
Fraud Controls
Part of Payment authentication and fraud controls
Reviewing false declines alongside fraud losses
Fraud controls can appear successful when reported fraud falls, even if they also stop many legitimate buyers.
Fraud controls can appear successful when reported fraud falls, even if they also stop many legitimate buyers. Review both sides of the decision: orders that passed and later proved fraudulent, and good transactions that the risk setup rejected. The second group is harder to observe, so do not present a blocked payment as a confirmed fraud case.
Separate the reasons for failure
Split merchant risk blocks from issuer declines, authentication failures and customer abandonment. They have different causes and owners. A rule change may reduce merchant blocks but have no effect on an issuer declining cards. Record the provider's outcome and rule identifier where available, then compare only like-for-like traffic.
Define the observation window for fraud outcomes. Disputes can arrive after an order is fulfilled, and not every dispute means fraud.
Calculate counts and value, but also consider goods loss, operating effort and the customer value potentially lost through a false decline. Avoid combining these into one confident “fraud prevented” number if the counterfactual is unknown.
Find evidence of good orders blocked
A customer contacting support after a blocked payment, a successful later attempt with another method, or a manual review can suggest a false positive. None proves that every similar blocked payment was good. Adyen documents a control-traffic approach that helps assess false positives and true positives within its system. Whether a merchant has comparable data depends on the provider and settings.
Look for patterns by rule, payment method, customer tenure, product and geography, while handling personal data appropriately. If one new rule coincides with a rise in legitimate-customer complaints, review its matched transactions. Do not automatically allowlist a broad group or retry a rejected payment without checking the provider's process and the original reason.
Make the decision reversible
Agree on the acceptable loss and acceptance measures before changing a threshold. Review a small sample of cases with fraud, customer support and payments staff. Change one major rule at a time where possible, document its date and scope, and watch both early acceptance and later fraud signals. Some providers support backtesting or control datasets; those are tools to inform, not guarantees of future performance.
The useful review asks whether a control stopped the right transactions at a tolerable cost. A lower fraud count alone cannot answer that question.
Reversible Decision Process for Risk Rule Changes
- Sample Review with Cross-Functional TeamInclude payments, fraud and support staff
- Implement One Change at a TimeDocument date, scope and rule ID


