Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› When should merchants prioritise data sharing over tighter…
Cyber Security

When should merchants prioritise data sharing over tighter payment friction controls?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Cyber Security

Merchants should prioritise data sharing when fraud patterns span multiple parties in the payment ecosystem and authentication alone does not stop abuse. PSD2 can shift strong authentication to issuing banks, but that does not eliminate synthetic fraud, friendly fraud, or social engineering. Shared data helps teams preserve conversion while improving detection and reducing unnecessary transaction failures.

When data sharing beats tighter payment friction

Data sharing is the better lever when the problem is ecosystem-wide fraud, not a weak step in one checkout flow. If the same device, identity signal, or behavioural pattern shows up across merchants, acquirers, issuers, and fraud teams, sharing those signals can improve decisions without forcing more customers through harder authentication or extra declines.

The practical test is whether friction is blocking good customers more than it is stopping bad ones. If authentication already happens upstream, or if the attack method is synthetic fraud, social engineering, or post-authentication abuse, a narrower checkout journey usually helps less than better cross-party visibility.

What merchants are really trading off

Friction controls are strongest when the merchant can directly stop a high-risk transaction at the point of payment. Data sharing is stronger when the merchant needs better context to separate legitimate variation from coordinated abuse. That means the decision is less about “security versus conversion” and more about where the best evidence lives, and who can act on it fastest.

Shared data can include fraud fingerprints, device reputation, chargeback signals, account history, email or phone reuse, and suspicious behavioural patterns. Those signals help because a single merchant often sees only one slice of the attack, while the abuse pattern becomes clearer when multiple parties contribute to the picture.

In payment flows, this also matters because one control can shift risk rather than remove it. Strong customer authentication may reduce some card-present or login abuse, but it does not by itself solve first-party fraud, mule activity, or disputes that are only visible after authorisation.

Where shared signals create the most value

Data sharing is most useful when the merchant sees repeated low-value abuse, bursty test transactions, account takeover patterns, or fraud that moves across channels and brands. In those cases, the goal is not to add more customer steps, but to improve the decision quality of the steps already in place. That usually preserves conversion better than simply adding another challenge screen.

It is also the right direction when the merchant is trying to reduce false positives. Better shared context can explain why a transaction is unusual without treating every anomaly as suspicious. In practice, that means fewer unnecessary declines, fewer manual reviews, and less pressure to compensate with heavier friction at checkout.

For governance and control design, the relevant discipline is to treat payment data as an operational security input, not just a reporting asset. Controls around access, logging, retention, and purpose limitation still matter because the same shared signals that improve detection can also become sensitive if they are overexposed or retained too broadly. Merchants can anchor that control thinking in CIS Controls v8 and the broader control structure in ISO/IEC 27001:2022 Information Security Management.

Why more friction can be the wrong answer

Extra friction often creates diminishing returns. Once the obvious fraud path is already covered, additional challenge steps mostly affect legitimate customers, especially repeat buyers, mobile users, and edge cases that already carry some natural variance. At that point, the merchant is paying a conversion cost for a control that does not materially improve loss prevention.

There is also a systems effect. If every participant hardens only its own checkout step, fraud can migrate to weaker points elsewhere in the flow, such as account creation, refund abuse, or post-purchase dispute handling. Shared intelligence helps because it lets merchants see patterns that single-step friction cannot reveal.

That is why payment governance should be measured against the whole fraud lifecycle, not only authorisation success. A merchant that wants stronger assurance without degrading the customer experience can pair shared signals with targeted controls, rather than making the whole journey uniformly harder. The relevant cloud and ecosystem control perspective is also well captured in CSA Cloud Controls Matrix.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementShared fraud data depends on controlled access to sensitive transaction signals.
Recommendation — Restrict access to fraud-sharing data and review who can consume or export it.
ISO/IEC 27001:2022A.5.15 — Access controlPayment data sharing needs controlled access and purpose-bound use.
Recommendation — Define and enforce access rules for shared payment and fraud datasets.
CSA Cloud Controls MatrixIAM — Identity and Access ManagementCross-party fraud intelligence sharing relies on governed access between parties.
Recommendation — Limit fraud-data access to approved parties and audit each sharing relationship.

Practitioner Guidance

What to prioritise: Prioritise shared fraud intelligence when losses are cross-merchant, cross-channel, or post-authentication, and keep friction targeted to the few steps where it actually changes the outcome.

What to verify: Verify whether the fraud signal is being generated at checkout, after authorisation, or in downstream dispute handling. If the abuse appears only after payment approval, adding friction at the front door is usually the wrong fix.

Decision rule: If a friction increase mainly raises customer abandonment while leaving the attack pattern intact, favour better data sharing and narrower, risk-based checks instead.

Practitioner takeaway: The best payment control is the one that moves the fraud decision closer to the evidence, not the one that simply makes the customer experience harder.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org