Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› Should merchants tighten return policies for everyone or…
Cyber Security

Should merchants tighten return policies for everyone or target risky customers only?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Cyber Security

Targeted controls are usually safer. Blanket tightening can alienate honest customers and reduce trust, while selective friction lets merchants focus on customers with repeat abuse patterns, suspicious evidence, or high-loss claim types without making the entire return journey painful.

Why targeted return controls usually outperform blanket tightening

Retail return policy design is a control problem, not just a customer-service choice. The practical question is whether the merchant can separate normal shoppers from repeat abusers without creating so much friction that it damages conversion, loyalty, or dispute handling. Targeted controls usually win because they reduce loss where the risk is concentrated while preserving a smoother path for low-risk customers.

A blanket policy change treats every return the same, even though the underlying behaviour is uneven. That often shifts cost onto honest customers and can hide the real problem, which is usually a smaller set of repeat claims, serial wardrobers, wardrobing-style abuse, or evidence patterns that justify tighter scrutiny.

What makes customer targeting more precise than a universal policy change?

Selective friction works best when it is based on observable signals rather than broad suspicion. Merchants can tighten controls around repeat return frequency, unusually high refund ratios, mismatched order and return behaviour, account history, or claim types that carry higher loss rates. The point is to apply more verification only where the expected loss justifies it.

That approach also improves operational clarity. Instead of rewriting the entire policy every time abuse rises, teams can tune thresholds, review queues, and exception handling for the specific patterns that drive loss. Done well, this creates a more measurable control environment because the merchant can see which friction points reduce abuse and which ones only slow legitimate returns.

How should merchants decide where to place friction?

The decision should follow the loss pattern. If returns are broadly healthy but a few customer segments, product lines, or claim types are driving a disproportionate share of cost, targeted controls are the better fit. If abuse is so widespread that the merchant cannot reliably distinguish normal from risky behaviour, the controls may need to become broader, but that is a sign of weak detection rather than a reason to punish everyone by default.

Good design also depends on proportionality. The more disruptive the friction, the stronger the evidence should be before it is applied. For low-value or low-confidence cases, soft controls such as automated checks, return windows, or proof-of-purchase validation may be enough. For high-loss or repeat-abuse patterns, merchants may need manual review, stricter eligibility rules, or temporary restrictions.

Risk and Threat Considerations

Blanket tightening can create its own failure mode: it pushes the burden onto legitimate customers, increases service friction, and may encourage workarounds or abandonment of the channel altogether. Targeted controls reduce that exposure, but they only work if the merchant can reliably identify abuse patterns and avoid false positives.

Failure mechanism: Weak segmentation, poor evidence quality, or overly coarse rules cause the merchant to over-restrict good customers while missing the higher-loss cases that actually need scrutiny.

Impact: The business absorbs avoidable churn and support cost, while abusive behaviour may continue under a policy that feels stricter but is not actually smarter.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementReturn abuse control depends on managing customer-account risk and limiting repeat misuse.
Recommendation — Use account monitoring and exception handling to focus friction on repeated abuse patterns.
NIST CSF 2.0ID.RA-01 — Risk IdentificationThe question is about identifying where return risk is concentrated and how to treat it proportionally.
Recommendation — Identify the return-abuse patterns that create the highest loss and target controls there.
ISO/IEC 27001:2022A.5.15 — Access controlSelective friction mirrors the principle of restricting higher-risk actions more tightly than normal use.
Recommendation — Apply tighter eligibility checks only to higher-risk return paths and exception cases.

Practitioner Guidance

What to prioritise: Start with the return patterns that create the most loss, not with a universal restriction. If a small number of behaviours explain most of the damage, targeted review and escalation will usually outperform a broad policy change.

What to verify: Before tightening anything, confirm that the candidate signals are genuinely predictive and not just correlated with normal shopping behaviour. A useful control should distinguish high-risk returns from frequent but legitimate buyers.

Decision rule: If the control would materially inconvenience a large population of honest customers, require stronger evidence that the same loss cannot be reduced with narrower filters, thresholds, or review steps.

Practitioner takeaway: The best return policy is usually one that is firm where abuse is measurable and light where trust is earned; broad friction is easy to implement, but selective friction is usually the better business control.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org