Join our Newsletter — 33% off our NHI Course

Why does blanket friction often create more customer harm than fraud prevention value?

Blanket friction treats trusted users and fraudsters the same, which pushes good customers into unnecessary verification, lockouts, and support complaints. That can create customer insult, reduce conversion, and hide real fraud signals inside noisy controls. A risk-based approach works better because it aligns the strength of verification with the likelihood of abuse.

Why blanket friction backfires

Blanket friction usually fails because it applies the same verification burden to low-risk and high-risk users alike. That means trusted customers are forced through checks that do little to improve fraud detection, while real attackers often adapt, retry, or move to channels where the control is weaker. The result is more churn, more complaints, and less signal where it matters.

Good friction is targeted. It should be reserved for moments where the risk signal changes, such as a new device, a high-value action, or a materially different behaviour pattern. When controls are not risk-based, they become noise: they consume customer patience without meaningfully improving trust decisions.

How unnecessary friction harms fraud detection

Overly broad controls can make detection worse, not better. If every session, login, or payment path gets the same challenge, analysts lose the ability to distinguish normal customer activity from genuine abuse patterns. That creates alert fatigue, suppresses useful behavioural signals, and can push fraudsters to probe for the weakest part of the journey.

It also changes customer behaviour in ways that reduce security value. Legitimate users abandon high-friction steps, contact support, or find workarounds, which can introduce manual exceptions and inconsistent verification. Those exceptions often become the real control weakness because they are harder to monitor than the original friction point.

For a broader control perspective, Segregation of Duties (SoD) Guide shows why controls work best when they are aligned to the actual abuse path rather than applied as a blanket rule across every user and action.

What risk-based prevention does differently

A risk-based approach focuses friction where the probability and impact of abuse are highest. That usually means combining behavioural signals, device confidence, transaction context, account history, and step-up verification only when those inputs justify it. The aim is not to remove friction, but to make it proportionate to the threat.

This approach protects conversion because most customers move through low-risk paths with minimal disruption, while suspicious activity gets a stronger challenge. It also creates cleaner operational decisions: teams can tune thresholds, review exception rates, and measure whether a control is blocking fraud or merely adding drag.

If your programme touches onboarding or account takeover patterns, Identity Fraud Prevention Guide is a useful companion because it ties friction to fraud signals across the customer lifecycle rather than treating every interaction as equally risky.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST SP 800-53 Rev 5, NIST SP 800-63 and OWASP ASVS set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS-5 — Account Management Controls user friction by governing access paths and exceptions.
Recommendation — Align verification steps to account-risk signals and remove standing exceptions that add customer drag.
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Friction often comes from how authenticators are issued, used, and challenged.
AC-6 — Least Privilege Risk-based friction reflects least-privilege access decisions at the point of use.
Recommendation — Tune authenticator challenges to risk events instead of applying the same step-up everywhere. Grant stronger verification only when the action justifies elevated access or assurance.
NIST SP 800-63 Digital Identity Guidelines Assurance levels and step-up authentication support proportionate verification.
Recommendation — Map customer flows to the appropriate assurance level and step up only when needed.
OWASP ASVS V10 — OAuth and OIDC Customer friction frequently appears in authentication and step-up identity flows.
Recommendation — Use risk-based step-up authentication rather than forcing universal re-verification.

Practitioner Guidance

What to verify: Check whether each friction step has a clear risk trigger and a measurable fraud outcome. If you cannot point to the specific abuse pattern it is meant to stop, it is probably degrading the journey more than protecting it.

Decision rule: If the control affects all users equally, treat it as a candidate for redesign; if it only appears when risk rises, it is more likely to be defensible. The right question is not whether friction exists, but whether it is targeted enough to justify the customer cost.

What good looks like: Low-risk customers should see smooth completion, while suspicious cases see stronger challenges, better review quality, and fewer support escalations. If support volume rises without a matching fraud reduction, the control is usually too blunt.

Practitioner takeaway: The most effective fraud control is usually the one customers barely notice until risk meaningfully increases.