TL;DR: Authorization rates for a Japanese fashion platform and ST improved by 15% while fraud fell to near zero and manual review was eliminated, showing how selective authentication and risk-based decisions can reduce checkout friction without weakening payment controls, according to Riskified. For identity and fraud teams, the lesson is that authorization, identity intelligence, and transaction risk governance now need to be treated as one operating model.
At a glance
What this is: This is a Riskified case study on how and ST balanced fraud prevention with payment approval performance through risk-based authentication and transaction scoring.
Why it matters: It matters because ecommerce teams responsible for identity verification, customer trust, and fraud controls need governance models that reduce false declines without relaxing account and transaction assurance.
By the numbers:
- and ST achieved a 15% increase in authorization rates after working with Riskified.
- and ST reduced fraud chargebacks to approximately 0.0005%, effectively near zero.
- and ST eliminated manual fraud review, saving approximately 10 hours per week.
👉 Read Riskified's analysis of how and ST improved authorisation rates and reduced fraud
Context
Ecommerce fraud control often fails when payment security is treated as a separate problem from identity and authorisation. In practice, strong authentication can reduce fraud exposure while also increasing false declines, which creates pressure on conversion, customer experience, and operational workload. This article sits squarely in identity verification and fraud governance, where approval logic and trust decisions are part of the same control plane.
For IAM and fraud practitioners, the key issue is not whether authentication exists, but whether it is applied with enough context to distinguish low-risk from high-risk activity. That is the boundary where transaction risk scoring, account protection, and checkout governance intersect with identity assurance. In this case, the starting position is typical for fast-growing ecommerce merchants facing both scale and tighter payment authentication requirements.
Key questions
Q: How should ecommerce teams balance fraud prevention with approval rates?
A: Treat fraud prevention as a decision-quality problem, not a blocking problem. Use identity, device, behavioural, and history signals to distinguish legitimate customers from repeat abusers, then measure success with approval rate, chargeback outcome, and false-positive rate together. The goal is to reduce loss without suppressing good revenue.
Q: How should ecommerce teams balance strong authentication with customer conversion?
A: Use risk-based authentication rather than blanket friction. Reserve step-up challenges for sensitive actions such as checkout, payment changes, and account recovery, while keeping everyday login flows simple. Strong authentication should reduce fraud without forcing low-risk customers through unnecessary prompts that increase abandonment.
Q: What breaks when fraud review is disconnected from identity signals?
A: Teams lose the ability to distinguish routine customer behaviour from suspicious activity early enough to act cleanly. That drives more manual review, slower decisioning, and weaker fraud detection at the account and login stages. Payment controls then carry too much of the burden, which usually worsens both operational cost and customer experience.
Q: Who is accountable when fraud controls reduce approval rates but do not reduce losses?
A: Accountability should sit with the team that owns the full decision chain, not just the final checkout control. In practice, that means fraud, payments, and identity governance teams need shared metrics, clear exception ownership, and documented policy approval. If those controls are split, merchants often optimise one metric while damaging another.
Technical breakdown
Risk-based authentication and checkout authorisation
Risk-based authentication uses behavioural, device, and transaction signals to decide whether a payment or login should pass with minimal friction or require step-up verification. In ecommerce, the core challenge is that blanket authentication treats every transaction as equally risky, which increases false declines and shifts cost into manual review. Selective challenge models aim to preserve trust while allowing low-risk activity to move quickly through checkout.
Practical implication: map authentication requirements to transaction risk tiers instead of applying the same control to every purchase.
Fraud decisioning across account creation, login, and payment
Modern fraud programmes do not begin at checkout. They start at account creation and login, where attackers test stolen identities, synthetic accounts, and reused credentials before attempting monetisation. When those upstream stages are weakly governed, payment controls absorb too much of the burden and merchants see more friction, more manual review, and weaker operational efficiency. Identity signals across the user journey are what make downstream risk decisions usable.
Practical implication: connect identity verification, login monitoring, and payment authorisation so fraud controls operate as one lifecycle.
3-D Secure pattern selection and approval optimisation
EMV 3-D Secure is often implemented as a binary requirement, but different operational patterns change how much friction the customer sees. Pattern-based approaches can permit low-risk transactions to bypass additional challenge while routing only higher-risk cases into stronger verification. That matters because the control is not just fraud prevention, it is also the governance of issuer approval, merchant liability, and checkout completion under changing regional requirements.
Practical implication: tune 3DS policy by merchant risk tolerance, issuer behaviour, and customer journey impact rather than using a single global rule.
Threat narrative
Attacker objective: The attacker objective is to complete fraudulent purchases or monetise account abuse while avoiding detection and challenge.
- Entry begins with fraudulent account creation or login attempts that exploit weak identity signals and stolen credentials.
- Escalation occurs when attackers move from account access to payment abuse, testing transactions until they find combinations that bypass review or trigger false confidence.
- Impact is chargeback loss, manual review burden, and conversion damage when merchants overcorrect with blanket authentication.
NHI Mgmt Group analysis
Checkout fraud is now an identity governance problem, not just a fraud problem. When merchants apply authentication without transaction context, they often convert security into customer friction and manual overhead. The better model is lifecycle governance across account creation, login, and payment, because that is where trust is actually established and exploited. For practitioners, the question is how to make identity signals usable at the point of authorisation.
Selective challenge is a control design pattern, not a workaround. The practical value is that low-risk transactions can move without unnecessary step-up while higher-risk activity receives stronger verification. That aligns with the broader principle of least friction for trusted activity and stronger controls where confidence drops. For ecommerce and identity teams, the governance task is policy quality, not just control deployment.
Fraud-exposed merchant status exposes a control maturity gap. It usually signals that fraud and authorisation decisions are being managed as separate functions when they should be coordinated. That gap creates too much manual review, too many false declines, and too little visibility into how identity signals influence payment outcomes. Practitioners should treat merchant risk classification as a governance signal, not a label to work around.
Identity intelligence must extend beyond human account ownership. Ecommerce environments increasingly blend customers, devices, session behaviour, and automated abuse patterns into one decision problem. That does not make every automation an NHI issue, but it does mean identity assurance has to cover more than credentials alone. For IAM and fraud teams, the real challenge is governing the trust boundary around the transaction, not just the account.
What this signals
Ecommerce fraud programmes are converging with identity governance because transaction risk now depends on the quality of account, session, and behavioural signals. For practitioners, the practical shift is toward policies that balance approval optimisation with assurance rather than treating those outcomes as separate goals. The governance question is no longer whether to add more controls, but where to place friction so it reduces loss without undermining customer trust.
Decision-layer fraud governance: this is the point where identity signals, merchant policy, and payment routing become one control layer. The organisations that benefit most will be the ones that can explain why a transaction was challenged, passed, or reviewed, and can tie that decision to measurable outcomes. That is also where standards-based control thinking, such as NIST Cybersecurity Framework 2.0, helps structure accountability.
For practitioners
- Align identity and payment risk policies Map account creation, login, and checkout controls into one decision framework so fraud teams and identity teams use the same risk thresholds and escalation paths.
- Reduce blanket authentication at checkout Use transaction risk scoring to reserve step-up authentication for higher-risk events instead of applying the same 3-D Secure challenge to all purchases.
- Track false decline and review burden together Measure approval rates, chargebacks, and manual review hours as a single control outcome so security gains are not purchased with avoidable friction.
- Review merchant risk flags as governance signals Treat fraud-exposed merchant status as evidence that identity and payment controls need rebalancing, then test where the decision chain is failing.
Key takeaways
- Fraud control and payment approval are now the same governance problem when identity signals drive transaction outcomes.
- The evidence in this case shows that selective authentication can improve approval rates while sharply reducing manual review and chargebacks.
- Practitioners should align fraud, IAM, and payments policy so risk decisions are based on context, not blanket friction.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, while GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Transaction authorisation depends on access control and identity assurance at checkout. |
| NIST SP 800-53 Rev 5 | IA-5 | Authenticator management underpins step-up and selective challenge decisions. |
| NIST SP 800-63 | SP 800-63B | Digital identity assurance matters when login and account creation drive fraud risk. |
| GDPR | Art.32 | Identity and fraud signals can involve personal data and security of processing. |
Ensure fraud analytics and identity checks are proportionate, documented, and protected under Art.32.
Key terms
- Real-Time Fraud Decisioning: Real-time fraud decisioning is the practice of evaluating a payment or account action before it completes, using identity, behavioural, and transaction signals. In fast-moving P2P systems, it is the difference between preventing abuse and only documenting it after funds have moved.
- Selective Challenge: Selective challenge is a risk-based authentication pattern that applies additional verification only when a transaction or session crosses a defined risk threshold. It reduces unnecessary friction for trusted activity while preserving stronger controls for suspicious behaviour or higher-value events.
- False decline: A false decline is a legitimate transaction that is rejected because the fraud controls interpret it as risky. It matters because the operational cost is not limited to one lost sale. It can also damage customer trust, reduce retention, and distort fraud programme metrics.
- Merchant Risk Flag: A merchant risk flag is an indicator from a payment provider or acquirer that a merchant’s transaction profile is considered elevated risk. It usually reflects fraud patterns, authentication issues, or loss trends, and it should trigger control review rather than simple compliance with a label.
What's in the full analysis
Riskified's full post covers the operational detail this post intentionally leaves for the source:
- The EMV 3-D Secure Pattern 1 operating model used to reduce friction for low-risk transactions.
- The merchant approval process context, including conversion and GMV impact modelling for the acquiring bank.
- The 24/7 monitoring arrangement and how it supported ongoing fraud decisioning.
- The account creation and login protections that extended the control model beyond checkout.
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and identity lifecycle control. It helps security practitioners connect identity assurance to the broader access and risk decisions their programmes depend on.
Published by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org