Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should merchants adapt fraud controls when online…
Identity Beyond IAM

How should merchants adapt fraud controls when online buying patterns change suddenly during a crisis?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Identity Beyond IAM

Merchants should tune fraud controls to the new behaviour pattern instead of relying on historical rules alone. During sudden shifts, first-time digital shoppers, altered basket sizes, and unusual payment volumes can look suspicious even when they are legitimate. The practical goal is to reduce false declines while still blocking organised abuse, using continuous review, staged risk thresholds, and close alignment between fraud, operations, and customer communication.

Why fraud controls need to move with the customer pattern

Fraud control logic is only as good as the behaviour it assumes. When a crisis changes who is buying, how often they buy, and what they buy, merchants need to re-baseline the signals that once looked normal, including order value, device patterns, and payment cadence. The goal is to separate genuine behaviour change from abuse without freezing legitimate customers out.

A practical response is to treat the shift as an operating condition, not a one-time anomaly. That means reviewing rules against live transaction patterns, checking which declines are driven by legacy thresholds, and confirming whether new customer segments are behaving differently for understandable reasons such as stockpiling, remote shopping, or first-time digital adoption.

Merchants also need to avoid overfitting controls to the last crisis event. A rule set that is too rigid will create false declines, but one that is relaxed too far invites organised abuse that hides inside the noise of changed demand. A staged approach works better: widen tolerance where the business sees legitimate pattern drift, then tighten specific controls where abuse indicators stay elevated.

How to tune controls without opening the door to abuse

The safest adjustment is usually selective, not wholesale. Keep high-risk checks in place for behaviours that remain suspicious across contexts, such as velocity abuse, account takeover signals, repeated failed authentication, or mismatched payment and shipping patterns, while easing rules that are only noisy because the market context changed. That distinction matters more than any single threshold.

Continuous review is more effective than waiting for monthly tuning cycles during a fast-moving event. Merchants should monitor approval rates, false-decline complaints, chargeback rates, and manual-review workload together, because improving one measure can easily worsen another. If customer service is seeing many legitimate customers escalated or abandoned at checkout, the fraud model is probably too sensitive for the current environment.

Communication with operations and customer support is part of the control itself. When shoppers are behaving differently for understandable reasons, front-line teams need to know what normal now looks like so they can explain declines, collect context, and spot genuine abuse patterns. That alignment reduces avoidable friction and helps analysts distinguish crisis-driven volume shifts from coordinated fraud attempts.

Risk and Threat Considerations

Sudden behaviour shifts create a double risk: legitimate customers may be declined because historical patterns no longer apply, while fraudsters can blend into the disruption and test weaker approval paths. The danger is not just lost sales, but also degraded trust, higher support costs, and a blind spot created by using yesterday’s baseline to judge today’s traffic.

Failure mechanism: Static rules, rigid score cut-offs, and stale customer profiles misclassify unusual but legitimate activity as suspicious, while overly relaxed exceptions can suppress useful risk signals and allow organised abuse to pass through at scale.

Impact: Merchants see avoidable false declines, increased abandonment, higher manual-review burden, and potentially higher fraud loss if the control reset is too broad or poorly monitored.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v811 — Data Recovery ManagementSupports continuous review and recovery of control effectiveness during rapid pattern shifts.
6 — Access Control ManagementSupports adjusting transaction approval logic to enforce least privilege on payment and account actions.
17 — Incident Response ManagementRelevant because crisis-driven abuse patterns need rapid investigation, triage, and rule changes.
Recommendation — Review fraud-control performance continuously and restore trusted thresholds as behaviour normalises. Tighten approval paths for high-risk transactions while allowing lower-risk activity to proceed. Use incident-response processes to triage suspicious spikes and update fraud rules quickly.
NIST CSF 2.0GV.RM — Risk Management StrategyApplies because merchants must rebalance fraud, customer friction, and loss exposure under changing conditions.
DE.CM — Continuous MonitoringSupports live monitoring of approval, decline, and chargeback signals during the crisis period.
RS.CO — CommunicationsApplies because fraud, operations, and customer support must share the same interpretation of changed buying behaviour.
Recommendation — Recalibrate fraud thresholds as part of the organisation’s risk strategy when behaviour shifts suddenly. Monitor fraud and false-decline signals continuously and adjust controls based on current patterns. Coordinate fraud, operations, and customer-facing teams so declines and exceptions are handled consistently.

Practitioner Guidance

What to prioritise: Start with the controls most likely to create false declines during the new pattern, usually basket-value thresholds, velocity limits, and first-transaction rules. Preserve stronger scrutiny on behaviours that remain abnormal regardless of crisis context, such as repeated retries, identity mismatch, or device and payment reuse across many accounts.

What to verify: Before trusting an adjusted rule set, verify that the change is improving approval quality rather than simply moving risk elsewhere. Look for stable or improving fraud loss, a lower legitimate-decline rate, and no sudden spike in manual-review bypasses or post-approval chargebacks.

Decision rule: If a control is blocking a meaningful share of clearly legitimate new-customer traffic, relax it in a bounded way and measure the result quickly. If the same pattern is also associated with repeat abuse, keep the control and add a review step rather than removing it entirely.

Practitioner takeaway: The right response to a crisis is not to abandon fraud controls, but to make them context-aware, time-bounded, and continuously recalibrated against observed customer behaviour.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org