Why Transaction Scoring Is No Longer Enough to Stop Payment Fraud
- Joao Moura, Founder and CEO at Fraudio
- 10.09.2026 01:15 pm #fraudprevention
For a long time, one of the fundamentals in payment fraud prevention has been relatively simple, how risky is this transaction? And we’ve become very good at answering it.
Today, a payment can be assessed against hundreds of variables in milliseconds. Models can consider transaction value, location, device information, previous behaviour and countless other characteristics before producing a risk score and helping determine whether that payment should proceed.
Transaction scoring remains a big part of fraud prevention, but I think the industry is asking too much of it. And the reason is simple, because fraudsters aren’t trying to create transactions that look fraudulent, they are trying to create transactions that look legitimate.
Whilst the industry's ability to identify anomalies has improved, criminals have adapted. They distribute activity, change devices, rotate accounts, test different merchants and reuse infrastructure in ways designed to avoid making any single interaction sufficiently unusual to trigger intervention. That creates a problem for any approach that concentrates too heavily on the transaction in front of it.
The payment may look normal, what it is connected to may not.
A Score Can Only Understand What It Can See
There is a tendency in fraud prevention to frame progress primarily in terms of modelling sophistication. Rules became more sophisticated, machine learning improved what could be detected and now much of the conversation has moved towards AI.
As someone who has worked in AI and data science for most of my career, I am obviously convinced of the value these technologies can provide, but there is a basic limitation that is too easily overlooked.
A better model doesn’t automatically mean a better understanding of the threat.
Every model is constrained by the information available to it. If you give an extremely sophisticated model a narrow view of what is happening, it can make an extremely sophisticated judgement about that narrow view. It can’t however discover relationships it has never been given the opportunity to observe.
This matters because the useful signal in fraud is found within the relationships between transactions, entities and behaviours.
A device could look unremarkable in one payment and so might an IP address, card, account or merchant, but what happens when the same entity begins appearing across other activity? What if seemingly unrelated transactions share infrastructure or if a behaviour that appears normal for one merchant becomes unusual when understood alongside comparable businesses?
Individually, the signals can be weak but connected they can tell a very different story. That is the distinction the industry needs to pay much more attention to. A transaction score tells you something about an event. Fraud prevention increasingly needs to understand the environment around that event.
Fraud Operates Beyond Individual Transactions
Part of the challenge is structural. Issuers, acquirers, PSPs, processors, marketplaces and merchants each see different parts of the payment journey, and fraud systems have often inherited those same boundaries.
Each transaction can appear reasonable when considered locally while becoming much more concerning when placed within a wider context.
For transaction scoring, the implication is important. Historical behaviour within one environment is valuable, but it is not always enough to establish whether the entities surrounding a payment are genuinely low risk.
If a card, device, merchant or other entity has already demonstrated concerning relationships elsewhere, that context can be as important as the characteristics of the transaction currently being assessed.
Legitimate Looking Payments Are The Harder Problem
Authentication provides a useful example. Strong authentication is an important layer of payment security, but passing an authentication step shouldn’t be treated as equivalent to establishing that a transaction is safe. It tells us something about that interaction but doesn’t tell us about the wider relationships surrounding it.
The same applies to any individual control. Fraud prevention works best when signals contribute to a broader understanding of risk rather than being treated as definitive answers in themselves.
Alongside asking whether a transaction looks suspicious, we need to ask what it is connected to. Have those entities appeared before? What do we know about the merchant beyond this particular payment? What does the surrounding activity tell us that the transaction alone can’t?
The Next Step is Context
None of this means transaction scoring is becoming obsolete, in fact, quite the opposite. Real-time scoring remains important to making decisions at the speed modern payments require.
But the quality of that decision depends on the context surrounding the transaction. As payments become faster and more interconnected, repeatedly analysing isolated events becomes less effective if the relationships around them remain invisible.
The next meaningful improvement is therefore not abandoning the transaction score, but enriching the intelligence behind it. A score becomes more useful when it can account for how cards, devices, accounts, merchants and other entities relate to one another over time and across activity.
AI can help identify those relationships at a scale that would be impossible manually, but only when the relevant context is available to it.
The transaction still matters. It is where the payment happens and, very often, where the decision has to be made. It just shouldn’t be where our understanding of the risk ends.






