Organisations should combine robust identity verification with step-based transaction checks, rather than relying only on risk scores. The strongest pattern is to verify possession of the device, assess reputation of the phone number, and confirm ownership linkage to the person. That approach helps expose fake personas earlier and creates stronger trust at the moment users are most vulnerable.
Why friction should be added at decision points, not everywhere
The core challenge is to slow suspicious romance-scam activity without making normal account use feel punitive. That means placing stronger checks where trust is being created or money is being moved, not at every login. The most effective controls are step-based, so legitimate users only see extra friction when the pattern crosses a risk threshold.
A practical design is to keep low-friction access for routine behaviour, then trigger stronger verification when the interaction becomes financially meaningful, unusually urgent, or inconsistent with the user’s normal profile. That keeps the user journey usable while still interrupting scammers before a transfer, gift-card purchase, or account recovery step becomes irreversible.
For identity assurance patterns that minimise unnecessary friction, NIST SP 800-63 Digital Identity Guidelines is useful because it frames assurance around the strength of the authentication event, not just the presence of a password or one-time code.
What to verify to catch fake personas early
Romance scams succeed because the attacker can maintain a believable persona long enough for trust to form. Organisations reduce that risk when they verify more than a single signal. Device possession, phone-number reputation, and ownership linkage are stronger together than any one check on its own, because each addresses a different layer of the impersonation problem.
Step-based checks work best when they are tied to an observable change in behaviour. For example, a sudden request to move the conversation off-platform, an unexpected account recovery event, or a first-time payment to a new payee should prompt a stronger check than a routine browse or message. That approach makes fraud controls feel contextual rather than constant.
The verification model maps well to NIST SP 800-53 Rev 5 Security and Privacy Controls, especially the access control and identification-and-authentication families, because the question is ultimately about proving that the party requesting action is the legitimate user.
It also aligns with NIST Cybersecurity Framework 2.0 since organisations need a repeatable way to govern, protect, detect, and respond to suspicious trust-building behaviour without overcorrecting for ordinary users.
How to reduce scam risk without turning every step into a checkpoint
The best balance usually comes from progressive trust. Let the user complete low-risk actions with minimal interruption, then increase scrutiny only when the interaction becomes high-consequence. This is especially important in romance scams because the scammer’s value comes from persuasion over time, not from a single obvious transaction.
Organisations should also distinguish between friction that blocks a task and friction that prompts reflection. A short warning, a second confirmation, or an out-of-band challenge can be enough to interrupt urgency-driven manipulation while still allowing a legitimate user to continue. In practice, that is often more effective than hard denial for every suspicious event.
Because the attack pattern frequently involves behavioural manipulation and social engineering, the response benefits from threat-mapping as much as from identity checks. MITRE ATT&CK Enterprise Matrix is useful for thinking about credential access, trust abuse, and the points where an attacker can turn influence into action.
Risk and Threat Considerations
Romance scams are high-conversion attacks because they target trust, urgency, and emotional commitment rather than technical weakness alone. The risk increases when organisations make it easy to move from conversation to payment, cash-out, or account recovery without a meaningful trust check.
Failure mechanism: The attacker builds a believable relationship, then times the request for a transfer or account action so that weak controls and user urgency line up. If the organisation only uses static risk scoring, a patient scammer can stay below thresholds until the loss event.
Impact: Legitimate users may experience direct financial loss, account misuse, or recovery abuse, while the organisation absorbs chargebacks, complaints, support load, and reputational damage.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-63, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Phishing-resistant assurance and step-up verification are central to trust checks. |
| Recommendation — Use assurance-based step-up authentication when high-risk actions need stronger proof. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | The topic depends on verifying the requesting user before sensitive actions. |
| AC-6 — Least Privilege | Friction should be limited to consequential actions, not every interaction. | |
| Recommendation — Strengthen user authentication before permitting high-consequence account or payment actions. Limit sensitive transaction paths to the minimum necessary authorization. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication and Access Control | The page is about reducing scam risk with verification and access checks. |
| Recommendation — Apply step-up identity checks when behaviour indicates elevated fraud risk. | ||
| MITRE ATT&CK | T1589 — Gather Victim Identity Information | Romance scams depend on building a believable persona and trust relationship. |
| Recommendation — Map social-engineering behaviour to attacker tradecraft and detection opportunities. | ||
Practitioner Guidance
What to prioritise: Put friction on high-consequence actions, not on ordinary engagement. The most useful checkpoints are the ones that interrupt payment, ownership change, or first-time payout behaviour, because that is where scam value is realised.
What to verify: Treat a single score as insufficient when the user is being asked to send money or change account state. Verify device possession, number reputation, and account linkage together, because the scammer only needs one weak point to succeed.
What good looks like: Legitimate users move through routine flows with little interruption, while suspicious trust-building patterns trigger proportionate challenge, a clear warning, or a step-up check that is visible but not excessive.
Practitioner takeaway: The right design goal is not maximum friction, it is maximum friction only at the moment trust is about to become loss.
Related resources from NHI Mgmt Group
- How should small and midsize organisations reduce the risk of credential compromise without adding too much friction for users and admins?
- How should security teams reduce fraudulent signups without adding too much friction for legitimate users?
- How should fraud teams use device and browser signals to reduce account takeover risk without creating too much friction for legitimate users?
- How should payment teams reduce peer-to-peer fraud without adding too much friction for legitimate users?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org