Traditional fraud controls often rely on static rules and heavy suspicion, so they flag normal buying behaviour as risky. That creates false declines, slows checkout, and can make legitimate customers feel treated like fraudsters. The business result is lost revenue and weaker conversion, especially when merchants overcorrect to avoid fraud instead of managing it with better detection.
Why friction happens when fraud teams optimise for certainty
Traditional fraud stacks are usually built to minimise loss by increasing suspicion, which sounds safe but often works against normal commerce. Static rules, device signals, velocity checks, and hard thresholds are good at spotting obvious abuse, but they also penalise legitimate variability, such as a new shipping address, a travel purchase, or a first-time buyer.
That mismatch matters because fraud review is not operating on perfect information. Merchants only see behaviour, not intent, so conservative rules tend to treat ambiguity as danger. The result is a control that is effective at blocking some fraud but expensive for customers whose behaviour looks unusual for harmless reasons.
The friction is often worst where the control has low context and low tolerance for change. A checkout system that cannot distinguish a genuine behavioural shift from suspicious activity will either send more orders to review or reject them outright, and both outcomes create avoidable customer effort. For high-volume businesses, even small false-positive rates can become a material conversion problem.
Why fraud controls and customer experience collide
Friction usually appears when the control path is longer than the purchase path. Extra steps, manual reviews, step-up verification, and repeated declines all add latency, and latency is costly in checkout. Legitimate customers often do not retry, especially if the merchant gives little explanation or asks them to complete a second round of verification mid-purchase.
The collision is also structural. Fraud teams are measured on loss prevention, while growth teams are measured on conversion, so the system can drift toward “safer” settings that are not actually safer for the business. If the decision logic is too rigid, it will overfit to old fraud patterns and underperform against normal customer behaviour that does not match historical templates.
This is why modern fraud programmes increasingly favour layered detection over blunt denial. They need enough signal to separate risky transactions from legitimate edge cases, but they also need a customer journey that preserves trust. Controls that cannot distinguish between high risk and unfamiliar but valid behaviour become a tax on good customers.
What practitioners should tune instead of simply tightening rules
Static thresholds should be treated as a starting point, not the operating model. The most useful question is not whether a rule catches fraud, but whether it catches fraud without collapsing legitimate approvals in adjacent cases. That means looking at decline reason, review rate, false-positive rate, and customer drop-off together, not as isolated metrics.
Practitioners should also separate high-confidence fraud signals from low-confidence anomaly signals. A payment that fails because of clear credential abuse is different from one that looks unusual because of a first-time device, an international IP, or an atypical basket size. When those cases are handled identically, the fraud stack becomes needlessly blunt.
For teams building or tuning controls, the practical aim is to make suspicious transactions more observable and less binary. That usually means better risk scoring, better post-decision analysis, and more careful use of step-up checks so that legitimate customers are challenged only when the expected loss justifies the added friction.
Risk and Threat Considerations
Overly aggressive fraud controls can create their own business risk by suppressing good transactions at scale, especially in markets with mobile users, returning customers, or high purchase variability. At the same time, under-tuned friction can push teams to weaken controls broadly just to recover conversion, which can open the door to easier abuse.
Failure mechanism: The control model relies on broad signals and rigid thresholds, so normal customer variation is misclassified as suspicious activity. That drives false declines, manual-review backlog, and repeated authentication or verification prompts that legitimate users abandon.
Impact: Revenue leakage, lower conversion, damaged trust, and a control posture that either frustrates customers or gets softened until real fraud is harder to stop.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-08 — Audit Log Management | False-decline tuning depends on decision logging and review traceability. |
| CIS-10 — Malware Defenses | Fraud controls often use device and behaviour signals that complement broader abuse detection. | |
| Recommendation — Log fraud decisions and review outcomes so you can tune thresholds from evidence. Correlate fraud signals with broader abuse telemetry to reduce blind spots. | ||
| NIST CSF 2.0 | PR.AA — Identity and Access Management | Customer verification and step-up checks materially affect how access to transactions is granted. |
| DE.CM — Continuous Monitoring | Fraud friction should be evaluated through live monitoring of declines, reviews, and abandonment. | |
| Recommendation — Align step-up verification with the minimum assurance needed for the transaction. Monitor conversion, false declines, and review backlog as one operational signal set. | ||
| OWASP Agentic AI Top 10 | A4 — Identity and Privilege Abuse | Automated decisioning can become overly punitive when authority is applied without contextual restraint. |
| Recommendation — Constrain automated actions so risky decisions remain reviewable and reversible. | ||
Practitioner Guidance
What to prioritise: Start by measuring false declines separately from confirmed fraud loss, then segment them by customer cohort, channel, geography, and transaction type. The goal is to find where the control is most punitive to legitimate behaviour, not just where losses are highest.
What to verify: Check whether step-up flows actually recover good transactions or just add abandonment. If a control forces customers to retry, prove that the retry path is fast, understandable, and materially more accurate than the original decision.
Decision rule: If a rule catches low-value suspicious traffic but creates disproportionate decline or review volume on trusted customers, tune the rule or replace it before adding more friction elsewhere in the funnel.
Practitioner takeaway: The right balance is not “more friction equals more safety”, it is enough friction to stop real abuse while keeping legitimate buyers moving with minimal interruption.
Related resources from NHI Mgmt Group
- Who is accountable when fraud controls create too much friction?
- How should travel businesses reduce booking fraud without creating too much friction for legitimate customers?
- Why do rules based fraud systems create more friction for legitimate travel and event customers?
- How should organisations combine AI and traditional controls to reduce fraud without adding too much customer friction?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org