Ownership should be shared, with digital leaders playing a central role because they understand customer behavior and the sign-up journey. Security and risk teams should provide controls, threat signals, and governance, while digital teams tune the experience so legitimate customers are not blocked. The article’s point is that revenue protection is not only a security problem.
Why New Account Fraud Ownership Cannot Sit in One Team
new account fraud sits at the intersection of acquisition, identity proofing, abuse detection, and customer experience, so ownership cannot be left to security alone or pushed entirely into growth teams. The practical question is not who can see the problem first, but who can coordinate the sign-up funnel, the fraud controls, and the customer impact without creating avoidable friction. That usually requires digital, marketing, and security to operate as one response path.
Digital teams own the journey, so they see where legitimate users abandon forms, where suspicious patterns cluster, and which friction points change conversion. Security and risk teams bring threat intelligence, control design, and escalation criteria. Marketing often owns the channels that attract both real customers and abuse, so campaign tuning can materially change fraud exposure. NHIMG research shows that 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, which is a reminder that abuse often begins in places the customer journey team does not monitor directly.
In practice, many organisations discover they have assigned ownership only after fraud losses rise or customer complaints spike, not when the sign-up flow first starts drifting.
How Shared Ownership Works in Practice
Shared ownership works when each team has a defined decision scope rather than a vague “inform and collaborate” arrangement. Digital should own the user journey, conversion metrics, and the operational changes to registration, onboarding, and step-up checks. Marketing should own channel quality, campaign integrity, affiliate scrutiny, and the rapid removal of sources that attract abuse. Security should own fraud detection logic, threat indicators, abuse patterns, escalation thresholds, and evidence handling. The useful model is a single response process with multiple accountable contributors, not a committee that waits for consensus.
A practical workflow usually starts with a common signal set: device anomalies, velocity spikes, synthetic identity indicators, disposable email patterns, phone-number reuse, and unusual account activation sequences. Those signals need to be visible to the team that can change the journey quickly. If digital sees a spike in failed registrations, it can introduce additional verification at the right step. If marketing sees a campaign being harvested by bots, it can pause spend or narrow targeting. If security sees a pattern consistent with scripted abuse, it can add controls, tune detection, and preserve evidence for longer-term review.
This structure works best when teams define who can approve friction, who can pause a campaign, and who can change fraud rules. It also helps to separate prevention from remediation: the sign-up path should be designed to discourage abuse up front, while case management handles disputed or borderline accounts after the fact. The NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because it reinforces the need for coordinated access control, monitoring, and incident handling, while NHIMG’s Ultimate Guide to NHIs — The NHI Market shows why abuse often scales through automated and machine-mediated paths rather than one-off human actions.
These controls tend to break down when ownership is split by organisational chart instead of by the actual fraud path, because no single team can then change the journey, the controls, and the channel source together.
Where the Ownership Model Gets Messy
Shared ownership increases coordination overhead, so the tradeoff is speed versus control quality. Tighter fraud intervention can reduce losses, but it can also harm conversion if the team applying the control does not understand customer behaviour. That is why the strongest operating model usually gives digital final say on journey changes, security final say on threat standards, and marketing final say on channel actions, with a pre-agreed escalation route for disputed cases.
There is also no universal standard for exactly where fraud ownership should sit in the org chart. In smaller organisations, one leader may temporarily own the programme, but the functions still need distinct responsibilities. In larger organisations, the failure mode is often diffusion: digital assumes security will spot abuse, security assumes marketing will clean up bad sources, and marketing assumes the product team will fix the funnel. The result is slow response, inconsistent customer treatment, and controls that drift away from the actual attack patterns.
The simplest test is whether the team that receives the signal can also change the thing that caused it. If not, ownership is probably too fragmented to respond effectively.
Risk and Threat Considerations
New account fraud creates a combined exposure: direct financial loss, abuse of promotional incentives, account takeover staging, and polluted identity data that weakens downstream trust decisions. The risk is not limited to bad sign-ups; once fraudulent accounts are present, they can be used for spam, credential testing, referral abuse, or as a foothold for broader trust exploitation.
Failure mechanism: Attackers exploit weak sign-up controls, channel abuse, and slow cross-team response to create accounts at scale while staying inside normal customer-flow noise. When no single team owns the end-to-end path, indicators are detected but not acted on quickly enough, and control changes lag behind the abuse pattern.
Impact: Organisations can lose revenue, distort growth metrics, degrade customer experience, and accumulate fraudulent identities that later support more serious abuse. Over time, the business may also lose confidence in its own onboarding data, which makes every downstream identity decision less reliable.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6 — Access Control Management | New account fraud often exploits weak access and onboarding controls. |
| 8 — Audit Log Management | Shared fraud response depends on usable logs and cross-team visibility. | |
| 17 — Incident Response Management | Fraud response needs clear escalation and coordinated handling. | |
| Recommendation — Tighten account creation and access rules to reduce fraudulent sign-up abuse. Centralise and review sign-up and fraud event logs for abuse patterns. Define fraud escalation paths and run coordinated response procedures. | ||
| NIST CSF 2.0 | ID.AM — Asset Management | Fraud ownership starts with knowing which journeys and channels are exposed. |
| DE.CM — Continuous Monitoring | Fraud signals must be monitored across digital and marketing funnels. | |
| RS.CO — Communications | Fraud response fails when teams cannot coordinate decisions quickly. | |
| Recommendation — Map sign-up channels and fraud-sensitive assets to responsible owners. Monitor registration activity and channel signals for abuse anomalies. Set a shared escalation path for fraud signals and control changes. | ||
| MITRE ATT&CK | T1583 — Acquire Infrastructure | Fraudsters use scaled infrastructure and automation to create accounts. |
| T1110 — Brute Force | Account fraud often includes automated credential and form abuse. | |
| Recommendation — Hunt for scripted sign-up infrastructure and block repeat abuse sources. Rate-limit and detect automated registration and credential stuffing attempts. | ||
Practitioner Guidance
What to prioritise: Establish one accountable owner for the fraud programme, but split execution authority across digital, marketing, and security. The owner should coordinate decisions, not personally operate every control.
Decision rule: If the action changes the customer journey, digital should own it; if it changes traffic source quality, marketing should own it; if it changes detection, escalation, or evidence, security should own it.
What to verify: Confirm that each team can both see the relevant signal and take the next action without waiting on another function. If a team can only report the problem, it is not truly owning that part of the response.
Practitioner takeaway: The best ownership model is the one that lets the team closest to the problem change the system fast enough to matter, while keeping fraud, revenue, and customer friction in the same governance loop.
Related resources from NHI Mgmt Group
- How should security teams make NHI best practices usable across the business?
- Who should own bot abuse response across fraud and IAM teams?
- Who is accountable when loyalty fraud occurs across marketing, support, and security teams?
- Who should own digital health access design across security and clinical teams?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org