Behind every "approved," "declined," or "flagged for review" decision is usually a risk score, built from dozens of signals that have nothing to do with the amount being charged.
What actually feeds a risk score
Device and browser fingerprinting, IP address and geolocation versus the billing address, how fast the checkout form was filled in, whether this card or email has been seen before, and the customer's own transaction history all feed into the same score. No single signal is usually decisive on its own.
Why one signal alone rarely decides anything
A mismatched billing country isn't automatically fraud — it might be a customer traveling, or a gift purchase. A risk engine's job is to weigh many imperfect signals together rather than hard-block on any one of them, because doing the latter blocks far more genuine customers than it stops fraudsters.
The trade-off every merchant is really making
Every risk setting is really a trade-off between fraud losses and false declines — turning risk thresholds up too far quietly turns away legitimate customers, while turning them down too far invites more fraud and chargebacks. There's no single "correct" setting; it depends on the business's risk tolerance and margins.
Key takeaways
- A risk score combines many weak signals, not one strong rule.
- Signals like location or device are context, not verdicts, on their own.
- Every risk threshold trades fraud losses against false declines — there's no zero-cost setting.
- The right balance depends on your margins and risk tolerance, not a universal default.