SardineCon SF/2026

Learn More
Detection & metrics4 min de leitura

O que é Friction?

SUBSCRIBE

Friction is any added step or check in a flow, like a one-time code, a document upload, or a step-up verification. It lowers risk but costs you real customers, so the operator's job is to spend it only where the risk earns it.

What is friction, in plain English?

Friction is anything you add to a flow that makes the user do more work: entering a one-time code, uploading an ID, answering a knowledge question, waiting for a manual review, or re-authenticating. Each step raises the bar for a fraudster, and each step also asks something of every genuine customer who hits it.

That is the core tension. Friction lowers risk, but it is never free: every extra step drops some share of real customers who abandon, mistype, get frustrated, or simply give up. A checkout that adds a step-up will stop some fraud and also lose some legitimate sales.

In the detection stack friction is the action side of a risk decision. Scores and rules decide how risky a case is; friction is one of the levers you pull in response, alongside approve and decline. The skill is applying it selectively rather than everywhere.

Too little versus too much

Friction is a dial, not a switch, and both extremes cost you. The goal is to spend it where the risk justifies the drop-off.

What changes

Too little friction

Too much friction

Fraud

Leaks through unchecked

Blocked, but so are good users

Good customers

Sail through smoothly

Abandon, complain, leave

Conversion

High, but with hidden losses

Falls, sometimes sharply

Where it goes wrong

Losses show up late as fraud

Lost customers never show up at all

The trade is protection versus completion. The right answer is not a fixed level of friction for everyone but a risk-based one, where low-risk users pass smoothly and scrutiny concentrates on the risky slice.

What it looks like in practice

In practice

A wallet app is worried about account takeover, so it adds a document upload step to every large transfer. Fraud on that flow drops, and the team declares success based on the fraud dashboard alone.

What the fraud dashboard does not show is the completion rate: a meaningful share of genuine users abandoned the transfer at the upload step, some permanently. When the growth team pulls conversion by step, the picture flips. The blanket friction blocked a little fraud and quietly cost far more in lost, legitimate volume than it saved. Moving to a risk-based step-up, applied only to suspicious transfers, recovers most of that volume while keeping the fraud reduction.

Why friction is a cost, not a free win

It is easy to treat friction as pure protection, because the fraud it blocks is visible and the customers it loses are not. Every added step is a cost you are spending, and the bill lands as abandonment and lost conversion that rarely files a complaint. Teams that only look at fraud blocked will always over-apply friction, because they never see the customers who walked away.

That is why friction should be measured by its effect on abandonment and completion, not only by the fraud it stops. Applied through risk-based decisioning, it goes where the risk earns it: near-invisible for the safe majority, heavier for the risky few. Get that balance wrong in either direction and you either leak fraud or bleed good customers to competitors with a smoother flow.

What to watch in the data

  • Completion by step. Measure where users drop out; a friction step with a big abandonment cliff is costing more than its fraud reduction may justify.
  • Blanket application. Friction applied to everyone, regardless of risk, is almost always over-spending; target it with a score.
  • Silent abandonment. Lost good customers do not complain, so a clean support queue is not proof that friction is cheap.
  • Step-up hit rate. If most people who hit a step-up pass it, you are probably challenging too many good users.
  • Fraud-only success metrics. Judging a friction change purely on fraud blocked hides its true cost; always pair it with conversion.

Quick questions

Is all friction bad?

No. The right friction on a genuinely risky case is well spent. The problem is unnecessary friction on safe users, which costs conversion for little fraud reduction. It is about targeting, not elimination.

What is risk-based friction?

It is applying checks in proportion to assessed risk: low-risk users pass with little or none, high-risk ones get step-up or review. It concentrates the cost where it does the most good.

How do I measure the cost of friction?

Watch abandonment and completion rates at each step, not just the fraud blocked. The cost shows up as good customers who fail to finish, which the fraud numbers never reveal.

Is a one-time code friction?

Yes. Any extra step, a one-time code, an ID upload, a security question, a delay for review, adds friction. Some are lighter than others, but all of them lose a share of good users.

Why do competitors with less friction win customers?

Because smoother flows convert better. If your friction is heavier than the risk requires, good customers can defect to a rival with an easier experience, so over-applying it has a real competitive cost.

Go deeper

O que saber junto com Friction