By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: SignifydPublished July 21, 2026

TL;DR: Fraud control now extends across the full customer journey, not just checkout, and identity signals matter at scale, according to Signifyd. Its Shopify-focused fraud coverage spans card-not-present chargebacks, non-fraud disputes, returns and abuse cases, while also helping merchants stay under Visa’s newly lowered 1.5% VAMP threshold, with results framed around approval rates and dispute reduction.


At a glance

What this is: Signifyd’s Shopify fraud-protection post argues that merchant risk control now has to cover the full customer journey, including disputes, returns and abuse, while helping merchants stay under Visa’s 1.5% VAMP threshold.

Why it matters: For fraud, IAM and identity verification teams, the key issue is that dispute handling, account trust and identity risk are converging into one operational control surface that affects revenue, approval rates and compliance exposure.

By the numbers:

👉 Read Signifyd's post on guaranteed fraud protection for Shopify merchants


Context

Fraud protection for ecommerce is no longer limited to a single checkout decision. Once merchants are measured on dispute ratios, return abuse, account trust and post-purchase behaviour, the control problem becomes broader than payment screening alone, especially when identity signals are used to decide which orders and claims are legitimate.

That matters for Shopify merchants because the same data used to approve a purchase can also inform returns, refunds, disputes and abuse patterns. In practice, this pushes fraud operations closer to identity governance, where account reputation, behavioural risk and dispute handling all need to be aligned rather than managed in separate silos.


Key questions

Q: How should merchants govern fraud decisions across the full customer journey?

A: Merchants should align account creation, login, checkout, returns and dispute handling under one policy model so the same identity and behavioural signals inform each decision. If those stages are run in separate systems, attackers and abusive customers can move into the gap between them. Governance should measure whether one control path is creating exceptions for another.

Q: Why do disputes and returns belong in the same fraud programme?

A: Because both are downstream expressions of trust. A customer who passes checkout screening can still create loss through item-not-received claims, refund abuse or promo misuse. When teams manage them separately, they miss the link between identity confidence, purchase legitimacy and post-purchase behaviour. Unified reporting gives a truer picture of merchant risk.

Q: How do security and fraud teams know if AI fraud scoring is working?

A: They should look for stable approval rates, lower false positives, consistent reason codes and a defensible review trail. A model can look accurate in aggregate while still creating operational harm if it cannot explain why a legitimate order was rejected. The test is whether the decision can be audited and improved.

Q: Who is accountable when a merchant’s dispute ratio exceeds network thresholds?

A: Accountability should sit with the team that owns the merchant risk metric, not just the team operating the fraud tool. Card-network thresholds are a governance issue because they affect acceptance, cost and programme health. The clearest structure is to assign one owner for dispute ratio outcomes across fraud, returns and chargebacks.


Technical breakdown

Full-journey fraud decisioning and merchant dispute ratios

Fraud decisioning that only looks at checkout leaves merchants exposed to post-purchase abuse, including returns, non-receipt claims and promo abuse. Full-journey decisioning connects account creation, login, purchase and dispute handling so the same risk model can influence multiple control points. The practical effect is that merchant loss metrics and card-network thresholds become coupled to identity and behaviour signals, not just transaction attributes. That is why dispute ratio management increasingly depends on how well merchants correlate identity confidence with claim validity.

Practical implication: align fraud, identity and dispute workflows so the same risk signals can shape approval, returns and chargeback handling.

Explainable AI in fraud operations

Explainable AI in fraud prevention means a team can trace why a transaction was approved, declined or escalated. In high-volume commerce, that matters because false positives directly affect revenue, while opaque decisions make it hard to tune policy or defend outcomes to internal stakeholders. Human review still matters for edge cases, but the real governance value comes from making the AI decision auditable enough to support appeal handling, policy refinement and regulator or partner scrutiny. Without that transparency, automation becomes harder to trust operationally.

Practical implication: require reason codes, review trails and policy transparency before expanding automated fraud decisions.

Visa VAMP thresholds and dispute governance

Visa’s Acquirer Monitoring Program ties merchant behaviour to dispute ratios, so fraud teams now have to think in terms of prevention before counting, not remediation after the fact. If a merchant crosses the threshold, the impact is not only operational friction but potentially higher costs and tighter acceptance. The governance challenge is that different providers may surface this through separate dashboards, which can fragment ownership. A single control plane that covers legitimate disputes, returns and abuse can reduce that fragmentation, but only if teams measure it against the network threshold itself.

Practical implication: map fraud controls to card-network dispute thresholds and assign explicit ownership for the ratio they influence.


Threat narrative

Attacker objective: The objective is to convert seemingly legitimate commerce activity into financial loss while avoiding detection across checkout, returns and dispute processes.

  1. Entry begins when attackers or abusers exploit account creation, login, or purchase flows to present themselves as legitimate customers rather than obvious fraud cases.
  2. Escalation occurs when false returns, item-not-received claims, promo abuse or reseller behaviour bypass simple checkout checks and move into post-purchase dispute channels.
  3. Impact is realised through chargebacks, refund leakage, higher dispute ratios and tighter card-network monitoring, which can erode acceptance and revenue.

NHI Mgmt Group analysis

Fraud governance is increasingly an identity problem, not just a payments problem. The article shows how checkout, account trust, returns and disputes now sit on the same control path. Once identity confidence influences whether a claim is accepted or rejected, fraud teams are effectively operating an identity assurance programme. Practitioners should treat merchant fraud controls as part of the broader identity governance surface.

Full-journey controls are becoming the new boundary for commerce risk. Stopping fraud at checkout is no longer enough when abuse can emerge later in the order lifecycle. That shifts the centre of gravity toward policy consistency, shared telemetry and common decisioning across commerce steps. For practitioners, the lesson is to measure control coverage across the whole customer journey, not a single transaction checkpoint.

Explainable AI is now a governance requirement in fraud operations. When automated decisions affect approvals, disputes and refunds, teams need traceability rather than model output alone. Black-box fraud scoring weakens internal accountability because operations cannot explain why a legitimate customer was challenged or why an abusive actor passed. Practitioners should insist on decision explainability that supports review, appeal and policy tuning.

Chargeback ratio pressure is forcing merchants to think in terms of prevention economics. Lower thresholds change the economics of fraud management because every illegitimate dispute now carries more programme-level risk. That pushes merchant teams toward a named control concept we would call dispute-ratio governance: the practice of aligning fraud, returns and chargeback controls to the same threshold outcome. Practitioners should tie fraud policy to the ratio they are actually judged on.

What this signals

Commerce fraud is converging with identity assurance, which means merchants need controls that measure trust across the whole customer lifecycle rather than only at the payment gate. The operational signal to watch is whether approval, dispute and return decisions are governed by one policy model or by separate teams with inconsistent thresholds.

Dispute-ratio governance: this is the practical shift merchants are making when card-network thresholds become programme-level controls instead of back-office metrics. The right response is to align fraud operations, data quality and review workflows to the same outcome, then verify that explainable decisions are available when customers challenge outcomes.

For identity and risk teams, the broader signal is that trust scoring is becoming a shared language between commerce, fraud and IAM-adjacent controls. Where a merchant can link identity confidence to dispute prevention, they gain a defensible way to prioritise investigation, reduce noise and keep automation from drifting away from policy.


For practitioners

  • Map fraud controls to the full customer journey Review whether account creation, login, checkout, returns and dispute handling share the same risk signals or operate as separate tools with conflicting decisions. The goal is to avoid allowing a transaction to pass one control point and fail another without a shared policy record.
  • Tie governance to dispute ratios, not only case counts Track the merchant threshold that matters to your acquiring and card-network relationships, then align fraud policy changes to that metric. If teams cannot show how a control affects the ratio, they are managing activity rather than risk.
  • Demand explainable decision records for high-value fraud actions Require reason codes and review trails for approvals, declines and escalations so operations can defend outcomes and refine policy. This is especially important where AI models and human reviewers both influence the final call.
  • Unify return abuse and CNP fraud reporting Treat return abuse, promo abuse and card-not-present fraud as linked categories in the same reporting structure. Separate dashboards make it harder to see whether a merchant is reducing losses or simply moving them between channels.

Key takeaways

  • Fraud control is no longer a checkout-only problem, because returns, disputes and account trust now shape the same merchant risk outcome.
  • The strongest evidence in the post is operational, not theoretical: Signifyd ties its model to approval rates, GMV coverage and lower dispute pressure.
  • Merchants that want to stay below network thresholds need unified decisioning, explainable AI and a single owner for dispute-ratio governance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Identity confidence and access decisions shape checkout and dispute risk.
NIST SP 800-53 Rev 5IA-2Authentication and identity proofing underpin account trust in commerce flows.
NIST SP 800-63SP 800-63BDigital identity assurance is relevant when trust signals affect merchant decisions.
GDPRArt.32Fraud scoring and identity-linked customer data require appropriate security controls.

Map fraud decision points to PR.AC-4 and ensure identity confidence is consistent across the customer journey.


Key terms

  • Dispute-ratio governance: The practice of managing fraud, returns and chargebacks against the same merchant threshold outcome. It treats dispute ratio as a control objective, not a reporting metric, and forces teams to align policy, review and measurement across the full customer journey.
  • Explainable fraud decisioning: Fraud scoring that can be traced back to a reason, policy or model output that humans can inspect. In governance terms, it lets operations defend approvals and declines, tune thresholds and review edge cases without relying on opaque automation.
  • Full-journey fraud control: A fraud operating model that spans account creation, login, purchase, delivery, returns and dispute handling. It is broader than checkout screening because it assumes abuse can emerge after the initial payment decision and must be governed across the lifecycle.

What's in the full article

Signifyd's full post covers the operational detail this analysis intentionally leaves for the source:

  • Merchant case-study outcomes by brand, including approval rate changes and chargeback reduction figures.
  • How the guarantee model applies across card-not-present disputes, return abuse and promo abuse.
  • The specific way Signifyd frames Visa VAMP threshold management without a separate dashboard.
  • Customer review excerpts and implementation examples from Shopify merchants already using the service.

👉 The full Signifyd article covers merchant outcomes, dispute handling and VAMP threshold details.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, secrets management and identity lifecycle control. It helps practitioners connect trust decisions across human, machine and automated systems in a way that supports real programme ownership.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 22, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org