Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Acceptable Friction
Governance, Ownership & Risk

Acceptable Friction

← Back to Glossary
By NHI Mgmt Group Updated October 10, 2026 Domain: Governance, Ownership & Risk

Acceptable friction is the level of challenge a platform can introduce before legitimate users abandon the journey or conversion drops materially. In fraud governance, it is the practical boundary between security and usability, and it must be tuned to the specific abuse profile of the workflow.

What Acceptable Friction Means in Fraud Governance

Acceptable friction is not just “less friction is better.” It is the point where added challenge still helps suppress abuse, but does not introduce enough abandonment to damage the business outcome the workflow exists to achieve.

Why Acceptable Friction Exists

Every login, payment, signup, recovery, or step-up check creates a trade-off between trust and conversion. In low-risk paths, heavy challenge can be counterproductive; in high-abuse paths, too little challenge invites fraud, bots, account takeover, and synthetic activity to scale.

The right level depends on the workflow’s value, the attacker’s incentive, the user population, and the control already present around the journey. A one-size-fits-all threshold usually fails because the same control can be tolerable in a checkout flow and harmful in a support or onboarding flow.

How Teams Set the Threshold

Acceptable friction is typically tuned by observing where legitimate users drop off, where suspicious activity declines, and where the control meaningfully changes attacker economics. The goal is not to eliminate every obstacle, but to place enough resistance in the path to make abuse uneconomic without breaking normal use.

Teams usually evaluate this through experiment data, funnel analysis, step-up challenge outcomes, and fraud loss signals. The practical question is whether the added control produces a measurable security gain that justifies the user cost in that specific journey.

Where It Shows Up in Security Design

This concept appears in onboarding, authentication, account recovery, transaction approval, device binding, and risk-based step-up flows. It also affects how teams combine signals, because a single rigid control often creates more user pain than a layered model that escalates only when risk rises.

NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because access, authentication, monitoring, and configuration controls can be combined to reduce abuse without forcing every user through the same burden.

NIST SP 800-63 Digital Identity Guidelines also helps frame how assurance strength and user burden should be balanced in identity flows that must remain usable.

Risk and Threat Considerations

Too little friction can make fraud cheap to scale, while too much friction can drive legitimate users away, increase support load, and create workarounds that weaken the control. The risk is rarely just conversion loss or just abuse, it is the interaction between the two.

Failure mechanism: Attackers exploit weak or absent challenge to automate signups, credential abuse, payment abuse, or account recovery abuse, while legitimate users abandon flows that become slow, confusing, or repetitive.

Impact: The business can see higher fraud losses, lower completion rates, more support contacts, and a gradual erosion of trust in the control itself.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeAcceptable friction balances access resistance with workflow usability.
IA-5 — Authenticator ManagementFriction often comes from authenticator and step-up design in user journeys.
AU-2 — Event LoggingMeasuring friction needs event signals from the affected workflow.
Recommendation — Apply least-privilege access to raise challenge only where risk justifies it. Tune authenticator requirements to add challenge without breaking legitimate completion. Log challenge outcomes and drop-off events to calibrate friction against fraud.
NIST SP 800-63Digital Identity GuidelinesThe guideline directly addresses assurance and usability trade-offs in identity flows.
Recommendation — Use assurance levels to choose challenge strength that matches the journey's risk.
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication, and Access ControlFriction is a control choice within identity and access enforcement.
Recommendation — Align challenge intensity to the access risk of the specific workflow.

Practitioner Guidance

Governance implication: Treat acceptable friction as a workflow-specific control decision, not a universal policy. The right threshold depends on the abuse profile, the value at risk, and the tolerance for user drop-off in that journey.

What to watch for: A control is probably too heavy when users consistently fail or abandon it for normal reasons, and probably too light when suspicious activity continues with little resistance. The useful boundary is where security uplift remains visible without creating avoidable friction for the intended user base.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org