Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What do merchants get wrong about using delivery…
Identity Beyond IAM

What do merchants get wrong about using delivery proof to stop did-not-arrive refund claims?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 9, 2026 Domain: Identity Beyond IAM

Merchants often overestimate the value of delivery proof. A signature, GPS record, or delivery photo can show that a parcel reached an address, but it may not prove the right person received it or that the item was not stolen after delivery. Fraudsters exploit that gap by disputing receipt, denying contact, or claiming the package never arrived.

Why Delivery Proof Rarely Settles the Question on Its Own

Delivery proof is useful evidence, but it is not the same thing as proof of receipt by the intended customer. A carrier scan, timestamp, GPS trace, or photo can confirm that a parcel reached a location or that a handoff occurred, yet did-not-arrive claims often turn on a different question: whether the right person received the goods, whether the package was left in a vulnerable place, or whether the item disappeared after delivery. That distinction matters because merchants frequently treat logistics evidence as if it were dispute closure, when it is only one input to a claims decision.

Industry control thinking aligns with this problem: evidence has to be reliable, relevant, and tied to the decision you are making, not merely present. The NIST SP 800-53 Rev 5 Security and Privacy Controls guidance is useful here because it reinforces the broader principle that control evidence should support accountability rather than create a false sense of certainty. In practice, many merchants discover the limits of delivery proof only after repeated refund disputes expose that proof of drop-off is not proof of custody transfer.

How Merchants Should Read the Evidence Chain

Merchants get better results when they treat delivery proof as part of a chain of evidence rather than a single decisive artifact. A strong claims review usually asks four separate questions: did the carrier mark the parcel delivered, did the package reach the correct location, was there a plausible opportunity for theft or misdelivery, and does customer history suggest a pattern of abuse. Each question narrows uncertainty, but none of them alone settles whether the customer actually took possession.

That is why the operational value of delivery proof depends on the surrounding process. A photo may help if the address is unmistakable and the packaging is visible, but it weakens quickly when the image is cropped, dark, or taken from a distance. A signature may matter more, but only if the merchant can trust the signature capture process and the carrier’s identity check at handoff. GPS coordinates can help confirm proximity, yet proximity is not possession. Merchants also need to consider whether the product category is easy to resell, whether porch piracy is common in the delivery area, and whether the claim timing aligns with a normal delivery window.

  • Use delivery proof to test the plausibility of the claim, not to assume the dispute is false.
  • Separate “delivered to address” from “received by customer” in internal review logic.
  • Require more context for higher-value, high-theft, or high-abuse orders.
  • Compare carrier evidence with customer communications, address quality, and prior claim behaviour.

Where merchants break down is when they turn one logistics artifact into an absolute rule and ignore the custody gap between doorstep delivery and actual receipt.

Where Delivery Proof Helps Less Than Merchants Expect

Tighter claims controls often reduce false approvals, but they also increase review effort and can frustrate legitimate customers, so merchants have to balance evidence strength against customer friction. The hardest edge cases are the ones where delivery proof looks strong on paper but does not answer the actual dispute.

For example, a signature can be weak if the carrier leaves the parcel with a neighbour, front desk, or building staff member and the merchant cannot verify who accepted it. A photo can be weak if it proves only that a parcel was left at a door that resembles the billing or shipping address. GPS data can be weak when the delivery point is a dense apartment block, a business park, or a shared property. In all of these cases, the proof may be directionally useful but not conclusive.

Merchants also get tripped up by assumption drift. They assume the same evidence standard should apply to every order, but the right threshold depends on value, channel, fraud history, and delivery environment. The best approach is often policy-based rather than absolute: lower-value low-risk orders can use lighter evidence, while high-risk claims need stronger corroboration, such as shipment exception data, customer confirmation history, or carrier investigation results. When the merchant cannot distinguish between proof of delivery and proof of receipt, the control becomes useful for triage but unreliable as a sole basis for denial.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v86 — Access Control ManagementControls dispute-handling access and approval decisions on reliable evidence.
Recommendation — Require evidence thresholds before approving denied refund outcomes.
NIST CSF 2.0GV.RM-01 — Risk Management StrategyMaps claim handling to risk-based evidence thresholds and exceptions.
PR.AA-01 — Identity Management, Authentication, and Access ControlRelevant where merchant claims hinge on who actually received the parcel.
DE.CM-01 — Monitoring for Anomalous EventsSupports spotting repeat abuse patterns in did-not-arrive claims.
Recommendation — Set risk-based refund review criteria by order value and fraud exposure. Validate recipient-assurance signals before treating delivery proof as receipt proof. Monitor claim patterns for repeat abuse and inconsistent delivery evidence.
MITRE ATT&CKT1656 — ImpersonationFraudsters may falsely deny receipt or misrepresent handoff circumstances.
Recommendation — Map disputed-receipt behaviour to impersonation patterns in claim triage.

Practitioner Guidance

What to prioritise: Build claims logic around the specific question being answered, which is whether the customer likely received control of the parcel, not whether the carrier completed a drop-off event. That distinction should drive evidence weighting, escalation thresholds, and denial confidence.

What to verify: Check whether the proof is location evidence, handoff evidence, or receipt evidence. If the artefact does not identify a recipient or does not clearly establish custody transfer, treat it as supporting context rather than decisive proof.

Decision rule: If the order is high value, high theft risk, or has prior claim signals, require more than one evidence source before closing the case. If the evidence only shows delivery proximity, route the claim for manual review instead of a reflex denial.

Practitioner takeaway: Merchants usually lose claims discipline when they confuse logistics confirmation with receipt assurance; the stronger the delivery artefact, the more important it is to ask what it still does not prove.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 9, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org