Adarsh Naidu is a chief Architect and Fractional CTO with leadership experience at AWS.
Every fraud team I’ve worked with can tell you its fraud loss rate, usually down to two decimal places. Ask how often it accidentally turns away a legitimate customer, though, and the answer gets slower. There is often a caveat, a qualification, or no clear number at all.
That gap isn’t because teams don’t care. It’s built into how fraud systems work—and it makes false declines one of the most expensive problems in payment operations that few companies actually measure.
Picture a customer at the checkout. They have a valid card and enough money in the account. The payment fails. They try again. It fails again. Maybe they assume something is wrong with their card. Maybe they close the tab and buy the same product somewhere else. They don’t call you. They don’t complain. They simply disappear. You just lost a legitimate customer and you may never know it happened.
That’s a false decline. Why does this keep happening? Part of the answer comes down to how fraud detection systems learn. They improve much like a new employee does: They get better when someone tells them when they made a mistake. That correction has a technical name: a label. It’s a confirmed answer attached to a previous decision that tells the system whether it was right or wrong. Those labels help a fraud model adjust its judgment over time.
The problem is that the system doesn’t get equal feedback from both sides. When you approve a transaction, you eventually get an outcome. A fraud claim may arrive weeks later, or it may never arrive. Either way, there is an answer attached to the transaction. When you decline a transaction, there is usually nothing. The rejected customer doesn’t come back and say, “I’m legitimate. You made a mistake.” They buy somewhere else or give up. The transaction ends without a correction.
No label. No feedback. No chance for the system to learn that it was wrong. Retrain that system repeatedly, and it can genuinely become better at catching fraud. But it’s getting better at the half of the problem it can actually hear about.
On wrongful rejections, it can remain almost completely blind. That’s where things get expensive. Leaders see fraud losses falling and assume the system is improving. Sometimes it is. But part of that improvement can come from the system becoming increasingly conservative in areas where nothing ever tells it that it has gone too far.
The cost doesn’t disappear. It moves somewhere else.
A wrongly rejected customer doesn’t appear in your fraud-loss report. There was no fraud and no money was written off. Instead, that customer shows up as lost revenue, lower repeat purchases, higher churn or additional marketing spend to replace a customer you already had. Those numbers usually sit on different dashboards and belong to different teams. The fraud team gets credit for improving its metric. The business absorbs the cost of the metric nobody was measuring.
I learned this while working as an architect on a payments portfolio. It wasn’t a dashboard that exposed the problem—it was a customer complaint. Our overall approval rate was a healthy 96%. Nothing about that number suggested a major issue. Then we broke the data down by geography. Foreign-issued cards were being declined roughly 40% of the time. Our conservative fraud settings had been quietly pushing away international customers for more than a year. The overall approval number looked fine because the problem was concentrated in one segment. Without that complaint, we might never have found it.
The pressure on fraud teams is only increasing. In April 2026, Visa tightened the threshold in its Acquirer Monitoring Program from 2.2% to 1.5% of transactions across the U.S., Canada, the EU and Asia-Pacific. Merchants crossing the threshold can face per-transaction penalties and mandatory remediation.
The natural reaction to a tighter limit is to reject more aggressively. That’s understandable. It’s also expensive. You’re protecting a number you’re formally being measured on while increasing the risk of damaging a number you may barely measure at all.
So what can businesses do about a blind spot they can’t directly see? Start with a second opinion. Run another fraud model alongside the live system in shadow mode. Let it score the same transactions, record its decisions and keep those decisions out of the actual payment flow. You still won’t know exactly which rejected customers were legitimate. But you’ll see where two independently built systems disagree. If those disagreements cluster around one customer group, geography, card type or device, you have something worth investigating.
Next, stop reporting approval rates as one company-wide number. A 94% approval rate can look healthy. But perhaps it’s 71% for first-time buyers using unfamiliar devices. Maybe customers shipping to work addresses are being rejected far more often than customers shipping home. Averages hide these problems. Break approval and decline rates down by card issuer, geography, device, order type and customer tenure. That’s where the damage starts becoming visible.
Then use the evidence you already have. Did the same card succeed elsewhere minutes later? Did the customer retry and eventually complete the purchase? Did the account have a long, clean history before the rejection? None of these signals proves that a transaction was legitimate. But each gives you more information than silence.
Your fraud system is only as good as the feedback it receives. Today, it hears much more from one side of the decision than the other. The answer isn’t to stop fighting fraud. It’s to measure both sides of the decision. Track false declines. Study where they happen. Compare models. Segment approval rates. Use the indirect signals already sitting in your transaction data.
The most expensive decision your business makes may not be the fraudulent transaction you stopped. It may be the legitimate customer you rejected, who quietly went somewhere else—and never gave you a chance to find out why.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

