Merchant Fraud Guide Sections

Fraud Scoring: What the Number Means

A fraud score turns a pile of risk signals into one number. Here is how to read it, act on it, and know when it is wrong.

Every order brings a pile of clues. The card, the device, the shipping address, the email. A fraud score squashes all of that into one number you can act on. This is fraud scoring.

What is a fraud score?

A fraud score is a number that says how risky one payment looks to a model. It is a judgment, and judgments can be wrong. It is a single judgment made from many signals at once.

The signals come from everywhere. Radar's AI models evaluate hundreds of risk factors when scoring a charge. Stripe's guide names location and past behavior as examples of the factors a model can weigh. This is ai fraud detection at work: a model judging each new payment against what it has learned. If you want the wider picture of how these models judge risk, read about fraud risk scoring.

How Stripe Radar's risk score works

Stripe Radar gives each payment a numerical risk score between 0 and 99. Zero is the lowest risk. Ninety-nine is the highest. Use that number to decide what to do before you ship.

Radar then sorts payments into risk levels. Stripe says a score of 65 or above indicates elevated risk, and a score of 75 or above indicates high risk. Payments can also be rated normal risk. Radar assesses the risk level for card, ACH, and SEPA Direct Debit payments.

What the risk levels mean by default

Each level triggers a default action. Know these before you change anything.

High risk means Stripe believes the payment is likely to be fraudulent, and it blocks those payments by default. Elevated risk payments are allowed by default.

Two things trip merchants up. First, normal risk does not mean safe. Stripe says payments with normal risk can still turn out to be fraudulent. Second, sometimes there is no score at all. If an error causes risk evaluation to fail, Stripe reports the payment as having unknown risk. Unknown risk is not a clean bill of health. It is a shrug. Decide how you want to handle those before one shows up.

How to act on scores

The defaults are a starting point. You can go further in three ways.

Custom rules. You can write custom rules for more control over which payments to review, allow, or block, if your Radar plan supports that feature. A rule is constructed using the syntax {action} if {attribute} {operator} {value}. In plain words, the rule names an action, then the condition that triggers it. Review rules place matching payments in a review queue while Stripe still processes them normally. Only successful payments are placed in review, so payments declined by the issuer never reach the queue. Allow rules override all other rules and Stripe risk assessment, so use them sparingly. Rules can negatively affect your business if used incorrectly. A bad rule blocks good customers.

Risk settings. Risk settings let you balance authorization and fraud on your account by using risk controls. Maximize protection blocks payments likely to receive early fraud warnings. Balance risk and revenue tolerates some risk. Maximize revenue prioritizes revenue by blocking high-risk payments. Note that risk controls and risk settings will not override the custom rules you created.

Reviews. Payments marked for review continue to the authorization process and can give additional risk factors. So a review is not a hold on the money. It is a second look for you, before you ship.

Limits of fraud scores

No score is a guarantee. Fraud scores do not catch every fraudulent payment, and a high score can land on an honest customer. These false positives cost you sales and customers.

Stripe is blunt about the final point. You are ultimately responsible for payments you choose to accept, including those later disputed or found to be fraudulent. A fraudulent sale can later turn into a chargeback. A score is a decision aid. The decision is yours.

How to improve scoring over time

The models learn from what you tell them. Refunding and reporting payments you believe are fraudulent helps improve Stripe's fraud detection algorithms and risk evaluations. Marking a payment as fraudulent adds its email address and card fingerprint to block lists. Payments using that email or card can then be blocked.

Machine learning models can be retrained on new data so they stay up to date and better detect emerging fraud patterns. Your reports feed that loop. If you use Sigma or Data Pipelines, you can query disputes and fraud data. You get rule decisions and attributes for each individual payment, so you can see which rules earn their keep.

One more gap to watch. Fraud scoring judges payments. Stripe says payments with normal risk can still turn out to be fraudulent, and that includes a payment from a taken-over account. That is account takeover fraud detection, a separate problem. For a deeper look at Radar's own models, see stripe ai fraud detection.

Start with the defaults. Read your reviews. Write rules only when you see a pattern worth catching. That is how a score becomes useful instead of noisy.

Sources

The rest of Fraud prevention