on the merchant’s risk appetite, refund profile, and fraud-loss tolerance. A common boundary mistake is to treat any success-based pricing as automatically aligned; in practice, the incentive can be helpful only when the measurement method is clear and auditable.
Examples and Use Cases
Performance-based fees appear in operating models where the buyer wants to pay for measurable fraud outcomes rather than generic support. They are most useful when both sides can agree on a clean baseline, a review period, and the exact event that counts as success.
- A merchant pays a fraud review partner per approved transaction above a baseline, so the partner is motivated to reduce false declines without relaxing controls indiscriminately.
- An e-commerce business ties part of the fee to chargeback rate improvement, but only after excluding seasonal spikes and campaign-driven traffic changes from the measurement window.
- A payments team uses outcome-based pricing for manual review services, where the provider is rewarded for fast, accurate disposition rather than raw case throughput.
- A fraud operations leader accepts a hybrid model with a fixed floor plus performance uplift, trading some pricing predictability for stronger alignment to business outcomes.
- A merchant insists on disputeable metric definitions because the same “approved transaction” can mean different things across checkout, authorization, and settlement stages.
The main tradeoff is between alignment and simplicity. The more tightly the fee follows business outcomes, the more attention the contract needs on baselines, exclusions, and attribution rules.
Security Implications
The security value of a performance-based fee structure is that it can reduce the incentive for a provider to over-decline transactions simply to appear conservative. That matters because excessive declines can create their own operational harm, including lost revenue, customer abandonment, and pressure on internal teams to bypass controls that seem to “break” conversion.
Mismanaged incentives can also create weaker fraud governance. If the provider is rewarded only for approval volume, it may underweight suspicious activity, tolerate risky edge cases, or optimize for short-term metrics that hide longer-term loss. If the measurement method is unclear, disputes quickly move from operational debate into commercial conflict, making it harder to assess whether poor outcomes came from fraud pressure, poor tuning, or a flawed fee model.
For merchants, the observable symptom is often a mismatch between business and control performance: approvals rise, but so do chargebacks, manual review exceptions, or post-transaction losses. For the provider, the failure mode is metric gaming, where narrow contractual targets distort behavior instead of improving fraud decision quality.
Domain and Governance Relevance
In the fraud and payments domain, this term matters because it changes who owns outcome quality. A performance-based structure turns fraud management from a purchased activity into a governed operating relationship, which means the merchant must define what is being optimised, how exceptions are treated, and who can challenge the reported results.
That governance lens is more important than the pricing label itself. A contract that rewards approved transactions can support better commercial alignment, but only if the underlying control model still preserves fraud detection, chargeback management, and escalation authority. Where the arrangement depends on automated decisioning, the merchant also needs clear accountability for model drift, review overrides, and reporting integrity.
This term is not inherently about NHI or identity security, but it can influence how trust is assigned across tools, reviewers, and outsourced decision paths. In practice, the question is whether the fee model reinforces accountable fraud operations or quietly incentivises unsafe tolerance.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| PCI DSS v4.0 | 8.2 — Management of Authentication and Authorization | Payment fraud outcomes depend on controlled access and trusted transaction handling. |
| Recommendation — Apply 8.2 to ensure only authorised actors can change fraud decisions or payment controls. | ||
| CIS Controls v8 | 6 — Access Control Management | Outcome-based fraud operations still require tight control over who can approve or override transactions. |
| Recommendation — Use Control 6 to restrict approval and exception paths to authorised personnel only. | ||
| NIST CSF 2.0 | GV.RM — Risk Management Strategy | The pricing model changes incentive risk and governance for fraud operations. |
| ID.GV — Governance | The model requires clear accountability for metric design, dispute handling, and oversight. | |
| DE.CM — Continuous Monitoring | Performance structures need monitoring to detect metric gaming or deteriorating fraud outcomes. | |
| Recommendation — Define risk appetite so performance metrics do not incentivise unsafe approval behaviour. Assign governance for metric definitions, reporting integrity, and commercial accountability. Monitor approval, chargeback, and exception trends for signs of distorted incentives. | ||
Related resources from NHI Mgmt Group
- How should teams decide between token-based and flat-fee security testing?
- How should partners adapt to a performance-based channel programme in a security vendor ecosystem?
- How should partners evaluate whether a performance-based channel program will improve their pipeline and certification outcomes?
- Performance-Based Partner Programme