By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: RiskifiedPublished July 26, 2026

TL;DR: Kogan says it exceeded 98% approval rates and identified $1.5 million in annual savings after improving fraud and policy abuse management with Riskified, while keeping chargeback rates below AusPayNet thresholds. The case shows that ecommerce fraud controls now have to balance loss prevention, identity signals, and customer experience rather than optimise for fraud blocking alone.


At a glance

What this is: This case study says Kogan improved approval rates and reduced fraud and policy abuse losses by using identity-based decisioning and automated dispute handling.

Why it matters: It matters because ecommerce teams need controls that distinguish legitimate customers from repeat abusers without adding false positives that suppress revenue or degrade checkout experience.

By the numbers:

👉 Read Riskified's case study on Kogan's approval rate and fraud controls


Context

Fraud and policy abuse in ecommerce is not just a loss-prevention problem. It is an identity and decisioning problem, because the control challenge is separating legitimate customers from repeat abusers, promo misusers, and high-risk transactions without blocking valid purchases.

In this case, the key governance issue is how much confidence a merchant can place in behavioural and device signals when approving card-not-present transactions. The identity angle is real here, because customer-level intent, session behaviour, and repeat abuse patterns shape who gets approved and who gets challenged.


Key questions

Q: How should ecommerce teams balance fraud prevention with approval rates?

A: Treat fraud prevention as a decision-quality problem, not a blocking problem. Use identity, device, behavioural, and history signals to distinguish legitimate customers from repeat abusers, then measure success with approval rate, chargeback outcome, and false-positive rate together. The goal is to reduce loss without suppressing good revenue.

Q: Why do policy abuse and fraud need different controls?

A: Because they create different kinds of loss and are often revealed through different patterns. Fraud may involve stolen payment details or account takeover, while policy abuse can involve promo misuse, serial returns, or chargeback exploitation. A single scoring rule usually misses that distinction and either under-detects abuse or over-blocks customers.

Q: What signals indicate that fraud controls are over-blocking good customers?

A: Watch for declining approval rates in specific segments, rising manual review volume, and strong chargeback suppression that comes with conversion loss. If the business is blocking more legitimate orders than it is preventing fraud, the model is too conservative and needs recalibration against customer-level intent signals.

Q: How do organisations know if chargeback automation is working?

A: It is working when manual effort drops, dispute outcomes improve, and review teams spend less time on low-value cases without a rise in unresolved loss. If automation simply moves more cases into a queue, the workflow is scaling complexity rather than reducing it.


Technical breakdown

Identity-based decisioning in card-not-present ecommerce

Card-not-present commerce depends on inference rather than direct physical verification, so fraud systems weigh device intelligence, behavioural signals, purchase history, and account patterns to estimate risk. Identity-based decisioning extends beyond a single transaction to link repeat behaviour across sessions and merchants. That matters because the same person can be legitimate in one context and abusive in another, especially when policy abuse, promo misuse, and chargeback behaviour are part of the same pattern. The technical question is not simply whether a transaction is fraudulent, but whether the actor's intent matches acceptable commercial behaviour.

Practical implication: merchants need decisioning models that join identity, device, and behavioural data before approval is finalised.

Chargeback guarantees and automated dispute workflows

A chargeback guarantee model changes the economics of fraud handling by shifting some financial exposure while requiring precise decisioning discipline. Automated dispute management reduces manual review load, but it only works well when the fraud signal quality is strong enough to avoid flooding operations with low-value cases. In practice, this is a controls problem as much as an operations problem, because poor triage leads to wasted analyst effort and inconsistent customer outcomes. The most relevant governance issue is whether the dispute workflow is tuned to the merchant's actual loss profile.

Practical implication: tie dispute automation to measurable fraud and policy-abuse categories rather than routing every exception into manual review.

Policy abuse detection as a revenue protection control

Policy abuse sits between fraud and customer behaviour management. It includes serial abuse of promotions, subscription chargebacks, and repeat misuse that may not always look like classic fraud but still erodes margin. Detection depends on correlating customer-level patterns over time, not just screening single orders. For ecommerce operators, this creates a governance challenge: the same analytics stack that reduces fraud can also help identify legitimate but unprofitable behaviour, which requires careful policy choices and transparent thresholds.

Practical implication: define which behaviours count as abuse, then tune controls so the same signal does not over-block valid repeat customers.


Threat narrative

Attacker objective: The objective is to extract value through fraudulent orders, policy abuse, or chargeback exploitation while avoiding detection and preserving enough legitimacy to keep accounts active.

  1. Entry occurs through card-not-present purchases, promo redemptions, and account activity where the attacker or abuser can blend into normal customer traffic.
  2. Escalation happens when repeat behaviour, serial policy misuse, or chargeback patterns exploit weak customer-level correlation and inconsistent review thresholds.
  3. Impact is margin erosion, unnecessary manual review, and blocked legitimate orders that degrade approval rates and customer experience.

NHI Mgmt Group analysis

Fraud and policy abuse controls are now an identity governance problem, not only a risk scoring problem. Kogan's results show that approval optimisation depends on understanding intent, repeat behaviour, and customer-level patterns rather than blocking as many transactions as possible. That shifts the control question from generic fraud reduction to identity-linked decision governance, where merchants need clear thresholds and review logic. Practitioners should treat identity signals as part of commercial governance, not just security telemetry.

Customer experience and abuse prevention now share the same control surface. If approval rules are too aggressive, legitimate customers are blocked; if they are too loose, serial abusers erode margin. That tension is especially visible in card-not-present ecommerce, where behavioural and device intelligence must be calibrated against business tolerance for false positives. Practitioners should align fraud policy with revenue, service, and risk objectives instead of optimising each in isolation.

Identity linkage is the real differentiator in policy abuse detection. The named concept here is customer-intent correlation: the ability to connect repeated sessions, devices, and behaviours to a single abuse pattern. Without that linkage, promo misuse and serial chargeback behaviour stay fragmented across transactions and escape review. Practitioners should build governance around linked behaviour, not single-order screening.

Automated dispute handling only scales when the underlying decision model is already disciplined. Manual chargeback management can consume time without improving outcomes if the merchant lacks a coherent model for risk, abuse, and customer intent. The operational lesson is that automation should reduce noise, not hide it. Practitioners should validate dispute workflows against the real sources of loss before expanding automation.

Merchant fraud programmes are increasingly evaluated on approved good traffic, not only blocked bad traffic. The post-approval outcome matters because ecommerce teams are accountable for conversion, margin, and trust at the same time. That makes approval rate a governance metric, but only when paired with loss and abuse outcomes. Practitioners should measure fraud controls as a balanced scorecard rather than a single rejection rate.

What this signals

Customer-intent correlation: ecommerce teams should treat linked behaviour as a control primitive, not an analytics luxury. When policy abuse and fraud sit on the same transaction path, the programme needs a way to connect repeat devices, behaviours, and account activity into one governed view. That is the difference between spotting isolated anomalies and controlling abuse at scale.

Balanced fraud governance is increasingly a board-level conversation because the metric mix now includes approval rate, dispute cost, and customer friction. Teams that optimise only for prevention will miss revenue loss from over-blocking, while teams that optimise only for conversion will invite abuse. The operating model has to balance both outcomes, ideally with clear thresholds and review accountability.

Where identity-linked abuse patterns are present, the most useful external lens is the approval decision chain rather than the individual transaction. NHI Mgmt Group's research on identity governance shows how durable governance depends on lifecycle visibility, and the same principle applies here: if the organisation cannot see repeated behaviour over time, it cannot govern it effectively.


For practitioners

  • Correlate customer intent across sessions Link device fingerprints, behavioural patterns, and account history so repeat policy abusers and promo misusers are visible as a single risk pattern rather than isolated transactions.
  • Separate fraud from policy abuse in control design Define distinct handling paths for fraudulent orders, serial promo misuse, and subscription chargebacks so review thresholds reflect the actual loss type and do not over-block legitimate customers.
  • Measure approval quality alongside loss rate Track approval rate, false positives, chargeback outcomes, and repeat abuse together so the team can see whether controls are improving revenue capture or merely shifting risk.
  • Automate disputes only after triage rules are tuned Use automated dispute management for predictable, well-defined case types and keep manual review focused on exceptions that materially change financial exposure.

Key takeaways

  • This case shows that fraud prevention is most effective when it distinguishes legitimate customer intent from repeat abuse patterns.
  • The headline result is operational as well as financial: Kogan reports 98%+ approval rates and $1.5 million in annual savings.
  • The control lesson is to link identity, device, and behavioural signals before the approval decision, then automate disputes only where triage is already disciplined.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST CSF 2.0 set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63BIdentity assurance matters where customer intent and behavioural signals affect approval decisions.
NIST CSF 2.0PR.AA-01Fraud and abuse controls map to identity verification and access decision governance.
GDPRArt. 5Behavioural and device signals can create personal-data governance obligations in identity-linked decisioning.

Align customer decisioning controls to PR.AA-01 and review false-positive handling regularly.


Key terms

  • Policy Abuse: The misuse of a legitimate transaction flow to bypass merchant rules around quantity, eligibility, resale, refunds, or claims handling. It may not always be fraud in the narrow sense, but it still creates governance risk because the merchant loses control over how buying privileges are exercised.
  • Customer-Intent Correlation: Customer-intent correlation is the practice of linking repeated behaviour, device signals, and account activity to determine whether a customer is acting legitimately or exploiting policy. It turns isolated transaction checks into a governed view of behaviour over time, which is essential where fraud and abuse overlap.
  • Chargeback: Chargeback is the allocation of technology costs back to the business unit, product, or service that incurred them. For AI workloads, it becomes a governance control when pricing and attribution are reliable enough that cost responsibility can influence design, usage, and prioritisation.

What's in the full analysis

Riskified's full case study covers the operational detail this post intentionally leaves for the source:

  • Decision model details for Kogan's higher-value and first-time customer categories
  • How Identity Engine and Identity Explore were used to separate policy abuse from legitimate repeat behaviour
  • The automated dispute workflow and chargeback handling model behind the reported savings
  • The merchant-facing operational changes that helped keep chargeback rates below AusPayNet thresholds

👉 The full Riskified case study covers the identity signals, policy abuse detection, and dispute automation detail.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, IAM, secrets management, and workload identity. It gives practitioners a structured way to connect identity controls to broader security programmes and operational decision-making.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 28, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org