Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should merchants evaluate whether liability shift is…
Governance, Ownership & Risk

How should merchants evaluate whether liability shift is actually reducing risk?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

They should test whether the mechanism reduces fraud liability without pushing too many legitimate orders into rejection or manual review. The key signals are approval quality, false-decline rates, and how well the model handles borderline orders that do not fit a simple rules-based profile.

Liability shift should be treated as a payment risk control, not as proof that the merchant’s overall fraud position improved. The useful test is whether it changes the distribution of outcomes in a way the business can tolerate: fewer fraud losses, but also no meaningful increase in good-order rejections, manual-review drag, or customer friction on borderline transactions.

What Liability Shift Actually Changes

Liability shift changes who absorbs certain fraud losses, but it does not guarantee that the authorization decision is better. A merchant can still end up with the same or higher operational loss if the control pushes too many legitimate orders into decline, review, or abandonment. That is why the right comparison is before-and-after performance on approval quality, not just chargeback exposure.

The mechanism can also behave differently by channel, issuer, country, product type, or customer segment. A shift that helps on one slice of traffic may create avoidable friction elsewhere, especially where the orders are legitimate but look borderline to a rules-heavy fraud stack.

Which Signals Show Real Risk Reduction?

Merchants should track three outcome layers together: fraud loss rate, false-decline rate, and manual-review rate. If liability shift lowers chargeback cost but approval quality drops, the merchant may simply be trading one form of loss for another. Good measurement also separates clean approvals from approvals that later become disputed or refunded for fraud-related reasons.

Borderline orders deserve special attention because they reveal whether the model is actually discriminating risk or just becoming stricter. When the merchant can approve more good orders without a corresponding rise in fraud loss, the control is doing useful work. When good orders are being rejected or delayed at scale, the apparent protection may be overstated.

Approval quality should be read alongside customer journey impact. A control that reduces merchant liability but increases abandonment, support contacts, or manual handling can still be economically negative once operational cost and lost revenue are included.

How to Judge Borderline Orders and Manual Review

Borderline traffic is the best stress test for whether liability shift is genuinely improving decisioning. Look at orders that sit near the decline threshold, require additional verification, or are frequently sent to manual review. If these cases are mostly good customers, the merchant is probably overfitting to fraud avoidance and underweighting conversion.

A practical evaluation compares the outcome of similarly risky orders across time or across cohorts with and without the shifted-liability treatment. If the control mainly suppresses edge cases without improving the quality of the final approved pool, the merchant has not actually reduced risk, only moved it.

This is where a simple rules-based profile often breaks down. Real fraud and real customer behaviour both contain exceptions, so merchants need a view that measures whether the control handles ambiguity well instead of rewarding only easy approvals.

Risk and Threat Considerations

Liability shift can create a false sense of security if the merchant treats downstream loss allocation as the same thing as fraud prevention. The main risk is that the control appears to reduce exposure while silently increasing friction, false declines, or manual workload, which can damage revenue and obscure the true fraud profile.

Failure mechanism: The merchant optimises for shifted liability or lower chargebacks, but the authorization and review logic becomes too conservative, so legitimate borderline orders are denied or delayed and the fraud model is never tested against the full mix of real traffic.

Impact: Reported fraud loss may fall while approval quality, customer conversion, and operational efficiency worsen. Over time, that can produce a misleading view of control effectiveness and encourage further tightening that does not improve actual security outcomes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-16 — Application Software SecurityFraud decisioning is an operational security control that must be measured for effectiveness.
Recommendation — Measure approval and false-decline outcomes to verify the control is actually reducing business risk.
NIST CSF 2.0GV.OV-01 — Cybersecurity Risk Management StrategyLiability shift should be evaluated as part of risk oversight and outcome measurement.
ID.RA-01 — Asset Vulnerabilities and ThreatsBorderline orders are a risk-analysis problem because weak decision thresholds change exposure.
Recommendation — Assess whether the control reduces loss without increasing friction or operational exposure. Review borderline-transaction outcomes to see whether the control changes risk materially.
ISO/IEC 27001:2022A.5.30 — ICT readiness for business continuityPayment-control changes can affect service continuity and customer-facing processing quality.
Recommendation — Check that fraud controls do not create avoidable interruption or excessive manual handling.

Practitioner Guidance

What to verify: Compare pre- and post-shift cohorts on the same segments, not just overall chargeback counts. The key question is whether lower liability coincides with stable or improved approval quality for legitimate customers.

What to measure: Track approval rate, false-decline rate, manual-review rate, and the downstream fraud rate on approved orders. If one metric improves while two others deteriorate, the control is probably redistributing loss rather than reducing it.

Decision rule: If liability shift lowers chargebacks but materially raises false declines or review volume, treat it as a partial control with a conversion cost, not as a net-risk win.

Practitioner takeaway: A good liability-shift program protects the merchant without degrading the quality of the order book, and the only reliable proof is stable fraud loss plus better approval performance on borderline traffic.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org