Fraud Controls

Part of Payment authentication and fraud controls

Comparing risk-based checks with blanket restrictions

A blanket payment restriction applies the same block or challenge to a broad group.

A blanket restriction blocks or challenges every payment in a broad group; a risk-based check uses transaction context to assess individual payments. Prefer a blanket action when a strong group-wide reason or provider requirement justifies it, and risk-based checks when transaction patterns can distinguish risk and be reviewed. Adyen Protect provides a named example of risk-based scoring.

Define the rule being compared

A blanket rule might reject payments from a geography, payment method, order-value band or customer type. It acts on group membership, so legitimate payments in that group may also be affected; a high order value alone does not establish fraud.

Adyen gives more than three top-ups in an hour and more than three retail purchases per hour as examples of customer behaviour a custom rule could treat as anomalous. Compared with blocking every top-up or retail purchase, these rules focus on repeated activity; a combination of signals may also warrant review rather than automatic rejection.

Risk-Based Checks vs Blanket Restrictions: Key Differences

Scope of Application
Targets specific transaction patterns or behaviours
Impact on Legitimate Transactions
Lower – only high-risk transactions are affected
Example Use Case
More than three top-ups in an hour or retail purchases per hour
Trigger Mechanism
Custom rules based on behavioural signals and machine learning
Opposite Approach
Blanket restriction (applies to entire group regardless of context)

Compare outcomes, not just block counts

Adyen Protect machine learning assesses the properties of each incoming payment request, using historical data connected to the transaction to assign a risk level from Very Low to Very High. Its Machine learning: fraud risk rule is a premium feature for payments that can be disputed, such as credit and debit card payments; it blocks a transaction before authorisation when its risk classification exceeds the selected threshold.

The Machine learning: bot attack risk rule, available in basic and premium versions, detects and blocks transactions arriving at an unusually fast rate with suspicious payment properties. Adyen says this can indicate scripted attacks such as card testing and bot attacks, and mostly prevents large-scale attacks. The rule has no configuration options; Adyen recommends premium and custom rules for adding logic about anomalous customer behaviour.

A blanket restriction applies its block or challenge to the whole selected group, while a risk classification can target payments assessed as riskier. Neither guarantees that every blocked payment is fraudulent: Adyen says the blocking threshold depends on the business model and the difference in cost between a fraud case and a false decline.

For either approach, compare approval and completed-order rates, merchant risk blocks, issuer declines, manual-review workload and later fraud outcomes for comparable periods and affected traffic. Consider product, margin, fulfilment and customer lifetime value when reviewing the trade-off; a larger block count alone does not show that a rule is better.

Adyen Protect Risk Rule Performance Indicators

Risk Classification Range
Very Low to Very High
Rule Type
Machine Learning: Fraud Risk (Premium Feature)
Action Triggered
Block before authorisation if risk exceeds threshold
Bot Attack Detection
Yes – detects fast-rate suspicious transactions
Configuration Options
No (for bot attack rule); custom logic available via premium features

Choose a response ladder

Use a risk-based check when transaction patterns or risk classifications can distinguish the payments of concern and the signals and outcomes can be audited. For example, a blanket restriction could block every top-up, while a custom rule could identify more than three top-ups in an hour as anomalous; Adyen gives that frequency as an example, not a universal threshold.

Choose a blanket block when there is a strong reason to restrict the whole group or an actual provider requirement. For a lower-confidence signal, consider review or a supported authentication request if operationally feasible, and define how a legitimate customer can recover from a failed attempt.

Adyen's fraud-risk rule requires premium features, while its bot-attack rule has no configuration options; provider actions and account settings therefore affect which checks are available. Before changing a rule, inspect historical matches, use provider-supported tests and assign an owner to review the result after rollout. An unchecked complex score can be as blunt as a blanket restriction.

Implementing a Risk-Based Check: Recommended Steps

  1. Inspect Historical MatchesReview past transaction data for similar patterns
  2. Use Provider-Supported TestsValidate rule logic in a controlled environment
  3. Assign OwnershipDesignate a team member to review post-rollout outcomes
  4. Avoid Unchecked Complex ScoresEnsure scoring logic is auditable and not as blunt as blanket blocks

More from Fraud Controls