Model-based fraud scoring assesses risk on card-not-present orders, giving a merchant a clear reject, review, or accept signal — and often flagging which specific preventive measure would help most on a given order.
What to evaluate in a vendor
- Model currency: monthly or real-time model updates beat a model trained on year-old fraud patterns
- Data verification: how often the underlying data sources themselves get refreshed and checked
- Techniques used: heuristics, neural networks, shared velocity data across the vendor's client base
- What's bundled in: address verification, reverse lookups, geolocation, device identification, freight forwarder checks
- Risk sharing: whether a chargeback guarantee comes with the score
- Scoring format: a simple pass/fail, or a numeric score with a defined range
- Channel support: eCommerce, mobile browser, and native app coverage
- Volume pricing: discounts at higher transaction counts
- Score descriptors: codes explaining the reasoning — "address unverifiable," "high velocity use" — not just a bare number
- Manual review tooling for whatever your review team actually needs
- Customization for your specific business, and realistic insult-rate expectations at different score thresholds
How it actually works
A merchant submits order data, and the service runs integrity checks, compares against fraud lists, analyzes velocity patterns, verifies address and phone, and applies geolocation — correlating all of it into a single score or pass/fail result, typically in seconds, in real time or batch.
Using the result well
- Submit every data element you have — accuracy scales with input completeness
- Run authorization checks before fraud screening, not after
- Set decline and review thresholds based on your own actual chargeback history, not a generic default
- Auto-accept anything below your review range floor
- Bring in a fraud analyst for the initial implementation if you don't already have one
The tradeoff that never goes away
Even the better fraud-screening services catch somewhere between 40–70% of fraud attempts — and a higher catch rate almost always comes with a higher false-positive rate too. In-house systems specifically lack the cross-merchant data breadth an external service has, which limits how well velocity and pattern analysis can actually perform.