Merchant Fraud Guide Sections

How Adyen Risk Rules Work

Adyen's risk rules sit in risk profiles you attach to a merchant account. Here is how the actions, lists and testing fit together.

Adyen risk rules are the checks that decide what happens to a payment before or after it runs. You do not set them one by one on each order. You group them in a risk profile, then attach that profile to a merchant account. This guide walks through how the pieces fit, based on what Adyen's own documentation says they do.

What Adyen's risk rules are

Adyen's docs say Protect is Adyen's risk management tool. Inside Protect, a risk profile controls which risk rules run on a merchant account's payments. A risk rule triggers when a transaction matches the conditions of the rule. That is the whole idea. You write a condition, and when an order meets it, the rule fires.

Some of the rules in a profile are machine learning rules. Adyen's docs say these evaluate the risk of transactions. Others are custom rules. Adyen says you can build these around the fraud risks your own store faces. Stripe has its own version, covered in Stripe Radar rules.

Rule actions and their priority order

Adyen's docs say each custom rule can trigger an action of Allow, Block, Review, or Check for 3DS. For each rule, you pick when it runs, before or after authorization. You also pick what it does when a payment matches.

The actions do different things. A Review action sends the transaction to case management when it matches the rule. Adyen's docs also say you can use a Check for 3DS rule as a trigger for Dynamic 3D Secure rules. This works for a rule that runs before authorization.

Priority matters when two rules point to different actions. Adyen's docs say Allow rules have the highest priority within a risk profile and override Block or Review rules. So if one rule says allow and another says block, the Allow rule wins. Rules that run after authorization beat rules that run before it. But there is a catch. If a payment is blocked before authorization, no rule that runs after it will fire.

Why would you run a rule after authorization? Adyen's guide says post-authorization rules can take extra signals into account, such as CVC/CVV codes or AVS responses.

Building custom rules

Custom rules let you tune your risk profile. They help you handle the risks your own store faces. There is a plan requirement here. Adyen's docs say you can only use custom rules when you use Protect premium. Check Adyen's current pricing page for what that tier includes, since pricing changes.

Writing a rule means stacking conditions. You can add conditions to a custom rule by selecting AND or OR. AND means every condition must hold. OR means any one of them is enough.

Then you pick operators. Adyen's docs say the data type of a field determines which operators you can use and how the fields will be compared. A few examples from the docs. The is one of operator compares a field against multiple field values of a list. The is in list operator checks a field against a risk list. The list can be yours or one from Adyen. The contains string operator compares the field value to a specific string. The greater than operator checks if the field value is above a number you set.

You can copy a custom rule to another risk profile.

Risk lists

Risk lists let you block or allow a transaction based on Adyen's data, your own data, or lists from third parties. They are aggregated and maintained per company account by default. You can set up separate risk lists for each merchant account in your risk settings. You can also set them up in different ways for different risk profiles.

There is a coverage limit to know about. By default, risk lists cover credit and debit cards, SEPA Direct Debit, and PayPal. That is what Adyen's docs say. You must add other payment methods in your risk settings to include them in the risk evaluation. A risk list will not fire on a method it was never given.

You also must submit the required fields in the payment request to trigger a risk list. If the field is not there, the list has nothing to compare.

How you fill a list. You can manually add a single item through your Customer Area. Most risk lists allow you to add multiple items with a.csv file. You can use the Referrals API to automate uploads to block and allow lists. You can also add or remove items based on a specific transaction in the Fraud control widget. You can block or allow a few shopper details. These include the email, the IP address, and the shopper reference.

One more plan note. Custom risk lists require that you enable premium features.

The Adyen global referral list

The Adyen global referral list holds card and bank account numbers. The card networks reported these as stolen or used for fraud. You do not build this one. It comes from the card networks. Payments that match the global referral list are blocked before authorization. You will not see the details in your own block list. You can indicate in the risk settings whether you want to use the global referral list.

Shopper details such as name, email, and IP address are masked by default.

Testing and measuring rules

Do not turn on a rule blind. You can backtest a rule before you turn it on. You can also backtest before you change a rule you already use. Adyen's docs say backtesting can give you helpful insights in your risk profile performance.

After a rule is live, you can watch it. You can see stats for each rule and for the whole profile. These include rates for approvals, refusals, and chargebacks. To see profile analytics, open the live Customer Area. Go to Risk & disputes, then Risk profiles. You can also view the transactions that matched a risk rule's criteria.

One input makes all of this work better. Adyen's docs say Protect can make better decisions if you include more fields in the payment request. See also fraud scoring and AI fraud detection.

Where manual review fits

A Review action sends the payment to case management. That is where manual review fraud handling starts.

Use Review for the orders you are not sure about. Use Block for the ones you are sure about. And keep watching the numbers, because a rule set is never finished. It is a thing you tune as your store and its fraud patterns change.

Sources

The rest of Fraud tools