Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM Why do traditional fraud controls create so much…
Identity Beyond IAM

Why do traditional fraud controls create so much friction for legitimate customers?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Identity Beyond IAM

Traditional fraud controls often rely on static rules and heavy suspicion, so they flag normal buying behaviour as risky. That creates false declines, slows checkout, and can make legitimate customers feel treated like fraudsters. The business result is lost revenue and weaker conversion, especially when merchants overcorrect to avoid fraud instead of managing it with better detection.

Why friction happens when fraud teams optimise for certainty

Traditional fraud stacks are usually built to minimise loss by increasing suspicion, which sounds safe but often works against normal commerce. Static rules, device signals, velocity checks, and hard thresholds are good at spotting obvious abuse, but they also penalise legitimate variability, such as a new shipping address, a travel purchase, or a first-time buyer.

That mismatch matters because fraud review is not operating on perfect information. Merchants only see behaviour, not intent, so conservative rules tend to treat ambiguity as danger. The result is a control that is effective at blocking some fraud but expensive for customers whose behaviour looks unusual for harmless reasons.

The friction is often worst where the control has low context and low tolerance for change. A checkout system that cannot distinguish a genuine behavioural shift from suspicious activity will either send more orders to review or reject them outright, and both outcomes create avoidable customer effort. For high-volume businesses, even small false-positive rates can become a material conversion problem.

Why fraud controls and customer experience collide

Friction usually appears when the control path is longer than the purchase path. Extra steps, manual reviews, step-up verification, and repeated declines all add latency, and latency is costly in checkout. Legitimate customers often do not retry, especially if the merchant gives little explanation or asks them to complete a second round of verification mid-purchase.

The collision is also structural. Fraud teams are measured on loss prevention, while growth teams are measured on conversion, so the system can drift toward “safer” settings that are not actually safer for the business. If the decision logic is too rigid, it will overfit to old fraud patterns and underperform against normal customer behaviour that does not match historical templates.

This is why modern fraud programmes increasingly favour layered detection over blunt denial. They need enough signal to separate risky transactions from legitimate edge cases, but they also need a customer journey that preserves trust. Controls that cannot distinguish between high risk and unfamiliar but valid behaviour become a tax on good customers.

What practitioners should tune instead of simply tightening rules

Static thresholds should be treated as a starting point, not the operating model. The most useful question is not whether a rule catches fraud, but whether it catches fraud without collapsing legitimate approvals in adjacent cases. That means looking at decline reason, review rate, false-positive rate, and customer drop-off together, not as isolated metrics.

Practitioners should also separate high-confidence fraud signals from low-confidence anomaly signals. A payment that fails because of clear credential abuse is different from one that looks unusual because of a first-time device, an international IP, or an atypical basket size. When those cases are handled identically, the fraud stack becomes needlessly blunt.

For teams building or tuning controls, the practical aim is to make suspicious transactions more observable and less binary. That usually means better risk scoring, better post-decision analysis, and more careful use of step-up checks so that legitimate customers are challenged only when the expected loss justifies the added friction.

Risk and Threat Considerations

Overly aggressive fraud controls can create their own business risk by suppressing good transactions at scale, especially in markets with mobile users, returning customers, or high purchase variability. At the same time, under-tuned friction can push teams to weaken controls broadly just to recover conversion, which can open the door to easier abuse.

Failure mechanism: The control model relies on broad signals and rigid thresholds, so normal customer variation is misclassified as suspicious activity. That drives false declines, manual-review backlog, and repeated authentication or verification prompts that legitimate users abandon.

Impact: Revenue leakage, lower conversion, damaged trust, and a control posture that either frustrates customers or gets softened until real fraud is harder to stop.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-08 — Audit Log ManagementFalse-decline tuning depends on decision logging and review traceability.
CIS-10 — Malware DefensesFraud controls often use device and behaviour signals that complement broader abuse detection.
Recommendation — Log fraud decisions and review outcomes so you can tune thresholds from evidence. Correlate fraud signals with broader abuse telemetry to reduce blind spots.
NIST CSF 2.0PR.AA — Identity and Access ManagementCustomer verification and step-up checks materially affect how access to transactions is granted.
DE.CM — Continuous MonitoringFraud friction should be evaluated through live monitoring of declines, reviews, and abandonment.
Recommendation — Align step-up verification with the minimum assurance needed for the transaction. Monitor conversion, false declines, and review backlog as one operational signal set.
OWASP Agentic AI Top 10A4 — Identity and Privilege AbuseAutomated decisioning can become overly punitive when authority is applied without contextual restraint.
Recommendation — Constrain automated actions so risky decisions remain reviewable and reversible.

Practitioner Guidance

What to prioritise: Start by measuring false declines separately from confirmed fraud loss, then segment them by customer cohort, channel, geography, and transaction type. The goal is to find where the control is most punitive to legitimate behaviour, not just where losses are highest.

What to verify: Check whether step-up flows actually recover good transactions or just add abandonment. If a control forces customers to retry, prove that the retry path is fast, understandable, and materially more accurate than the original decision.

Decision rule: If a rule catches low-value suspicious traffic but creates disproportionate decline or review volume on trusted customers, tune the rule or replace it before adding more friction elsewhere in the funnel.

Practitioner takeaway: The right balance is not “more friction equals more safety”, it is enough friction to stop real abuse while keeping legitimate buyers moving with minimal interruption.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org