Because they intervene at the exact point where legitimate customers are trying to complete a transaction. If identity verification, risk scoring or manual review is too strict, the control reduces conversion and weakens trust. The goal is not maximum blocking, but calibrated decisioning that protects the business without making normal customer journeys unnecessarily hard.
Why fraud controls slow down onboarding and checkout
Fraud controls create friction because they inspect or interrupt a customer journey that is designed to be fast. The more a control asks for proof, cross-checks signals, or pauses for review, the more likely it is to add abandonment risk, even when the customer is genuine. The practical challenge is deciding where extra friction is justified by fraud loss reduction.
At onboarding, friction usually comes from identity proofing, document checks, device and behavioural screening, or step-up review when a profile looks unusual. At checkout, the same pattern appears through score thresholds, payment verification, and challenge flows that protect against abuse but can also penalise legitimate edge cases, such as new customers, international buyers, or high-value orders.
Good fraud design is therefore not “more control” in the abstract. It is calibrated decisioning: enough signal collection to stop clearly risky activity, but not so much friction that normal customers feel blocked, mistrusted, or forced to abandon the transaction.
Where the friction comes from in practice
The main source of friction is a mismatch between the control’s caution level and the customer’s intent. Onboarding usually demands higher confidence because it is where the relationship begins, while checkout is where speed matters most. If a rule treats every uncertain case as suspicious, legitimate users are pushed into manual review or repeated verification steps that feel disproportionate to the moment.
Friction also increases when the control is opaque. Customers are more tolerant of extra steps when the reason is clear, the delay is brief, and the outcome is predictable. When the process looks arbitrary, the business pays twice: first in conversion loss, then in support demand and reduced trust.
In fraud operations, the hardest balancing act is deciding which signals should trigger a hard block, which should trigger a softer challenge, and which should only inform post-transaction monitoring. That distinction matters because the same signal can be useful without being strong enough to justify interruption.
How to balance fraud protection with conversion
Fraud controls work best when they are tuned to the stage of the journey and the value of the transaction. Low-risk users should move through the path with minimal challenge, while higher-risk cases can be stepped up with additional verification. That keeps the control focused on exceptions instead of turning every customer into a suspect.
Calibration also depends on operational ownership. Fraud, product, and customer experience teams should agree on the decision thresholds that matter most: approval rate, false positive rate, manual review rate, and downstream loss. If those metrics are not reviewed together, one team can “win” on fraud reduction while the business loses revenue through avoidable drop-off.
Where onboarding is concerned, some friction is unavoidable because the control has to establish trust before access or spending is granted. Where checkout is concerned, the bar should be higher before forcing intervention, because the customer already has intent and any extra delay has a more immediate conversion cost.
Risk and Threat Considerations
Overly strict fraud controls can create a structural business risk by blocking legitimate customers at the exact moment they are ready to complete a transaction. That reduces conversion, increases abandonment, and can push low-friction competitors ahead even when your fraud prevention is technically effective.
Failure mechanism: Rules that are tuned too conservatively, or manual review queues that are too slow, force genuine users into challenge loops, false declines, or delayed approvals. Attackers may also exploit this by creating noisy activity that raises friction for everyone else, making the journey worse for legitimate customers.
Impact: The business loses revenue and trust, customer support volume rises, and fraud teams can become isolated from commercial outcomes. In severe cases, the control posture becomes self-defeating because customers abandon the path before risk decisions can even help.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-8 — Identification and Authentication (Non-Organizational Users) | Onboarding friction often comes from customer identity verification controls. |
| IA-5 — Authenticator Management | Checkout friction is often driven by step-up checks, tokens, and verification prompts. | |
| Recommendation — Calibrate customer verification steps to the minimum assurance needed for the transaction risk. Limit step-up prompts to high-risk cases and keep authenticator flows fast for normal users. | ||
| CIS Controls v8 | CIS-5 — Account Management | Fraud controls in onboarding depend on controlled account creation and review. |
| Recommendation — Align account onboarding checks with fraud risk so legitimate users are not blocked unnecessarily. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access control decisions shape how much friction is added during customer onboarding and checkout. |
| A.8.5 — Secure authentication | Checkout and onboarding friction often comes from authentication and verification steps. | |
| Recommendation — Apply access decisions proportionately so friction increases only when risk justifies it. Use authentication strength that matches the risk of the customer action being taken. | ||
Practitioner Guidance
What to prioritise: Tune controls by journey stage and transaction value, not with one universal threshold. Checkout usually needs the lightest viable intervention, while onboarding can tolerate more verification if the customer is clearly being granted ongoing access or spend capability.
What to verify: Measure false declines, manual review delays, and conversion drop-off together. If fraud loss is falling but abandonment is rising, the control is probably overcorrecting and needs recalibration.
Practitioner takeaway: The best fraud control is the one that concentrates friction where uncertainty is real, not where it is merely convenient to enforce.
Related resources from NHI Mgmt Group
- Who is accountable when fraud controls create too much friction?
- How should e-commerce teams reduce checkout friction without weakening fraud controls for returning shoppers?
- How should payment service providers use fraud controls to improve merchant acceptance rates without adding checkout friction?
- Why do traditional fraud controls create so much friction for legitimate customers?