Why low fraud isn’t always a win, with Galit Shani-Michel of Forter

Low fraud and chargeback rates? Great. But what if it’s costing you customers? In this episode of Payments Unfiltered, host Theo Spyrides is joined once again by Galit Shani-Michel, VP of Emerging Products at Forter, to explore the hidden risks of a “zero fraud” mindset. From KPI misalignment to false declines and friction-filled 3DS flows, Galit explains how well-meaning fraud strategies can quietly damage conversion, customer experience, and long-term growth.

Theo Spyrides

Host of Payments Unfiltered

Galit Shani-Michel

VP of Emerging Products @ Forter

Read transcript

TS: Welcome back, Galit. Great to be speaking again. Today we're going to be diving into how we can help merchants think and manage their fraud strategy better. You've obviously had lots of experience even before Forta managing fraud for businesses, how do you approach building a fraud prevention strategy for a merchant?

Galit Shani-Michel: It's a really good question. I think the most important thing today is to realize that the technology has changed — a lot of the ways merchants used to fight fraud in the past aren't necessarily best practice anymore. A lot of things happened manually in the past. When I managed fraud, I had fraud rules and a team reviewing them, deciding if a transaction was fraudulent. Everything happened post-authorization — the authorization would go to the bank, then if a rule caught the transaction, it would wait for manual review. A lot of the riskier or flagged transactions would be reviewed by a fraud analyst who'd decide to void the transaction. Back then, the most important thing to get from your PSP was a long window between auth and capture, so you could still void the transaction if the agent thought it was fraud. Today, with all the technology, you can make real-time decisions using AI and other tools — you don't need to manually review transactions. You might still manually review a very small percentage, but best practice is doing it before authorization, so you can clean the traffic before sending it to the banks. Issuers and acquirers love you more when you only send them good traffic. When an issuer sees a lot of fraud, they block a lot of it — they don't know you'll catch it later, so they think they're blocking it all for you, and your risk level with them stays high, even if your chargeback rate is great. I recently talked to Bank of America about a merchant doing a great job with fraud post-authorization. I asked what their risk level was — "very high." I said there were no chargebacks. They said, "Look how many transactions we block for fraud" — they think it's thanks to them. That merchant moved their fraud detection to pre-authorization — real-time decisioning, no manual review needed (manual review can't happen before authorization anyway). They cleaned all the traffic, blocked fraud before it even went to authorization, and saved on decline fees. Issuers stopped seeing all that fraud. Two months later, Bank of America said the merchant was now low risk — "We don't have to decline fraud anymore." When issuers like you better, they lower their defenses, and the auth rate goes up over time. Fraud strategy ties closely into payment strategy. Some businesses separate fraud and payment managers, but we're seeing more consolidation there. To optimize your payments, you need a proper fraud prevention strategy. If your fraud strategy isn't great, your payment acceptance rate won't be either. Number one: make sure merchants are handling fraud pre-authorization.

TS: Is there any reason to do anything post-authorization in this modern world, with all the tools available pre-auth?

GS-M: Not really. Some merchants still want to manually review some traffic, depending on their business. We always advise: do everything pre-auth, then handle whatever's left post-auth if there's a real reason.

TS: And you save on headcount, right? You could take the budget for fraud analysts reviewing payments manually and put it toward the tooling instead.

GS-M: Exactly. Merchants moving to pre-auth and automating fraud don't need all those people reviewing it. It's more than that. With manual review, how do you double your headcount just for Black Friday and Cyber Monday? Consumers also want fast service; waiting three days in a queue isn't great customer experience, and that matters a lot today. When you automate and move to pre-auth, everything scales regardless of peak season, as long as you have the right fraud vendor. Merchants can redeploy that headcount to more strategic work — reviewing performance, understanding machine learning outputs. You still need people to decide how much risk to take on, per segment — automation doesn't mean handing the world over to a computer. In the US especially, 3DS used to be post-auth for years, but more merchants now understand the advantage of moving fraud to pre-auth. The other reason is to properly leverage 3DS: risky transactions should go to 3DS (not be declined outright), pure fraud should be declined, and good transactions should get a frictionless experience. You can't do that if your fraud check happens after the transaction — it's too late to apply 3DS then. Fraud strategy today has to span the whole flow — registration, login, checkout, post-purchase. Fraud can happen anywhere in that journey. If your checkout fraud defenses are strong, fraudsters will abuse you elsewhere — account takeover is a big one. They log into accounts that aren't theirs, change the address, and order freely since a card's already saved. Same with return abuse — claiming items weren't received, or returning something else entirely. The key is understanding identity at every interaction. Say "Garet" is registering — is it really Garet? It depends on your strategy: some merchants don't mind fake accounts (looks good for growth metrics), others want one account per person, especially to prevent coupon abuse. You have to decide whether to block at registration, at login, or only apply friction like 3DS at checkout, and understand what's actually at risk in that account (saved credit card, loyalty points, etc.).

TS: It sounds like you need to think very holistically about fraud strategy. You mentioned some companies have a head of fraud and a head of payments as separate roles. But maybe siloing fraud isn't the best approach. As a merchant, how would you advise setting up a fraud team? Separate from payments, or under one leader steering both strategies?

GS-M: It really depends on the merchant. There's also digital, customer experience, e-commerce management roles in the mix, so the structure varies. But the most important thing is that whoever leads fraud and whoever leads payments work together, with aligned KPIs. For example: if I'm the fraud manager measured purely on chargeback rate, I might send everything to 3DS (even using EU regulation as an excuse) — no chargebacks, looks great for me, but conversion tanks. The payment manager gets blamed for conversion, even though it was the fraud team's 3DS decision. Conversion isn't just auth rate — it's overall "complete rate": how many people tried to buy vs. how many succeeded. If your complete rate is 85%, that 15% loss might break down as 5% fraud declines, 5% 3DS drop-off, 5% bank declines — but it's all lost revenue. Someone needs to own that combined KPI, along with payment optimization (smart routing, data sharing with banks, etc.) and customer experience — which is often owned by someone else entirely. When I started managing fraud at one company, I proudly told the CEO chargebacks were really low. He said, "It's too low — can you show me your fraud decline rate?" I didn't have that report. He asked if I was sure I wasn't blocking good customers. That's when I realized I had it wrong. I fixed the strategy, fraud declines dropped, and average transaction value went up — because higher-value transactions that used to get flagged as fraud were now going through. Fraud needs to be low, but not zero — how low depends on your business, your chargeback losses, your 3DS exemption thresholds with your PSP. The real question is: are you measuring fraud decline rate and false decline rate? False declines are harder to track, but issuers can tell you that rate after the fact.

TS: How would you advise merchants on iterating and experimenting, like apply to all volume, a subset, use specific tools?

GS-M: With all the technology and fraud vendor networks available today, number one is understanding identity — hard to do alone since you only know identities you've seen before. Using a fraud vendor with a broader network helps determine legitimacy. Most large enterprises don't handle fraud in-house anymore, because even a 0.5% improvement in approvals is pure bottom-line revenue — and we're seeing merchants gain 2-3% more approvals with proper fraud prevention. A/B testing is critical — before/after data on any strategy change. For example, moving from post-auth to pre-auth: auth rate goes up, fraud declines go up, bank declines go down — but is your overall complete rate actually improving? You need to watch KPIs per segment too — new regions, new regulations (like Japan requiring 3DS) — and break it down further: 3DS success rate, auth completion rate, fraud detection rate. Measuring each step, across segments and countries, shows you exactly where the gaps are — e.g., "auth rate in India isn't great, but 3DS is fine, so what's happening?" You can loop in your PSP or peers in the community to investigate. The key is continuously monitoring KPIs to catch what's changed.

TS: Amazing. What's the one piece of advice you'd want businesses to take away when building their fraud strategy?

GS-M: Keep your customer in mind. A lot of fraud thinking assumes everyone's bad — instead, assume everyone's good unless proven otherwise. Think about the experience: customers want a frictionless, one-click checkout. They've already spent time finding what they want to buy, now they just want to get through payment and look forward to their package arriving. (My daughters ask "did my package arrive?" before they even say hello!) Payment shouldn't be the thing that stops that excitement. Build your strategy around detecting and protecting good customers while still catching bad actors. But if you treat everyone as a suspect, you'll block a lot of good customers too. Customer experience has to stay at the center.

TS: That's amazing advice. Thank you so much for your time. It's been great speaking with you.

GS-M: Thank you so much.

Meeting with the best in the business

Primer puts you in control of how money moves across the business. With our unified infrastructure you can orchestrate every flow, reduce friction, and capture more revenue everywhere.

Revolut Bank
Revolut Bank
Revolut Bank
Revolut Bank
Revolut Bank
Revolut Bank
Revolut Bank

Latest episodes

Episode
5

February 11, 2025

Buyer liars, AI fraudsters & lost revenue with Galit Shani-Michel

Featuring:

Theo Spyrides

&

Galit Shani-Michel

Fraud is evolving, and merchants can’t afford to fight it alone. In this episode of Payments Unfiltered, our host, Theo Spyrides, speaks with Galit Shani-Michel, VP of Payments at Forter, to discuss the rise of AI-powered fraud, the growing threat of friendly fraud, and why false declines cost businesses more than they realize. They also discuss why traditional fraud rules no longer work, how merchants can leverage data-sharing networks, and the real impact of 3DS on fraud prevention and conversion rates.

Episode
4

October 8, 2024

How partnerships power payments with Michaela Weber

Featuring:

Theo Spyrides

&

Michaela Weber

Join host Theo Spyrides as he dives deep with Michaela Weber, SVP & GM of Payments & Global Business Development at BigCommerce, to reveal how partnerships are reshaping the payment ecosystem. Discover how these alliances are fueling innovation and unlocking massive value for merchants. Theo and Michaela also discuss the breakthrough ecommerce trends and cutting-edge tactics merchants use to redefine their customers' checkout and payment experience.

Episode
3

August 7, 2024

Driving change in fintech with Parvinder Dahri-Cooper

Featuring:

Theo Spyrides

&

Parvinder Dahri-Cooper

Join host Theo Spyrides as he sits down with Parvinder Dahri-Cooper to explore her extensive experience in the payments ecosystem. Parvinder shares insights from her pivotal role in taking Worldpay to IPO and discusses her impactful efforts in driving diversity, equity, and inclusion (DE&I) within the fintech industry. Discover why fintech must champion diversity and how it can lead the charge in supporting underserved communities. This episode also delves into the challenges of balancing product innovation with regulation and the potential for fintech to drive social good.

Episode
2

April 25, 2024

Behind the scenes with a Fintech VC, featuring Rob Moffat

Featuring:

Theo Spyrides

&

Rob Moffat

Rob Moffat, a partner at Balderton Capital, joins Theo Spyrides to discuss his journey into the VC space and his passion for payment and fintech innovation. He also discusses the trends He believes have shaped the payment industry in the last five years, how He spots and evaluates promising payment startups, and the essential skills and traits that payment entrepreneurs need to thrive.

Episode
1

February 22, 2024

The Founder's Story with Gabriel Le Roux

Featuring:

Theo Spyrides

&

Gabriel Le Roux

Primer CEO & Co-Founder Gabriel Le Roux speaks on the Payments Unfiltered Podcast about his journey in payments, his experiences founding a successful start-up, and the evolution of the payments ecosystem over the past decade and where it’s going.

Subscribe and never miss an episode

The next move is yours

Want to join the podcast