Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What do security and product teams get wrong…
Governance, Ownership & Risk

What do security and product teams get wrong about improving conversion and fraud outcomes together?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Governance, Ownership & Risk

A common mistake is treating conversion optimisation and fraud prevention as separate goals. If teams only remove friction, they can weaken assurance and invite abuse. If they only harden controls, they can drive abandonment. The stronger pattern is layered identity verification that adapts to risk, so low-risk users move quickly and suspicious activity gets more scrutiny.

Why conversion and fraud teams keep talking past each other

The error is usually organisational, not technical: conversion teams optimise for the shortest path to success, while fraud teams optimise for the safest path to trust. If those goals are handled separately, each side can create new failure modes. The practical fix is to design the journey as one system, with step-up checks only where risk justifies them.

That means the question is not whether to add friction or remove it, but where assurance needs to be adaptive. NIST SP 800-63 Digital Identity Guidelines is useful here because it reinforces assurance levels and phishing-resistant authentication as a risk-based design choice, not a universal default.

What the strongest conversion-fraud pattern actually looks like

The best pattern is layered assurance: start with low-friction signals, then increase scrutiny only when the risk profile changes. That can mean stronger verification for unusual device, velocity, payment, or behaviour patterns, while keeping trusted users on a fast path. This reduces abandonment without opening the door to high-volume abuse.

Teams also get the sequence wrong when they assume every control must appear at the same point in the funnel. Good fraud controls are often invisible until a risk trigger appears. NIST Cybersecurity Framework 2.0 supports that mindset because it frames governance, protection, detection, and response as linked functions rather than competing workstreams.

In practice, layered identity verification works best when product, risk, and engineering agree on the thresholds that justify extra checks. If the signal is weak, do not force an expensive step-up. If the signal is strong, do not let conversion metrics override the need for assurance.

Why separate success metrics produce bad decisions

Conversion teams often celebrate a shorter funnel without measuring whether the new flow attracted more synthetic accounts, account takeover attempts, or payment abuse. Fraud teams sometimes do the opposite, adding controls that are effective in isolation but degrade the customer journey so much that legitimate users drop off. Both are incomplete if they optimise only one side of the equation.

That tension becomes clearer when you treat authentication and authorisation as control points rather than obstacles. NIST AI Risk Management Framework is not a fraud manual, but its emphasis on managing risk across the lifecycle maps well to adaptive decisioning, where the system must stay usable and controlled at the same time.

The more mature operating model is to measure combined outcomes, such as approved good users, prevented abuse, false positives, recovery effort, and downstream losses. When those signals move together, teams can see whether a control is genuinely improving the business or simply shifting cost from one queue to another.

Risk and Threat Considerations

When conversion and fraud are not aligned, attackers and abusers exploit the gap. Low-friction flows can be gamed with bots, synthetic identities, bonus abuse, account takeover, or payment abuse, while overly aggressive controls can create avoidable abandonment that hides whether the true problem is fraud or poor design.

Failure mechanism: One team relaxes assurance to improve completion rates, while another adds blunt controls to suppress abuse, and neither side sees the full effect on trust, losses, or legitimate-user drop-off.

Impact: The result can be higher fraud rates, weaker identity confidence, more manual review, and a customer experience that is both less secure and less profitable than intended.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesRisk-based identity assurance directly supports adaptive verification in conversion and fraud flows.
Recommendation — Apply assurance levels to step up verification only when risk signals justify it.
NIST CSF 2.0GV.OC-01 — Organizational ContextShared conversion-fraud goals depend on common business context and aligned outcomes.
PR.AA-05 — Protective TechnologyAdaptive checks rely on enforcing stronger verification for higher-risk activity.
DE.CM-01 — Monitoring and AnalysisBalancing friction and abuse requires monitoring user behaviour and abuse indicators.
Recommendation — Align fraud and conversion goals to the same business context and decision model. Use step-up controls to increase assurance when user or transaction risk rises. Monitor behavioural signals to detect when conversion changes are increasing abuse.

Practitioner Guidance

What to prioritise: Define a shared decision policy for when the journey should stay friction-light and when it should step up. The policy should be driven by observable risk signals, not by whichever team owns the last optimisation review.

What to verify: Check that every added control has a measurable purpose, such as reducing a specific fraud pattern or increasing confidence in a risky transaction. If you cannot name the abuse case, the control is probably too blunt or too expensive.

What good looks like: Trusted users move quickly, suspicious activity is challenged, and both teams can explain the same journey in terms of conversion, loss prevention, and assurance rather than defending separate metrics.

Practitioner takeaway: The goal is not “more friction” or “less friction”, it is calibrated friction, applied only where the risk justifies the cost of asking for more proof.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org