SardineCon SF/2026

Learn More
The Saturday Fraud Strategist

誤検知マスタークラス 第4回:不正対策スタック全体にセーフティネットを構築する

不正検知システムには厄介な点があります。個々の要素はどれももっともらしく見えても、全体としては迷路のような振る舞いをしてしまうことがあるのです。

ひとつルールを直す。いいですね。モデルをチューニングする。素晴らしい。手動審査フローを整理する。とても責任感のある対応です。なのに、どこか別の場所で、別のルールやパートナーからのレスポンス、支払いルーティングの判断、KYCチェック、AIエージェント、デバイスインテリジェンスのシグナル、あるいは3四半期前のどこかで忘れ去られていたロジックが割り込んできて、「絶対にダメだ」と言い出したせいで、まっとうなユーザーが結局ブロックされてしまうのです。

今回の「False Positives Masterclass」では、詐欺オーバーライドロジックについてお話しします。これは、成熟した不正対策チームが、複雑な不正対策スタック全体で誤検知を減らす際に使える、より強力なツールのひとつです。考え方自体はシンプルで、理論としてはこうです。スタックのどこかの要素がユーザーをブロックしようとしても、「このユーザーは十分に信頼できる」と強く判断できる場合には、それを認識して守れるよう、システム全体の上位レイヤーにセーフティネットを構築する、というものです。

しかし、理論上は単純だからこそ、多くの悪い不正対策のアイデアが生まれてしまいます。だからこそ、慎重である必要があります。

不正検知システムのオーバーライドは近道ではありません。「なんとなく良さそう」という雰囲気で承認するためのレイヤーでもなく、その下にあるおかしなロジックを無視するための言い訳でもありません。これは、ユーザーをブロックする前に「この人が本当に正当なユーザーであるという、揺るぎない証拠があるか?」と問いかける、管理されたエビデンスベースの仕組みなのです。

それは一見当たり前のことのように聞こえますが、実際にはそうではありません。もし本当に当たり前のことなら、もっと多くのチームがうまくやれているはずです。

このエピソードでお届けする内容:

  • なぜ十分に調整された不正防止ロジックでも、誤検知が発生してしまうのか
  • 不正防止のオーバーライドロジックが、ルール、モデル、AIエージェント、手動審査、KYCチェック、パートナーからの回答の上にかぶさるセーフティネットとしてどのように機能するか
  • 一部の不正検知ルールは決して自動で上書きすべきでない理由
  • 既知の優良ユーザーと継承された信頼シグナルが、誤検知を減らすのにどのように役立つか
  • なぜ高い露出度の環境が有用な誤検知の指標になり得るのか
  • ジオチェイニングは、旅行者や正当な不一致と不正行為をどのように見分けるのか
  • なぜ再販売できない商品やリスクの低い商品が、より安全な不正決済の承認に役立つのか
  • シャドウモードでのテストと段階的なロールアウトを用いて、不正防止オーバーライドシステムを安全に導入する方法

このエピソードは次のような方におすすめです:

  • 不正対策業務に携わっており、自社のスタックに独立したボトルネックが多すぎると感じている方
  • 不正検知ルールを弱めることなく、誤検知を減らそうとしている
  • アカウント、デバイス、カード、各種フローをまたいで信頼できるユーザーを特定する、より安全な方法が必要です
  • 一般的な許可リストを超えた、不正検知のオーバーライドロジックの具体的な実例が欲しい
  • デバイスインテリジェンス、ジオチェイニング、手動審査、あるいはチャレンジャールールを、意思決定の精度向上のためにいつ活用すべきかを検討している
エピソードの概要と主なポイント

不正防止のオーバーライドロジックは、スタック全体を覆うセーフティネットです

このエピソードの主なポイントは、誤検知(フォルスポジティブ)を減らす取り組みは、個々の不正検知ルールをチューニングしたところで終わりではない、ということです。それ自体はもちろん有効ですが、たとえすべてのルール、モデル、AIエージェント、パートナーからのレスポンス、手動審査キュー、ペイメントルーティングの判断、KYCチェック、デバイスインテリジェンスのシグナルがそれぞれ単体では妥当であっても、システム全体としては依然として望ましくない結果を生み出しうるのです。

それは、ユーザーがあなたの管理を一つずつ体験するのではなく、全体という迷路として体験しているからです。

ユーザーは、あるルールは通過できても、その後モデルによってブロックされるかもしれません。モデルを通過しても、パートナーからのレスポンスによって保留にされることもあります。KYC を通過しても、今度は支払いルーティングの判断で引っかかるかもしれません。どこかの段階で、システムの一部が「いいえ」と判断してしまうのです。たとえ全体的な証拠から見れば、そのユーザーはおそらく良いユーザーだとしてもです。

そこで登場するのが、不正オーバーライドロジックです。これはスタックの上位に位置し、却下やブロックを取り消すのに十分な根拠があるかどうかを判断します。不正対策のセーフティネットルールの「鏡像」と考えてください。すり抜けた不正を捕まえる代わりに、誤って止められてしまった優良ユーザーを救い出す役割を果たします。

たしかに危険そうに聞こえます。実際に危険になり得ます。だからこそ、設計が重要なのです。

すべての不正に関する判断が覆されるべきとは限りません

最初の設計上の問いはシンプルです。決して上書きしてはならないものは何でしょうか?

ここではチームに規律が求められます。不正対策スタックにあるあらゆるソリューションが、同じ扱いに値するわけではありません。弱いシグナルもあれば、方向性を示すだけのシグナルもあり、文脈の中でのみ意味を持つものもあります。一方で、安易に上書きしてしまうと問題になりかねないほど強力なシグナルも存在します。

たとえば、盗難カードのブラックリストで「このカードは不正利用されている」と判定された場合、端末の位置情報が良さそうに見えるという理由だけで、その判断を覆したいとはおそらく思わないはずです。デバイスインテリジェンスのベンダーが間違っている可能性もありますし、ネットワークがクリーンに見えることもあります。行動パターンが一見正常に見えることさえあるでしょう。しかし、決済手段そのものがすでに不正利用されていると分かっているのであれば、それはまったく別種のシグナルなのです。

これを必要以上に複雑にする必要はありません。すべての不正検知ルールに対応する誤検知ルールを用意する必要もありません。デフォルトでは上書きすべきでないほど強力なソリューションやロジックのグループだけをマークしておけばよいのです。

そのひと手間を加えるだけで、将来の多くのトラブルを防げます。というのも、もしオーバーライド層があらゆるものをひっくり返せるようになっていると、いずれ本来触るべきではないものまで書き換えてしまうからです。

そして、みんなで楽しい会議を開くことになります。楽しいと言っても、全然楽しくないという意味ですが。

優良ユーザー向けのヒューリスティックは、通常の不正対策ルールよりも強力である必要があります

2つ目の設計上の論点は、ブロックされた集団の中から誤検知を特定できるほど十分に強力なヒューリスティックはどれか、という点です。

この点が重要なのは、あなたが検索している対象の母集団が、すでに高リスクだからです。ここにいるのは、通常のトラフィックに含まれるランダムなユーザーではありません。あなたのシステムがすでにブロックすると判断したユーザーたちです。したがって、たとえ上書きルールが元の却下ロジックより高い精度であったとしても、このセグメントにおける不正発生率は依然として通常より高いままなのです。

つまり、優良ユーザーを示すシグナルは、特に強力である必要があります。通常の不正対策ルールよりも、さらに抜け目なく厳密でなければなりません。

あなたが問うべきことは「このユーザーはなんとなく問題なさそうか?」ではありません。それでは不十分です。あなたが問うべきなのは、「不正検知のどこかがこのユーザーを止めようとしたにもかかわらず、このユーザーが正当な利用者だと強く裏付ける証拠があるか?」ということです。

それはより高いハードルです。そうあるべきです。

このエピソードでは、内容を次の4つの有用なロジックの系統に分解しています:優良ユーザー、高リスクな利用環境、地理的な連鎖、そして転売不可またはリスクの低い商品です。どれも鵜呑みにしてそのまま真似すべきではありませんが、それぞれが不正対策チームにとって、実務的な出発点を与えてくれます。

信頼できる既存ユーザーは、新しいアカウントやイベントにもその信頼を引き継ぐことができます

最もシンプルなオーバーライドの対象は、信頼できる既知のユーザーです。長期間にわたり健全な行動履歴を持つアカウントや、高負荷な本人確認を通過したユーザーなど、強い信頼の根拠がある人たちです。

さて、ええ、わかっています。とても基本的な話に聞こえますよね。「良いユーザーは良いユーザーだ。」素晴らしい洞察です。スライドにでも載せておきましょうか。

しかし、興味深い点は、古くから信頼されているアカウントそのものではありません。本当に重要なのは、そうしたユーザーが新しいアカウントや新しい国、新しいフロー、あるいは単発の取引に現れたときに何が起こるかということです。

「新規」ユーザーが、実は本当の新規ではない場合があります。まだシステム上で紐づいていない、再訪ユーザーである可能性があるのです。新しいイベントを、過去の信頼できるイベントと関連付けることができれば、不必要な摩擦を安全に減らせるかもしれません。

このエピソードで挙げられている例は、個人的な体験に基づくものです。複数の国に住んだことがあるために、複数のPayPalアカウントを持っているという状況です。ユーザー体験としては理想的とは言えませんが、コンプライアンス上の要件としては理解できます。重要なのは、プラットフォーム側がデバイスや氏名、過去のアカウント履歴といったシグナルを使って、新しいアカウントを既存のアカウントと紐づけられることです。

それが本当の教訓です。信頼は集めるだけでなく、推し量ることもできるのです。

以前に正当性が確認されたアカウントと同じデバイスと名前を使って作成された新規アカウントは、その一例です。ほかにも、カード情報とIPアドレスの組み合わせ、メールアドレスと同じ商品を購入した履歴の組み合わせ、あるいは名字と完全に一致する位置情報といった、家族関係を示すようなシグナルの組み合わせなどが考えられます。

重要なのは、無作為なつながりを見つけることではありません。無作為なつながりこそが、誤ったロジックに自信を持ってしまう原因になります。重要なのは、新しいイベントを、確実で信頼できる実績のあるイベントと結びつけることです。

高い注目を集める環境では、不正行為が起こりにくくなることがあります

2つ目のグループは、高い露出度の環境です。

詐欺行為を行う者は、通常、自分の本当の身元や勤務先、所属機関、所属組織が明らかになる可能性のある環境を避けます。一方で正当なユーザーは、そのような場所から自然に取引を行うことがよくあります。

それによって、有用な誤検知シグナルが生まれます。

ユーザーが高度に管理されている、あるいは追跡可能なネットワーク環境から取引を行っている場合、不正行為をしている可能性は低くなることがあります。例としては、企業ネットワーク、政府機関のネットワーク、軍事用IPレンジ、大学のIPネットワーク、または大規模な非営利団体のネットワークなどが挙げられます。

だからといって、企業ネットワーク上にいるすべての人が自動的に正当な利用者だという意味ではありません。そんなことは明らかにありません。勘違いしすぎないようにしましょう。

しかし、雇用主や学校、その他の組織に紐づいた監視下の環境から不正行為を行うことは、別の意味でリスクが高い行為です。多くの詐欺師は、抽象的な意味での刑事訴追そのものをそれほど恐れてはいません。しかし、自分の勤め先や大学、所属組織から処分を受けるとなると話は別です。それは、より直接的で即効性のある抑止力になり得ます。

同じ考え方は、管理された配送先にも当てはまります。たとえば軍事基地に送られる荷物は、転送業者にとって都合のよい一般住宅宛ての荷物とは、異なるリスクプロファイルを持つ可能性があります。

繰り返しになりますが、これはあくまで状況次第の話であって、魔法ではありません。ただし適切に精査されていれば、露出度の高い環境は、不正対策のオーバーライドシステムがブロック対象となっている集団の中から正当なユーザーを見分けるのに役立ちます。

ジオチェイニングは、位置情報に基づく誤検知を減らすことができます

地理的な不一致ルールは、不正検知における典型的な誤検知(偽陽性)の原因です。ロジックは誰もが知っています:カードの国がIPアドレスの国と一致しない、請求先の国が配送先の国と一致しない、アカウントの国がログイン元の国と一致しない。こうしたルールが不正を検知することもありますが、一方で、ごく普通の人間の行動をブロックしてしまうこともあります。人は旅行や通勤をし、VPNを使い、きれいに整ったデータベースの行に収まるような行動ばかりはしてくれないからです。

とても配慮に欠けています。

ジオチェイニングとは、地理データをより賢く活用するための手法です。すべての不一致を不審なものとみなすのではなく、その不一致が正当なものである理由を説明できる、地理的な文脈パターンを探し出すアプローチです。

最初のタイプは、特定の場所における地理的な近接性です。IPアドレスがニューヨーク市の請求先住所のすぐ近くに解決されたとしても、それ自体はあまり意味を持たないかもしれません。詐欺者は大都市の近くにあるオープンプロキシを簡単に見つけられるからです。しかし、請求先住所が小さな町や地方エリアにあり、そのIPがその周辺のごく狭い範囲内に解決される場合、それは正当なユーザーであることを示す、より強いシグナルになり得ます。一般的な大都市近郊の近接性よりも、人目につきにくい地域での地理的近接性を偽装する方がはるかに難しいのです。

2つ目のタイプは、国籍と一貫した不一致です。エピソードでは別の個人的な例として、イスラエルでスペインのカードを使ったところ、スペインのBINとイスラエルのIPアドレスの不一致が原因でブロックされたケースが挙げられています。しかし、名前がイスラエル人らしく、IPもイスラエルのものであれば、その文脈は重要になります。スペインのカードを持つ不正利用者であれば、おそらくスペインのIPを使うはずです。スペインのカード、イスラエル風の名前、イスラエルのIPというパターンを、わざわざ複雑に作り込む明確な理由はありません。

それがジオチェイニングの価値です。正当な行動を説明できる、微妙で文脈的な相関関係を見つけ出します。慎重に使えば、不必要な不正リスクを招くことなく、位置情報に基づく誤検知を覆すことができます。

再販売できない商品は、より安全な支払い不正承認を後押しします

第4のカテゴリーは主に決済詐欺に当てはまり、再販売できない商品やリスクの低い商品が該当します。

詐欺師は、たいてい自分が欲しいから商品を盗むわけではありません。転売できるから盗むのです。これが経済モデルです。もしその商品に転売市場がまったくない、あるいはごく弱い場合には、不正リスクを理由に取引を拒否することが、かえって逆効果になることもあります。

例としては、教育関連の商品やサービス、ニッチまたは高度にパーソナライズされた商品、オーダーメイドの家族向けギフト、セラピーセッション、パーソナルトレーニング、その他、個人的な消費を前提とするサービスなどが挙げられます。

これは、私たちが電子機器や自動車部品、ギフトカードをリスクが高いと考える理由を、裏返したような話です。そういった商品は転売が簡単にできます。家族向けにカスタマイズされた、誰かの犬の写真入りマグカップなんてどうでしょう?組織的な詐欺グループにとっては、あまり魅力的ではありません。たぶんですけど。

よく設計された不正オーバーライドシステムでは、転売価値の低さを承認ロジックの一部として組み込むことができます。すべてを承認するための単独の理由ではなく、不正者が好まない取引をシステムが見分けるのを助ける補助的なシグナルとして活用するのです。

その違いは重要です。リスクの低い商品のロジックは、あくまでオーバーライドを支援する役割であり、それだけで全体を支えるべきではありません。

安全なデプロイはロジックと同じくらい重要です

エピソードの最後のセクションはデプロイについてです。なぜなら、ここが良いアイデアが悪いインシデントに変わりうる場面だからです。

初日から全トラフィックの100%に対して不正上書きロジックを有効化してはいけません。まずテストします。慎重に。

より安全なロールアウトは、まずシャドーモードでのテストから始めます。意思決定に影響を与えないようにしたまま、オーバーライドロジックを実行します。想定していた対象にきちんと当たっているかを計測します。個々のケースを確認し、その結果を自分たちの分析と比較します。

その後、チャレンジャールールを導入して、却下の一部だけを上書きし、残りはシャドーモードのままにしておくことができます。トランスクリプトでは例として20%を挙げていますが、具体的な割合は、あなたのリスク許容度やビジネスの状況によって異なります。

その後、30〜60日ほど、あるいは不正が通過させた母集団の中でどのように成熟していくかを把握できるだけ十分な期間、結果を観察します。結果が良好であれば、段階的に拡大します。はっきりしない場合は様子を見ます。不正が急増した場合は、シャドーモードを再び100%に戻し、ロジックを見直してください。

この慎重な段階的拡大によって、決して上書きすべきでない不正検知ソリューションがどれかも明らかになります。もし、上書き設定をすり抜ける不正の大半がごく一部のルールやモデルから生じているのであれば、それらのソリューションは「上書き禁止」の階層に分類すべきかもしれません。

そして、自分が設けた除外条件に対してさらに除外条件を作らなければならない段階にまで来たのなら、おめでとうございます。あなたは周囲をリードしているか、相当疲れているか、その両方でしょう。

最終的なポイント:

不正検知のオーバーライドロジックが強力なのは、重要な点を理解しているからです。誤検知は、必ずしも一つの悪いルールだけが原因とは限りません。ときには、妥当な要素が多すぎるあまり、それらが不合理な形で相互作用してしまうシステムそのものが原因になることもあります。

高度なオーバーライドレイヤーは、成熟した不正対策チームが、すでに強い信頼の根拠を持っているユーザーを承認するのに役立ちます。ただし、それはロジックが精緻であり、シグナルが完全で、ロールアウトが適切に管理されている場合に限られます。

信頼できる既存ユーザーや高露出環境、ジオチェイニング、低リスクなアイテムなどは、すべて誤検知を減らすのに役立ちます。シャドーモードでのテストと段階的な導入によって、誤検知の問題を解決しようとして新たな不正リスクを生まないようにすることができます。

とにかく、それがバランスというものです。安全網はしっかり張りつつも、重力がなくなったふりはしてはいけません。

慎重になりすぎているでしょうか? たぶんそうです。

しかし不正検知システムでは、たいていの場合、賢さよりも慎重さのほうが長い目で見て通用します。

つながる:Chen Zamir | LinkedIn

「The Saturday Fraud Strategist」のホスト

フィンテック企業がより賢い不正防止対策を構築できるよう支援します

『The Fraud Fighter’s AI Playbook』の共著者

私の、そしてできればあなたの一番好きなテーマについての会話を、まだ終わらせたくありませんか? ぜひ購読してください:The Saturday Fraud Strategistニュースレター。

Episode transcript
Chen Zamir
Chen Zamir
00:07
In the previous part of this masterclass, we talked about how to tune your solutions so they create less false positives. This sounds great in theory, and it's often the case that it would work great in reality as well. But even if you do all of that perfectly, you still face one more problem. Your fraud system is a maze. You have rules, models, AI agents, manual review queues, partner responses, payment routing decisions, KYC checks, device intelligence, and dozens of other components That are each capable of blocking a user. Even if each component is reasonable on its own, their interactions can still produce false positives in places you never intended. A user might bypass one part of the system only to be caught by another. This is why mature fraud teams eventually introduce a different mechanism altogether, a high-level override layer that sits on top of the entire stack to help the system speed through users you already have reason to trust. Think of it as the mirror image of your fraud safety net rules. When any actor in the system, be it a rule, a model, an agent, or even a human, tries to block a user, this safety net checks whether there is strong evidence that the user is actually a good one. And if so, it reverses the decision. This idea is extremely powerful when implemented correctly, but it requires thoughtful design. So let's walk through how it works.
Chen Zamir
Chen Zamir
01:55
There are two questions you must answer before designing any override logic. The first one touches on the parts of your system that shouldn't be overridden, and definitely not by default. Why? Well, frankly speaking, not all solutions should be treated equally. If a stolen card blacklist says a card is compromised, you shouldn't automatically override the decision just because the device location looks good. After all, the data intelligence vendor can be wrong. That doesn't mean it has to be complex, and there is no need to pair fraud logics with false positive logics. Just mark the solutions in your system that are particularly strong and should never be overridden. The second thing you want to consider, obviously, is which heuristics are strong enough in detecting false positives. Keep in mind, you are searching for good users in a population that is inherently high risk. You already chose to block them. So even if this can be more accurate, the fraud rate in this segment is much higher than your baseline. So your false positive heuristics need to be especially airtight, much more than a normal fraud rule. The question then is, where do you start? I'd like to suggest four key heuristics, or logic families, that usually prove to be effective at sifting through high fraud rate populations and finding false positives in them. Which of them you implement, and how exactly, depends on your specific business context.
Chen Zamir
Chen Zamir
04:01
Let's start with the simplest and most intuitive category: users you already know and trust. These signals might include long-standing accounts with clean behavioral history, or users who passed high friction verification. And I'm not talking about your generic KYC, but something more meaningful. Now, I know what you must be thinking. Hold up, this is the most trivial piece of information ever. Surely I didn't waste my time watching this for this. But here's the catch: while flagging established accounts is straightforward, the logic changes entirely when you need to assess new accounts or one-time users. In many cases, these new users can be returning users. And if we manage to associate them with their past activity, we might exclude them from high friction risk mechanisms. For example, I myself have three PayPal accounts, as I've lived in three different countries, and PayPal requires users to open an account in each new country they move to. This is not the ideal user journey, but I understand the compliance requirements they need to uphold. At the same time, I also know that whenever I open a new account, They immediately link it to my previous ones. How?
Chen Zamir
Chen Zamir
06:30
Simply because I'm using the same device to open a new account with the same name as an account I already own. That's me. The key insight is that trust can be inferred, not just collected. You don't have to wait for someone to build a long history on one account if they are the same user behind multiple accounts, and you verify the legitimacy of any one of them, the new one inherits that trust. Now, using the same device and name to open a new account is not exactly a groundbreaking heuristic, even though not all teams have even that in place. But you can easily find similar logics that don't rely on the same device and are still as strong. Here are some examples: card plus IP address, email plus the same, item bought. And you can also infer across family members, for example, with last name plus exact geolocation. Just remember, it's not about finding random links. It's about linking a new event to an airtight, proven good event.
Chen Zamir
Chen Zamir
08:31
Fraudsters avoid environments where their real identity or real affiliations could be exposed. Legitimate users, on the other hand, often operate from those environments naturally. This leads to a surprisingly powerful heuristic. If a user transacts from a highly controlled or highly traceable network environment, the likelihood they are a fraudster drops dramatically. What could be examples of that? One example can be corporate, government, or military IP networks with strict access controls, where the user is likely an employee. University IP networks, where the user is either on staff or a student, are also a good example. And some large nonprofit organizations, think about like the UN, Where the user is likely an employee as well, can also be considered. Committing fraud from such a network is highly unlikely, as they are monitored for security breaches and can lead back to the individual user. Similarly, sending packages to a highly controlled shipping address, let's say a military base, for example, is another indicator the user is highly unlikely to be a fraudster. Now, keep in mind, it's not necessarily about identifying and prosecuting the fraudster. Most of them don't fear that. But it is about the fear of being sanctioned by their own employer that would deter them from utilizing these assets to commit fraud.
Chen Zamir
Chen Zamir
11:16
When we think about geographic data, we often think about rudimentary fraud detection logics that look for geo mismatches. And as rudimentary logics, we also know they are many times the main culprit when it comes to causing false positives. We just talked about it in the previous part, where I gave the US-Canada example. But we can also use geographic data to identify false positives quite accurately using a technique called geo chaining. Specifically, I'd like to point out two types of geo chains. The first one deals with geographic proximity in specific locations. Here's what I mean. If an IP address resolves to a location extremely close to the legitimate billing address, that on its own is not necessarily a redeeming indicator. For example, if the address is located in New York City, finding an open proxy IP that is less than 10 miles away from the billing address you stole is probably not so hard. But what if the address is in a small town or a rural area? When you get a strong match to the IP location, let's say less than 10 miles, this can be a stronger good user indicator than most people realize. Fraudsters can spoof large cities easily, but it is not that easy to do that with obscure villages in the countryside. The second thing you want to look for is nationality-consistent mismatch. And again, let me share an example from my own personal experience. When I use my Spanish card in Israel, I often get blocked. Why? Because of the Spanish BIN, Israeli IP mismatch. But it shouldn't be the case. Analyzing my name should mark it as Israeli. The technology exists, trust me. And matching it to the Israeli IP should be easy. That's not to say that when a name shares the same nationality as the IP address, it means it's a good event. But when we see a very specific pattern where the card mismatches the IP, but the name matches the IP, we find a correlation that is too obscure for a fraudster to mimic. Think about it. When a fraudster sees a Spanish card, they simply go for a Spanish IP. There's no reason for them to overengineer it. This is subtle and contextual, but when the logic is vetted properly, it can overturn a surprising number of geo-based false positives while introducing minimal additional fraud risk. As a side note, by using this heuristic, we basically identify travelers. And you can probably think of other ways to identify travelers. For example, identifying hotel or airport Wi-Fi IPs. Are travelers by definition good users? Not always, but it helps explain that rudimentary geo mismatch logic we mentioned earlier.
Chen Zamir
Chen Zamir
15:03
The final heuristic applies mainly to payment fraud. Usually fraudsters don't steal goods so they can use them themselves. They steal it so they can later resell it and pocket their earnings. This means that their economic model depends on transferring the stolen goods, whether digital or physical, to someone else. If the item being purchased has no resale market, or only a very weak one, then declining it for fraud risk is often counterproductive. Here are some examples. Educational goods and services, niche and hyper-personalized items, like think about customized family gifts, or services that require personal consumption, like a therapy session or a personal training session. If you think about it, we're basically reversing the heuristic that makes high-value products riskier. Why do we perceive electronics, auto parts, or gift cards as high risk? Because it's very easy to resell them. So in a well-designed override system, low resale value can help your system approve things fraudsters don't even want in the first place.
Chen Zamir
Chen Zamir
16:50
Let's make it simple. You do not turn on override logic for 100% of your traffic on day one. You test it robustly. A typical rollout might look like this. First, deploy the override rule in shadow mode only. Second, you measure the hits and compare them to your analysis. Is it hitting according to your expectations? Third, you lower the shadow mode rule to 80% of the population, and introduce a challenger rule that actually overrides declines for the rest of the 20%. These numbers are, of course, placeholders, so you can decide what's the level of risk you want to take here. Fourth, you watch the results over, say, 30 to 60 days, and this should show you how fast fraud matures in the undeclined population. If it looks good, you can ramp up to, let's say, 50%, and repeat the process. If it's not really clear yet, you want to wait another 30 days. And if fraud spikes, you go back to 100% shadow mode and to the drawing board in general. You go through several iterations, again, based on your risk appetite, and gradually increase it until you reach full deployment. One thing that you might find out throughout this cautious ramp up is that the fraud you do see penetrating these rules can come from a handful of fraud detection solutions. This is pretty common, and in that case, you should move these fraud solutions to that tier we mentioned that doesn't get overridden. And if you've gotten to this point, essentially developing exclusion logics to exclusion logics, you know you're leading the pack.