The Optimal Fraud Rate Is Not Zero

The Optimal Fraud Rate Is Not Zero | HL Hunt
Payments & AI

The Optimal Fraud Rate Is Not Zero

A merchant tightens their rules, watches the fraud rate fall from 0.6% to 0.2%, and reports it as a win. Nobody asks what it cost. No screening rule separates fraud from legitimate business perfectly, so every point of fraud prevented is bought with declined good customers — and past a threshold, the revenue lost exceeds the fraud avoided. The reason almost every business sits past that threshold is a measurement asymmetry: fraud losses arrive as itemized chargebacks with someone accountable for them, while customers you wrongly declined generate no record at all. One cost is visible and attributed; the other is invisible by construction. Managers respond rationally to what they can see, and the rules get tighter than the economics support.

By the HL Hunt Research Desk · 16 min read · Updated August 2026

The tradeoff nobody prices

Every screening rule sorts transactions into approve and decline, and every rule makes two kinds of error:

ApproveDecline
LegitimateCorrect — margin earnedFalse decline — margin and customer lost
FraudulentFraud loss — chargeback and goodsCorrect — loss avoided

Tightening a rule moves transactions from the left column to the right. It catches more fraud and declines more legitimate customers, always, in some ratio.

The economics turn on how that ratio changes as you tighten. The first rules you apply are efficient — obvious fraud signals catch many fraudsters and few legitimate customers. Each additional tightening is less efficient, because you're now working in the region where fraudulent and legitimate transactions look increasingly similar.

Which means the marginal fraud caught per additional decline falls steadily while the cost per false decline stays roughly constant. Somewhere those cross, and past that point every tightening destroys value. The fraud rate keeps improving all the way — it improves right up to the point where you've declined everyone — which is precisely why the fraud rate is useless as an objective.

Why the bias runs one way

If the tradeoff were symmetric in visibility, businesses would land near the optimum by ordinary management attention. It isn't.

Fraud lossFalse decline
Appears asAn itemized chargebackNothing
Has a date and amountYesNo record exists
Someone accountableYesNo
Reported to managementMonthlyNever
Triggers a responseImmediatelyNever

A manager whose fraud losses rise gets asked about it. A manager whose false declines rise gets asked about nothing, because an order that didn't happen leaves no trace in any system. The career risk is entirely one-sided, and the rational individual response is to tighten.

This is the same structure as the forbearance asymmetry in our workout analysis and the censoring in our reject inference analysisan institution that measures one side of a decision and not the other will drift toward the measured side regardless of the economics. The pattern recurs because the underlying situation recurs: whenever a decision forecloses its own counterfactual, the foreclosed outcome becomes unmeasurable and therefore free.

Two aggravating features specific to payments:

  • Chargeback thresholds are enforced. Exceeding a network monitoring threshold carries fees and program consequences, per our chargeback guide. That's a genuine hard constraint and it's frequently used to justify screening well beyond where the constraint binds.
  • Fraud tools are sold on detection rates, not on contribution. A vendor demonstrating higher catch rates is demonstrating the metric that's easy to show, and the false decline consequence isn't on the slide.
One cost is itemized. The other doesn't exist.
A chargeback has a date, an amount, and someone answering for it. A customer you wrongly declined produces no record anywhere — which is why nearly every business screens too hard.

Costing both sides

Cost of an approved fraudulent transaction:

  • The chargeback amount — full order value, not margin
  • The chargeback fee
  • Cost of goods shipped and not recovered
  • Handling and representment time
  • A contribution to threshold risk

On a $180 order with 40% margin: $180 + $22 fee + $108 goods cost + handling ≈ $320. Note it exceeds the order value substantially, which is why fraud feels expensive — you lose the goods and refund the money.

Cost of a false decline:

  • Lost margin on the order: $180 × 40% = $72
  • Lost future value from a customer who doesn't return
  • Support cost where they complain
  • Reputational effect, which is real and hard to size

The second line is where most of it sits and where most businesses stop counting. If a customer would have generated four more orders over three years, the lost lifetime margin is roughly $288, bringing the false decline cost to around $360higher than the fraud cost.

Not every declined customer is lost — some retry, some use another card. But a meaningful share don't, and the ones most likely to abandon are those with alternatives, which is to say your better customers. The false decline population is adversely selected against you.

Finding the optimum

Work a real decision. A merchant with 100,000 annual transactions at $180 average, 40% margin, currently 0.6% fraud. Fraud cost $320; false decline cost $360.

Rule settingFraud rateFraud costFalse declinesFD costTotal
Loose1.2%$384,000200$72,000$456,000
Current0.6%$192,000700$252,000$444,000
Tighter0.4%$128,0001,400$504,000$632,000
Tightest0.2%$64,0003,200$1,152,000$1,216,000

Read the last column. Moving from 0.6% to 0.2% fraud cut fraud cost by $128,000 and raised total cost by $772,000. The fraud team would report a two-thirds reduction in fraud as a major success, and it would be a serious loss.

Note also that the optimum here sits between the loose and current rows — meaning this merchant is already slightly over-screening at 0.6%, and the intuition that 0.6% seems high would push exactly the wrong way.

The general rule:

Tighten only while: Fraud prevented × Fraud cost > Additional false declines × False decline cost

The ratio that decides it

Simplify to one number. Rearranging the rule above, a tightening pays only when:

Good customers declined per fraud caught < Fraud cost ÷ False decline cost

With our figures: $320 ÷ $360 = 0.89. So a tightening only pays if it declines fewer than 0.89 legitimate customers for each fraudster it catches — a demanding bar, and one that efficient early rules clear easily while marginal later rules almost never do.

What moves the threshold:

  • Higher margin raises false decline cost and lowers the acceptable ratio — high-margin businesses should screen more loosely, which is the opposite of common practice.
  • Strong repeat purchase raises lifetime value and pushes the same way.
  • Digital goods lower fraud cost — no physical goods lost — so they can afford more fraud than physical goods merchants.
  • High-value items raise fraud cost and justify tighter screening.
  • Proximity to a chargeback threshold raises the effective fraud cost sharply, which is the legitimate case for tightening beyond the pure arithmetic.

The finding worth carrying: a high-margin business with repeat customers should tolerate a visibly higher fraud rate than a low-margin one, and the fraud rate benchmarks circulated as best practice ignore this entirely. Comparing your rate to an industry figure compares you to businesses with different economics.

Testing rules properly

The critical methodological point: you cannot evaluate a fraud rule by watching the fraud rate. The fraud rate improves with every tightening by construction, including tightenings that destroy value. It is not a performance measure.

What works:

  1. Approve a random sample of transactions the rule would decline. The only way to learn what's in the declined population, since declined transactions otherwise generate no outcome. If most turn out legitimate, the rule is destroying value — and the expected fraud loss on the sample is the price of finding out.
  2. Run rule changes as holdout tests, comparing total contribution per visitor rather than fraud rate.
  3. Measure approval rate alongside fraud rate, always, so the tradeoff is visible on the same page.
  4. Track declined customers' subsequent behaviour — retry, alternative payment, or never return. This converts the invisible cost into a number.
  5. Report total contribution as the objective.

The first is the same holdout logic as reject inference, and it's cheaper here — the exposure is one transaction rather than a multi-year loan, and outcomes arrive in weeks rather than years. There is no good reason not to run it, and almost nobody does.

Why one threshold is wrong

A single rule set applied to all traffic is wrong for nearly every transaction, for the same reason uniform collections treatment is wrong in our recovery frontier analysis: the optimal threshold depends on the economics of the individual transaction.

Where thresholds should differ:

  • By order value. A $40 order and a $2,000 order have completely different fraud costs and warrant different scrutiny.
  • By customer history. An established customer's transaction has lower fraud probability and far higher false decline cost — declining a loyal customer is the most expensive false decline available and is exactly what velocity rules do when someone shops unusually.
  • By product. Physical, digital, and service goods have different recovery profiles.
  • By channel.
  • By whether a step-up exists. Where additional authentication is available — per our authentication guide — the choice isn't binary. A challenge converts a decline into a friction cost, which is far cheaper, and the availability of a middle option changes the optimum substantially.

That last point is the most useful operational conclusion. The binary framing of approve-or-decline overstates the tradeoff. A merchant with a step-up path can screen aggressively on suspicion without paying the full false decline cost, because suspicious-but-legitimate customers can prove themselves. Adding a step-up path is frequently worth more than any amount of rule tuning.

Where the model stops

Four honest limits:

Chargeback thresholds are a hard constraint, not a cost. Entering a monitoring program carries fees, remediation requirements, and in severe cases account termination — which is not a marginal cost to be traded off. Contribution optimization operates below the threshold, not through it, and a merchant approaching one should tighten regardless of the arithmetic.

Fraud is adversarial and adaptive. Loosening rules invites testing, and fraud volume responds to the rules rather than sitting fixed. This is a genuine dynamic the static model misses, and it argues for tightening somewhat beyond the static optimum as a deterrent.

Some fraud has consequences beyond the loss — account takeover, identity theft, or activity that harms the cardholder. Those warrant screening beyond what merchant economics justify, and the merchant's contribution calculation isn't the only interest at stake.

Lifetime value estimates are soft. The false decline cost depends heavily on an estimated repeat rate, and businesses tend to be optimistic about it. Use a conservative figure — even a conservative one usually shows over-screening, and an aggressive one invites dismissal of the whole analysis.

See both sides of the decision

HL Hunt Pay reports approval rate, decline reasons, and fraud outcomes together — with step-up authentication available as a middle path — so the cost of declining good customers is a number on the same page as the fraud rate rather than an absence nobody notices.

Get Started with HL Hunt Pay

Frequently asked questions

Why isn't a zero fraud rate the goal?

No rule separates fraud from legitimate business perfectly, so each additional point of prevention costs more declined customers. A business with no fraud is turning away substantial profitable business to achieve it.

How much does a false decline actually cost?

Lost margin on the order plus lifetime value of a customer who may not return — and for repeat-purchase businesses the second dominates. In our example it exceeded the fraud cost.

Why do most businesses screen too aggressively?

Fraud arrives as itemized chargebacks with someone accountable; wrongly declined customers produce no record at all. Managers respond to what they can see.

How do you test whether your fraud rules are too tight?

Approve a random sample of transactions the rules would decline and see what share are fraudulent. It's the only way to learn what's in the declined population, and outcomes arrive in weeks.

Key takeaways

  • Every tightening catches more fraud and declines more good customers; past a threshold the second exceeds the first.
  • In the worked example, cutting fraud from 0.6% to 0.2% saved $128,000 and cost $772,000 — reported as a success.
  • A tightening pays only if it declines fewer than (fraud cost ÷ false decline cost) good customers per fraudster caught.
  • High-margin businesses with repeat customers should tolerate visibly higher fraud rates, which inverts common benchmarking.
  • The fraud rate improves with every tightening including value-destroying ones, so it cannot be the objective — measure total contribution.
  • A step-up authentication path converts declines into friction and changes the optimum more than rule tuning does.

Optimize contribution, not the fraud rate

Sign up for HL Hunt Pay for acceptance across rails with fraud, approval, and decline analytics in one place — so rule changes can be evaluated on what they earn rather than on the one metric that always improves.

Sign Up for HL Hunt Pay


This guide is educational and does not constitute financial advice. Worked figures are stylized illustrations; fraud rates, margins, chargeback costs, and customer lifetime values vary substantially by business. Card network chargeback monitoring thresholds are contractual requirements that operate independently of contribution optimization.