Use layered checks that combine proofing strength, device reputation, payment risk, and booking behaviour, then reserve the hardest verification for higher-risk transactions. The goal is not universal friction, but risk-based verification where the service is most exposed.
Balancing Fraud Reduction with Customer Friction
Mobility fraud controls work best when they score the transaction, not the customer as a whole. The practical objective is to raise confidence only where the booking, payment, device, or route profile is unusual enough to justify added checks, while leaving low-risk customers on the fastest path.
That means treating proofing, device reputation, payment signals, and booking patterns as inputs to a step-up decision, rather than as a single hard gate. A customer with one weak signal should not be blocked automatically if the rest of the journey is consistent and low risk.
Risk-based verification is also better for operations because it concentrates the strongest controls on the cases most likely to be abused. In practice, that reduces blanket friction, lowers abandonment, and gives investigators better signals because the hardest checks are reserved for transactions that deserve closer scrutiny.
What Good Risk-Based Verification Looks Like
Good implementations distinguish between signals that are merely suspicious and signals that are strong enough to justify escalation. Device reputation, payment mismatch, velocity, and booking anomalies often work best as a combined score, with the response tuned to severity rather than to any single trigger.
For example, a low-risk customer might see only lightweight verification, such as a routine confirmation step, while a higher-risk booking may require stronger identity proofing or a manual review. The design should allow legitimate customers to pass quickly when their behaviour is normal, even if one data point is imperfect.
Teams should also calibrate thresholds by journey stage. A login, a first booking, a high-value change, and a refund request do not deserve the same control strength. The closer the action is to irreversible value transfer, the more justified the friction becomes.
How to Reduce Fraud Without Overblocking
The most effective pattern is progressive friction. Start with the least disruptive control that can still reduce risk, then step up only if the transaction becomes harder to trust. That approach is usually stronger than a single binary allow-or-block decision because it gives the service room to differentiate ordinary behavior from abuse.
Teams should also validate their controls against false positives, not just fraud catches. If a rule is catching obvious fraud but also pushing too many legitimate customers into abandonment or support, the threshold is probably too aggressive or the signal is too noisy.
To keep the decision defensible, the organisation should be able to explain why the challenge was applied. Clear reason codes, auditable policy logic, and monitored exception paths help separate sound fraud prevention from arbitrary blocking.
Risk and Threat Considerations
Fraud controls create their own failure mode when they become too blunt. Overly aggressive rules push good customers into friction, while overly weak rules let repeat abusers learn the thresholds and adapt their behaviour until the control no longer meaningfully reduces loss.
Failure mechanism: Static rules, weak signal quality, and poor threshold tuning can either suppress genuine demand or leave an exploitable gap that fraudsters can probe, especially when they test the service across many small variations of the same pattern.
Impact: The business can lose both revenue and trust, either through unnecessary abandonment or through successful abuse that compounds across bookings, refunds, chargebacks, or account misuse.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Customer and staff verification strength affects fraud screening and step-up checks. |
| AC-6 — Least Privilege | Risk-based friction limits stronger checks to higher-risk actions and reduces unnecessary exposure. | |
| Recommendation — Tune step-up authentication to the transaction risk and identity confidence. Limit strong verification to the actions that need it most. | ||
| NIST CSF 2.0 | PR.AA-05 — Least Privilege | Risk-based verification aligns access strength to the exposure of the specific transaction. |
| Recommendation — Apply the minimum verification needed for each customer action. | ||
| CIS Controls v8 | CIS-5 — Account Management | Fraud reduction depends on trustworthy identity and access lifecycle decisions during high-risk transactions. |
| Recommendation — Strengthen account checks where booking or payment risk increases. | ||
Practitioner Guidance
What to prioritise: Start with the signals that are both predictive and explainable. A smaller set of high-quality checks is usually easier to tune, monitor, and defend than a long list of weak indicators.
What to verify: Confirm that each step-up decision is tied to a measurable risk increase, not to a generic dislike of unusual behaviour. If the control cannot be explained in terms of observed exposure, it will be hard to tune and harder to justify.
Common mistake: Teams often optimise for fraud catch rate alone and ignore customer drop-off, support load, and false positives. A control that blocks good customers at scale is not a strong control, it is a poorly calibrated one.
Practitioner takeaway: The best fraud control is selective friction, applied late enough and strongly enough to matter, but only after the service has gathered enough evidence to justify it.
Related resources from NHI Mgmt Group
- How should payment teams reduce chargeback fraud without blocking too many legitimate customers?
- How should financial services teams reduce true name fraud without blocking legitimate customers?
- How should security teams reduce identity fraud without blocking legitimate users?
- How should security teams reduce return fraud without hurting legitimate customers?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org