Acceptable friction is the level of challenge a platform can introduce before legitimate users abandon the journey or conversion drops materially. In fraud governance, it is the practical boundary between security and usability, and it must be tuned to the specific abuse profile of the workflow.
What Acceptable Friction Means in Fraud Governance
Acceptable friction is not just “less friction is better.” It is the point where added challenge still helps suppress abuse, but does not introduce enough abandonment to damage the business outcome the workflow exists to achieve.
Why Acceptable Friction Exists
Every login, payment, signup, recovery, or step-up check creates a trade-off between trust and conversion. In low-risk paths, heavy challenge can be counterproductive; in high-abuse paths, too little challenge invites fraud, bots, account takeover, and synthetic activity to scale.
The right level depends on the workflow’s value, the attacker’s incentive, the user population, and the control already present around the journey. A one-size-fits-all threshold usually fails because the same control can be tolerable in a checkout flow and harmful in a support or onboarding flow.
How Teams Set the Threshold
Acceptable friction is typically tuned by observing where legitimate users drop off, where suspicious activity declines, and where the control meaningfully changes attacker economics. The goal is not to eliminate every obstacle, but to place enough resistance in the path to make abuse uneconomic without breaking normal use.
Teams usually evaluate this through experiment data, funnel analysis, step-up challenge outcomes, and fraud loss signals. The practical question is whether the added control produces a measurable security gain that justifies the user cost in that specific journey.
Where It Shows Up in Security Design
This concept appears in onboarding, authentication, account recovery, transaction approval, device binding, and risk-based step-up flows. It also affects how teams combine signals, because a single rigid control often creates more user pain than a layered model that escalates only when risk rises.
NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because access, authentication, monitoring, and configuration controls can be combined to reduce abuse without forcing every user through the same burden.
NIST SP 800-63 Digital Identity Guidelines also helps frame how assurance strength and user burden should be balanced in identity flows that must remain usable.
Risk and Threat Considerations
Too little friction can make fraud cheap to scale, while too much friction can drive legitimate users away, increase support load, and create workarounds that weaken the control. The risk is rarely just conversion loss or just abuse, it is the interaction between the two.
Failure mechanism: Attackers exploit weak or absent challenge to automate signups, credential abuse, payment abuse, or account recovery abuse, while legitimate users abandon flows that become slow, confusing, or repetitive.
Impact: The business can see higher fraud losses, lower completion rates, more support contacts, and a gradual erosion of trust in the control itself.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Acceptable friction balances access resistance with workflow usability. |
| IA-5 — Authenticator Management | Friction often comes from authenticator and step-up design in user journeys. | |
| AU-2 — Event Logging | Measuring friction needs event signals from the affected workflow. | |
| Recommendation — Apply least-privilege access to raise challenge only where risk justifies it. Tune authenticator requirements to add challenge without breaking legitimate completion. Log challenge outcomes and drop-off events to calibrate friction against fraud. | ||
| NIST SP 800-63 | Digital Identity Guidelines | The guideline directly addresses assurance and usability trade-offs in identity flows. |
| Recommendation — Use assurance levels to choose challenge strength that matches the journey's risk. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication, and Access Control | Friction is a control choice within identity and access enforcement. |
| Recommendation — Align challenge intensity to the access risk of the specific workflow. | ||
Practitioner Guidance
Governance implication: Treat acceptable friction as a workflow-specific control decision, not a universal policy. The right threshold depends on the abuse profile, the value at risk, and the tolerance for user drop-off in that journey.
What to watch for: A control is probably too heavy when users consistently fail or abandon it for normal reasons, and probably too light when suspicious activity continues with little resistance. The useful boundary is where security uplift remains visible without creating avoidable friction for the intended user base.
Related resources from NHI Mgmt Group
- When does zero trust IAM create more friction than risk reduction?
- How should organisations implement PSD2 controls without adding too much checkout friction?
- How should security teams implement zero trust authentication without adding too much user friction?
- How should security teams replace traditional MFA without creating new access friction?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org