The fraud rate is the most quoted number in risk management and one of the least informative. It is easy to calculate, easy to benchmark and easy to present to a board. It is also trivially easy to improve in ways that damage the business.
A fraud rate falling from one period to the next tells you almost nothing on its own. It may reflect stronger detection. It may equally reflect a threshold change that removed thousands of legitimate customers from the population being measured. Both movements look identical on the chart.
The objective is not to stop the greatest amount of fraud. It is to make the most profitable decisions at an acceptable level of risk.
The Seductive Simplicity of the Fraud Rate
Single metrics survive because they are convenient. The fraud rate compresses a complex portfolio of decisions into one figure that can be tracked monthly and compared across peers. That convenience is exactly the problem — it removes the denominator from the conversation.
When a target is set on the fraud rate alone, the fastest route to hitting it is never better detection. Better detection is slow, requires data work and shows up over quarters. Tightening rules shows up immediately.
Three ways to lower a fraud rate without improving anything
- — Lower the score threshold and decline a wider band of customers
- — Add step-up authentication broadly, so risky sessions abandon before authorization
- — Expand manual review, then decline anything ambiguous under queue pressure
Each of these produces a better fraud dashboard. None of them produces a better business. The losses avoided are visible and attributable; the revenue forgone is invisible and unattributed.
How Fraud Teams Accidentally Destroy Good Revenue
Very few fraud teams set out to suppress revenue. The damage is structural rather than intentional, and it accumulates through ordinary, defensible decisions.
Asymmetric feedback
A confirmed fraud loss arrives with a chargeback, a case number and an owner. A declined good customer produces silence. The team receives high-quality feedback on one side of the decision and almost none on the other, so calibration drifts toward caution over time.
Rules that are never retired
Rules are written in response to specific attacks and then left in place long after the attack pattern has disappeared. Each rule was justified when created. Collectively, an unpruned rule set declines a growing population of customers for reasons no one currently owns.
Incentives that only price one error
When performance objectives reference losses and chargeback thresholds but not approvals or conversion, the rational behaviour of a competent team is to decline more. The metric is doing exactly what it was designed to do.
The Four Costs Behind Every Fraud Decision
Every approve, decline or review decision creates cost somewhere. Only one of those costs is routinely measured.
1. Direct fraud losses
Chargebacks, write-offs, unrecovered goods or funds, and associated network liability. This is the best-measured cost in most organizations and the reason fraud functions exist. It is also the only one of the four that appears on a standard fraud report.
2. Legitimate transactions declined
False declines are usually the largest cost in the set and the least visible. The immediate loss is the transaction margin. The larger loss is the customer: a good customer declined at first purchase frequently never returns, and the acquisition spend that brought them is written off with them.
3. Customer friction and abandonment
Step-up authentication, document requests and delayed approvals suppress conversion without ever producing a decline record. These customers abandon before a decision is logged, so they are absent from both the approval rate and the fraud rate. Friction cost has to be measured at the funnel, not in the fraud system.
4. Manual-review and operational expense
Review capacity is a fixed operating cost with variable quality. As queues grow, decision time per case falls and accuracy degrades — meaning higher spend often buys worse outcomes. Review volume should be treated as a budget line with a defined return, not as a safety valve.
Net fraud contribution, in plain language
Take the revenue you approved. Subtract the fraud you absorbed. Subtract the margin on the good customers you declined. Subtract the conversion you lost to friction. Subtract what the review operation cost to run. What remains is the contribution your fraud strategy actually delivered — sometimes called risk-adjusted revenue.
The point is not precision. Several of these figures are estimates and should be stated as such. The point is that a strategy which lowers losses while reducing contribution has failed, and only this view will show it.
Why Approval Rate Cannot Be Viewed in Isolation
The common correction to a loss-only view is to elevate the approval rate. That is an improvement, but a portfolio approval rate is an average, and averages conceal precisely the population that matters.
A stable overall approval rate can hide a sharp decline in approvals for new customers, a specific issuer, a geography or a high-value segment. The aggregate looks healthy while the acquisition funnel and the most profitable cohorts are being quietly suppressed.
Approval rate should always be read with
- — Loss rate on the approved population
- — Review rate and average decision time
- — Approval by customer tenure: new versus returning
- — Approval by value band and by segment margin
- — Abandonment at each friction step
An illustrative example: if a control change raises approvals by one point while loss rate rises by a fraction of a point on the same population, the change may be strongly positive — or negative — depending entirely on the margin of the transactions approved and the cost of the losses absorbed. The figures here are illustrative only; the discipline is to run the calculation with your own numbers before and after every material change.
From Fraud Prevention to Revenue Protection
The shift is one of mandate rather than tooling. A prevention mandate asks how much fraud was stopped. A revenue protection mandate asks how much profitable business was preserved at an acceptable level of risk.
That change has practical consequences. Risk appetite becomes an explicit, executive-approved position rather than an emergent property of the rule set. Thresholds are set by segment economics rather than by a single global score. And control changes are evaluated commercially before deployment, not audited for losses afterwards.
It also changes the conversation with the rest of the business. Growth, payments and finance can engage with a contribution number in a way they never could with a loss number.
Building a Balanced Fraud Performance Scorecard
A scorecard replaces the single metric with a small set of measures that cannot be improved in isolation without exposing the trade-off. Five to seven measures, reviewed on the same cadence, are sufficient.
Two operating rules make the scorecard work. First, no measure moves without its counterweight being reported alongside it. Second, every material control change carries a stated expected effect on contribution, reviewed after the fact against what happened.
Five Questions Executives Should Ask Their Fraud Team
These questions are diagnostic. The quality of the answer matters more than the answer itself.
- 01What did our fraud strategy contribute in net terms last quarter — approved revenue less losses, false declines, friction and review cost?
- 02How many good customers did we decline, how do we estimate that, and what is the confidence in the estimate?
- 03Which of our rules were written more than twelve months ago, and what is the precision of each today?
- 04How does approval rate differ between new and returning customers, and is that gap intentional?
- 05If we accepted a higher fraud rate in a defined segment, what would it be worth — and what would it cost us to find out?
If the fraud rate is the only number the organization can answer confidently, the controls are being managed against a metric rather than against the business. That is a solvable problem, and usually a profitable one to solve.
If it would be useful to examine whether your current controls are protecting revenue or simply reducing a loss figure, we are happy to have that conversation.

