Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What do retailers get wrong when they rely…
Identity Beyond IAM

What do retailers get wrong when they rely on clicks and impressions to judge ad performance?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Identity Beyond IAM

Retailers often mistake activity for value. Clicks and impressions are easy for bots to fake, so they can make campaigns look successful even when real buyers are not responding. The practical error is using shallow engagement signals as the main basis for ROI decisions instead of validating whether the traffic produces qualified leads, sales, or other meaningful conversions.

Why click and impression counts overstate ad performance

Click and impression metrics measure exposure and interaction, but they do not prove commercial intent or purchase quality. In retail media, that gap matters because a campaign can generate plenty of visible activity while still failing to produce incremental sales, qualified traffic, or profitable customer behavior. The mistake is treating attention as if it were outcome.

Retailers also tend to overestimate how much these signals can be trusted at face value. Ad traffic can be inflated by bots, accidental taps, low-quality placements, or repeated exposure from the same audience, which makes the campaign look busy without proving it influenced buying decisions. A higher count is not the same thing as a better business result.

That is why click-through rate and impression volume should be treated as diagnostic inputs, not the verdict. They help show reach and friction, but they do not answer the questions that matter most to merchants: did the traffic contain likely buyers, did it convert, and did it move revenue in a way that justifies spend?

What good measurement looks like instead

The stronger test is whether ad exposure leads to meaningful downstream behavior. For retailers, that usually means validating conversions, revenue, basket quality, repeat purchase patterns, or another business-specific outcome that is closer to value than raw engagement. When possible, compare exposed audiences with a reasonable control or baseline so you can separate real lift from background demand.

Measurement should also distinguish between upper-funnel and decision-stage activity. Impressions can be useful for awareness, and clicks can still help with path analysis, but neither should carry the full burden of ROI proof. If the reporting stack cannot connect ad exposure to sales or qualified conversion events, the problem is not the channel alone, it is the evaluation model.

Retail teams often make better decisions when they combine media metrics with operational evidence from NHI Mgmt Group’s Ultimate Guide to NHIs, especially the sections on visibility and lifecycle control for machine-driven activity. In practice, the same discipline applies here: if you cannot attribute and validate the source of traffic, the metric is too weak to drive spend allocation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS Control 8 — Audit Log ManagementHelps validate whether reported ad traffic and conversions are attributable and reviewable.
Recommendation — Correlate campaign events with conversion logs before using engagement metrics for spend decisions.
NIST CSF 2.0GV.RM-01 — Risk Management StrategySupports basing ROI decisions on business outcomes rather than vanity metrics.
DE.CM-01 — Continuous MonitoringApplies to monitoring traffic quality and detecting anomalous or bot-inflated ad activity.
Recommendation — Define decision thresholds that require outcome-based evidence before scaling spend. Monitor campaign traffic for anomalies that indicate non-human or low-quality engagement.
MITRE ATT&CKT1218 — System Binary Proxy ExecutionBot-driven or automated abuse can inflate engagement signals and distort performance measures.
Recommendation — Hunt for automated traffic patterns that can distort marketing performance metrics.

Practitioner Guidance

What to verify: Check whether the campaign reporting ties clicks and impressions to a conversion event that matters to the retailer, such as purchase, qualified lead, new customer acquisition, or incremental revenue. If the dashboard stops at engagement, treat it as directional only.

Common mistake: Do not let a high click volume override weak post-click behavior. A campaign with strong exposure but poor conversion quality often signals misplaced targeting, low-trust traffic, or a landing experience that does not match shopper intent.

What to measure: Prioritise conversion rate, cost per meaningful outcome, and lift against a baseline before you rely on CTR or CPM for budget decisions. If those downstream measures are missing, add them before scaling spend.

Practitioner takeaway: Retailers get into trouble when they optimise for visible activity instead of verified commercial impact, so the right question is not “Did people click?” but “Did this exposure create measurable buyer value?”

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org