Join our Newsletter — 33% off our NHI Course

How should fraud and risk teams balance growth with security without adding friction for good customers?

The strongest approach is to treat trust and safety as a shared business function, not a standalone risk gate. Teams should align fraud controls with product and revenue goals, then apply adaptive friction based on user behavior. That lets security respond to fraud patterns while preserving a smooth journey for legitimate customers and reducing unnecessary review burden.

How to balance conversion goals with fraud controls

Fraud and risk teams get the best results when they stop treating controls as a blanket gate and start treating them as a decision layer. The practical question is not whether to add friction, but where friction changes the outcome enough to justify the customer cost. That means aligning policy to business value, customer segment, and transaction context rather than applying the same threshold everywhere.

In practice, the balance comes from making the control respond to confidence signals. Low-risk, repeat, and well-understood behavior should move quickly, while uncertain or unusual activity should trigger step-up review, additional verification, or delayed settlement. That approach preserves conversion for good customers and concentrates operational effort where fraud pressure is highest.

Teams usually make better decisions when they measure controls in terms of both loss prevented and customer experience preserved. A control that blocks fraud but creates excessive false positives can damage revenue, support capacity, and retention. A control that is too invisible can also fail quietly if it does not actually change fraudster behavior.

What adaptive friction should look like

Adaptive friction works best when it is proportional, explainable, and reversible. Proportional means the user only sees added steps when the risk signal warrants it. Explainable means the policy is consistent enough that product, operations, and customer support can understand why a transaction was challenged. Reversible means the team can tune rules quickly when a legitimate flow is being over-blocked.

Typical controls include step-up authentication, velocity checks, device and behavior scoring, selective manual review, and tighter limits on higher-risk actions. The important design choice is to place friction at the moment of highest uncertainty, not at the start of every journey. That keeps the good-customer path short while still protecting the points in the flow where loss is most likely.

For teams working in payments and identity-heavy environments, FinCEN is a reminder that controls often serve both customer trust and regulatory obligations, especially where transaction monitoring and suspicious activity handling intersect. In the same spirit, current control guidance for authentication and least privilege, such as PCI DSS v4.0 and NIST SP 800-53 Rev 5 Security and Privacy Controls, reinforces the value of restricting higher-risk actions without forcing every customer into the same experience.

Where fraud and risk programs usually go wrong

The common failure is overcorrecting for fraud spikes by broadening friction across the entire customer base. That can reduce short-term loss, but it often shifts the cost into abandonments, support escalations, and manual queue growth. Another failure is treating fraud controls as static, which leaves the team chasing yesterday’s attacker behavior while legitimate users are still absorbing the friction.

Teams also run into problems when they do not differentiate between policy intent and operational effect. A rule that looks safe on paper may be too coarse in production if it flags too many good users, especially in onboarding, recovery, and high-value transactions. The reverse is also true: a smooth journey can still be weak if the risk model is not sensitive to change in device, behavior, or transaction pattern.

When controls depend on tokens, device signals, or session trust, authentication quality matters too. Standards such as RFC 9449: OAuth 2.0 Demonstrating Proof of Possession (DPoP) and RFC 7523: JWT Profile for OAuth 2.0 Client Authentication and Authorization Grants show why sender-constrained and strongly authenticated flows matter when you want to reduce abuse without adding unnecessary manual review.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while PCI DSS v4.0 defines the regulatory obligations.

Framework Control / Reference Relevance
PCI DSS v4.0 8.6 — Authentication mechanisms and passwords for system and application accounts Fraud controls often rely on stronger authentication for higher-risk actions.
Recommendation — Require stronger authentication for high-risk customer and system actions.
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Adaptive friction depends on managing authenticators and step-up controls safely.
AC-6 — Least Privilege Risk-based restriction of actions aligns with limiting access by need and context.
Recommendation — Manage authenticators to support step-up verification without excess friction. Limit sensitive actions to the minimum access needed for the risk level.
NIST CSF 2.0 PR.AA-05 — Identity management, authentication, and access control Balancing friction with trust requires risk-based authentication and access control.
Recommendation — Apply risk-based authentication and access control to preserve user experience.

Practitioner Guidance

What to prioritise: Start with the journeys that create the most loss or the most customer drop-off, then tune controls at those points first. A small improvement in high-volume checkout, account recovery, or payment authorization usually matters more than tightening a low-volume edge case.

Decision rule: If the user action is low value and high uncertainty, add friction; if the user is known, repeat, and behaving within normal bounds, keep the path as close to frictionless as possible. That simple rule helps teams avoid turning every control into a blanket blocker.

What to measure: Track fraud loss, false-positive rate, review volume, abandonment, and time-to-complete together. If one metric improves while the others degrade sharply, the policy is not truly balanced.

What good looks like: Good customers move through the core journey with minimal interruption, while suspicious behavior is slowed, challenged, or reviewed in a way that meaningfully changes attacker economics. The control set should feel selective, not random.

Practitioner takeaway: The right balance is not “less security” or “more friction”, it is tighter targeting, so every added step has a clear fraud justification and a measured customer cost.