Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM Why does Australia’s CNP fraud framework create so…
Identity Beyond IAM

Why does Australia’s CNP fraud framework create so much operational risk for online merchants?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Identity Beyond IAM

The risk comes from the combination of low chargeback thresholds, quarterly measurement, and escalating remedies. Once a merchant exceeds the framework’s limit, it may face monitoring, mandatory authentication controls, and financial penalties. That creates commercial pressure because stronger verification can reduce fraud, but it can also add friction and lower conversion rates.

Why the framework creates operational pressure rather than just fraud pressure

The operational risk is not limited to card-not-present fraud losses. The framework turns fraud performance into a measured operating condition, so merchants must manage fraud controls, customer experience, and payment acceptance as one system. That is why it becomes an operations problem: the organisation can be penalised for weak fraud outcomes, but also harmed if the control response slows checkout or suppresses legitimate sales.

A merchant therefore has to treat fraud controls as production controls. The practical tension is that the same verification step that reduces abuse can increase abandonment, customer support load, and exception handling, especially when the business has high-volume checkout or thin-margin conversion economics.

Why the measurement model amplifies the burden

Quarterly measurement and threshold-based escalation create a short feedback loop. A merchant can move from acceptable to monitored status quickly, which forces continuous tuning rather than occasional review. That makes the framework operationally demanding because the business must watch trendlines, not just end-of-quarter totals, and it must be ready to change controls before the next measurement cycle closes.

Escalating remedies also reduce flexibility. Once a merchant crosses the limit, the response is no longer purely internal optimisation; it can become mandated control uplift, added review steps, or financial consequences. In practice, that means the payment team, fraud team, product team, and operations team all inherit the same performance issue and must coordinate changes fast.

Risk and Threat Considerations

The main risk is that the framework creates a binary commercial exposure around a metric that is inherently noisy. Fraud patterns, issuer behaviour, and customer mix can shift quickly, so a merchant may incur intervention even when the underlying business has not materially changed. The resulting control response can also push bad actors to probe the weakest step in the checkout flow rather than the fraud control itself.

Failure mechanism: A merchant exceeds the allowed fraud threshold, then has to add stronger verification, monitoring, or remediation steps under time pressure. That can increase false declines, operational exceptions, and manual review volume while fraudsters adapt to whichever friction point remains easiest to bypass.

Impact: The merchant can suffer direct financial penalties, slower conversion, higher customer friction, and extra support and operations cost. Over time, repeated interventions can also distort checkout design, making the business optimise for compliance with the fraud framework instead of overall revenue quality.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01 — Organizational ContextThe framework ties fraud controls to business operating context and risk appetite.
DE.CM-08 — Anomalies and Events DetectedMerchants need ongoing monitoring to spot fraud trend changes before escalation triggers.
RS.MI-01 — Incident MitigationEscalating remedies require rapid mitigation when fraud performance crosses policy limits.
Recommendation — Align fraud thresholds with business impact and conversion tolerance. Monitor fraud-rate anomalies continuously and escalate before threshold breach. Activate mitigation steps quickly when fraud thresholds are exceeded.
CIS Controls v86 — Access Control ManagementCheckout fraud controls often hinge on controlling abusive access and transaction abuse paths.
Recommendation — Restrict abusive access paths and review exceptions that enable fraud.

Practitioner Guidance

What to prioritise: Track the framework as an operating limit, not a quarterly report card. The key question is whether current fraud controls are stable enough to stay below the trigger while preserving approval rates and conversion, because the business cost of crossing the line is usually larger than the marginal cost of early tuning.

What to verify: Validate whether the merchant can separate genuine fraud reduction from simple friction increase. If tighter verification reduces fraud but also raises abandonment or manual review materially, treat that as a control design problem, not just a fraud problem.

Practitioner takeaway: The merchants that struggle most are usually the ones that manage fraud, checkout experience, and payment operations as separate functions; this framework forces them to run them as one governed control surface.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org