Merchants should prioritise reducing false positives when fraud controls are rejecting a meaningful share of legitimate orders. The article notes that many merchants believe only a small fraction of declines are false, yet a much larger share can be legitimate. When that happens, overly strict filters can destroy more value than they save by blocking high-value customers and repeat buyers.
Why merchants should tune fraud rules to the real cost of false positives
fraud filters are not just about stopping bad orders, they also decide how many legitimate customers you turn away. The right threshold depends on your order mix, customer lifetime value, and operational tolerance for review. If false declines are materially harming revenue, loyalty, or conversion, the merchant should shift attention from maximum strictness to better precision.
What happens when filters are too strict
Overly aggressive fraud controls tend to fail in the same places every time: repeat buyers, higher-value baskets, cross-border orders, and legitimate customers who do not look routine. That creates a hidden tax on growth because the business pays for lost revenue, abandoned carts, customer-service handling, and churn. The tighter the filter, the more important it becomes to know whether the decline rate is actually improving fraud outcomes or just increasing friction.
For merchants, the practical question is not whether a rule “catches fraud”, but whether it improves net business value after chargebacks, review costs, and lost legitimate sales are included. A filter that reduces fraud by a small amount but blocks many genuine orders can be the wrong control in a low-loss, high-conversion segment.
How to decide when to ease up versus harden controls
Start by separating high-confidence fraud signals from borderline cases. If the rule is catching clearly abusive behaviour, keep it tight. If it is mainly intercepting normal customer behaviour, reduce the weight of that rule, move the transaction into step-up review, or apply more context before decline. This is especially important when the merchant depends on repeat purchase volume or has thin margins on acquisition.
Useful decision inputs include false-positive rate by segment, review overturn rate, post-decline customer recovery, and the business value of approved repeat customers. The more valuable and predictable the legitimate segment, the more conservative you should be about automatic declines. In many cases, a better outcome comes from targeted exceptions and better signal quality rather than a blunt increase in filter strictness.
Risk and Threat Considerations
When fraud filters are tuned too aggressively, the main risk is not only lost revenue, but also distorted decision-making. Teams may treat a high decline rate as proof of stronger protection when it is actually just stronger friction, which can mask the real exposure and push legitimate customers away.
Failure mechanism: Weak signal discrimination, excessive rule stacking, or thresholds set without segment-level performance analysis can cause legitimate transactions to be rejected at scale while genuine fraud still slips through other paths.
Impact: Merchants can lose conversion, damage repeat-customer trust, increase manual review load, and misallocate fraud operations effort toward blocking low-risk buyers instead of reducing real loss.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-12 — Network Infrastructure Management | Supports tuning security controls to reduce operational friction and false blocking. |
| Recommendation — Measure control outcomes and adjust thresholds when protection creates excessive business disruption. | ||
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Applies because fraud-filter tuning is a risk trade-off between loss prevention and customer harm. |
| Recommendation — Set fraud thresholds by balancing expected loss, conversion impact, and acceptable false-positive rates. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Relevant where fraud controls govern whether legitimate customers can proceed with transactions. |
| Recommendation — Review control settings to ensure they do not block legitimate access or business activity unnecessarily. | ||
Practitioner Guidance
What to prioritise: Prioritise reducing false positive first when declines are disproportionately hitting profitable, repeat, or low-risk customer segments. That is the point at which tighter fraud filters stop behaving like a protection control and start behaving like a revenue leak.
What to verify: Check the false-decline rate by channel, geography, basket size, and customer tenure before tightening thresholds further. If review overturns are common, the control is probably too blunt for the segment it is targeting.
Practitioner takeaway: The right balance is not “looser” or “stricter” in the abstract, it is whether the filter is preserving more loss than it is creating in legitimate business harm.
Related resources from NHI Mgmt Group
- When should merchants prioritise fraud prevention over fraud detection in the checkout flow?
- How should security teams prioritise NHI remediation in cloud environments?
- What is the difference between patching a vulnerability and reducing identity blast radius?
- Should organisations prioritise external exposure or internal credential governance first?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org