Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What do security teams get wrong about balancing…
Identity Beyond IAM

What do security teams get wrong about balancing fraud prevention and customer conversion in CIAM?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Identity Beyond IAM

The common mistake is treating fraud and friction as opposing goals. If every user faces the same challenge, legitimate customers abandon the journey. CIAM works better when risk-based authentication uses signals such as device reputation, location, velocity, and behaviour to add friction only when risk rises. That keeps low-risk users moving while challenging suspicious activity.

Why This Matters for Security Teams

CIAM teams are often measured on two outcomes that seem to conflict: reducing fraud losses and preserving customer conversion. The mistake is assuming the only lever is blanket step-up authentication. That approach ignores the reality that most customer journeys are not equally risky at every point. Risk-based decisions should be tied to context such as device reputation, IP anomalies, velocity, and behavioural changes, then applied only when the signal justifies added friction.

This matters because over-challenging low-risk users creates abandonment, support load, and brand damage, while under-challenging high-risk sessions leaves account takeover, bot abuse, and synthetic identity fraud unchecked. Guidance from NIST SP 800-53 Rev 5 Security and Privacy Controls supports adaptive access control as a control objective, but current practice still varies widely in how it is tuned. NHIMG research also shows how fragile identity operations can be in practice: in The State of Non-Human Identity Security, only 1.5 out of 10 organisations are highly confident in securing NHIs, which is a useful warning sign for any identity programme relying on static assumptions.

In practice, many security teams discover they have overfit fraud controls to worst-case scenarios only after legitimate users have already abandoned the funnel.

How It Works in Practice

Effective CIAM balances conversion and fraud by moving from static rules to continuous risk evaluation. That usually means collecting signals at login, signup, checkout, password reset, and high-value account changes, then combining them into a policy decision that determines whether the user proceeds, receives a step-up challenge, or is blocked. The key is not to add more friction everywhere, but to reserve it for the moments that matter.

Common signals include device fingerprint stability, geolocation drift, impossible travel, velocity, email reputation, browser automation indicators, and recent credential exposure. A low-risk returning customer may pass without interruption, while a suspicious session may trigger MFA, passkeys, document verification, or a delayed transaction review. This aligns with the broader zero trust idea that trust should be earned per request, not granted once and reused indefinitely. For identity assurance, eIDAS 2.0 - EU Digital Identity Framework reflects the direction of travel toward stronger, contextual identity assertions rather than broad assumptions.

Operationally, teams should separate fraud policy from authentication mechanics:

  • Use low-friction checks first, such as passive risk scoring and device recognition.
  • Reserve step-up for thresholds that indicate meaningful fraud probability.
  • Shorten challenge duration so security review does not become journey abandonment.
  • Measure drop-off, false positives, and fraud capture together, not separately.

NHIMG case studies also show why static credentials are a weak control anchor: TruffleNet BEC Attack — Stolen AWS Credentials illustrates how stolen secrets can be reused at scale once a trust boundary is too permissive. These controls tend to break down when risk engines are tuned only for fraud loss and not for user journey impact, because legitimate customers become collateral damage.

Common Variations and Edge Cases

Tighter fraud controls often increase abandonment and support overhead, requiring organisations to balance conversion against the operational cost of investigation. That tradeoff becomes especially visible in high-growth products, regulated onboarding, and markets with high mobile usage, where even small amounts of friction can suppress conversion materially.

There is no universal standard for this yet, but current guidance suggests tuning controls by transaction type and customer segment rather than applying one policy to the entire population. For example, account creation may justify stronger bot and synthetic identity controls, while routine sign-in may rely more on passive risk scoring. High-risk actions such as payout changes, beneficiary updates, or profile recovery deserve stricter step-up than simple browsing or cart addition. This is also where fraud and IAM teams must coordinate, because a decision that looks conservative to one group can be destructive to the other.

The hardest edge cases are returning customers with legitimate travel, shared devices, accessibility needs, or password reset flows after a security event. Over-reliance on one signal, such as geolocation, can create avoidable false positives. Better practice is evolving toward layered signals, contextual thresholds, and rapid exception handling. The goal is not zero friction, but proportionate friction that preserves trust and conversion while still catching suspicious behaviour.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-02Adaptive access decisions support risk-based CIAM controls.
NIST SP 800-63IAL2Identity assurance levels help match verification strength to account risk.
OWASP Non-Human Identity Top 10NHI-03Credential misuse in CIAM overlaps with poor secret handling and rotation.
NIST AI RMFGOVERNRisk-based CIAM needs accountability for model-driven decisions.
NIST Zero Trust (SP 800-207)PR.AC-6Zero trust supports continuous verification rather than one-time login trust.

Reduce fraud blast radius by limiting credential lifetime and rotating exposed secrets quickly.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org