A stolen credit card gets tested on your ecommerce site at 2 a.m. With traditional post-auth screening, the transaction may already be authorized — and you may already have paid a processing fee — before your fraud system flags it. Using pre-auth for fraud protection moves fraud screening earlier in the payment flow, assessing risk in real time while the shopper is still at checkout and before the transaction is sent to the card issuer for authorization.
Here are five ways moving fraud detection pre-auth can boost customer experience and your bottom line.
TL;DR
- Pre-auth fraud detection screens each order for risk during checkout, letting merchants block suspected fraud before payment data ever reaches the issuing bank for approval.
- Blocking fraudulent transactions earlier limits per-attempt processor and gateway fees from card-testing attacks and reduces the risk of tripping card-network monitoring thresholds like those in the Visa Acquirer Monitoring Program (VAMP).
- Issuers often lack full visibility into a shopper’s history, so pre-auth screening lets merchants pass along richer transaction context, which research links to higher authorization rates when fraud rates fall.
- Screening orders before authorization gives issuers extra context, helping prevent legitimate, but unusual purchases from being turned away.
- Pre-auth screening lets merchants apply extra verification only to higher-risk orders, so low-risk shoppers proceed with minimal friction while riskier transactions get closer scrutiny.
- Signifyd’s Authorization Rate Optimization (ARO) solution reviews orders in real time using Commerce Network signals, stops fraud prior to authorization and shares deeper context with issuers to improve payment authorization decisions.
- Customers have reported conversion improvements over 200 basis points and issuing partners have reported reversal rates on authorization declines above 50% after leveraging ARO.
1. Pre-auth stops fraud before it reaches authorization
With traditional post-auth fraud screening, brands like yours send a transaction to the card issuer (bank) for authorization before their fraud system completes its assessment. That means issuers may evaluate both legitimate and fraudulent traffic without knowing which transactions the merchant ultimately plans to accept.
Pre-auth fraud protection changes the order. Your systems assess fraud risk first, while the shopper is still checking out. If the fraud system identifies a transaction as fraudulent, you can stop it before sending an authorization request to the issuer.
That gives you more control over the traffic you send into the payment ecosystem. Instead of asking issuers to evaluate every attempted transaction, you can filter out more known fraud first and reserve authorization requests for traffic you actually want the bank to consider.
2. Pre-auth prevents unnecessary costs
Fraudulent authorization traffic carries costs of its own. Processor and gateway fees can add up across high-volume attacks, while card-testing activity can also increase your exposure to network monitoring programs.
Processor and gateway fees
Fraudulent authorization attempts can still generate processor and gateway fees whether the issuer declines the payment or you later reject the order. The amount depends on your providers, contract and pricing model, but high-volume attacks can multiply those per-attempt charges across hundreds or thousands of transactions.
In a card-testing attack, for instance, fraudsters rapidly submit stolen card credentials to determine which cards are still active, often generating large volumes of authorization attempts in a short period. If your business faces 10,000 fraudulent attempts, you would pay 10,000 times whatever per-attempt processor or gateway fee your contract specifies. Even a small fee — say, $0.05 per attempt — would add $500 in costs from fraudulent traffic alone.
Costs tied to network monitoring
That same card-testing traffic can also increase a merchant’s exposure to card-network monitoring programs.
VAMP, for example, tracks enumeration activity (systematic attempts to test payment credentials) across approved and declined authorization transactions. Visa identifies merchants for enumeration monitoring when they exceed both its transaction-count and enumeration-ratio thresholds.
If excessive enumeration activity puts you on the network’s radar, you may need to work with your acquirer to implement additional fraud controls, investigate the source of the traffic and demonstrate that you’ve reduced it. That adds operational overhead on top of the fraud and dispute costs the same card-testing activity may already be generating.
By filtering out more fraudulent traffic earlier, pre-auth screening can reduce the volume of bad transactions generating processor and gateway fees while limiting the damage from card-testing activity.
3. Pre-auth gives issuers better context for authorization decisions
You don’t make payment decisions alone. Once a transaction reaches the issuing bank, the issuer runs its own fraud analysis before deciding whether to authorize the payment. But the issuer doesn’t always have access to the same information that you and your fraud platform do.
You may know, for example, that a shopper has a long purchase history, regularly uses the same device or consistently ships orders to the same address. The issuer may see only a subset of that information when it evaluates the authorization request.
The quality of the traffic you send also matters. Worldpay (now Global Payments Inc.) found a direct negative correlation between merchant fraud rates and authorization rates: As fraud rates rise, authorization rates fall.
Issuers have little tolerance for fraud affecting their cardholders, so consistently risky traffic can lead them to apply tighter controls to your transactions. Cleaner traffic, on the other hand, gives issuers less reason to add friction in the name of fraud prevention.
Pre-auth fraud screening can help on both fronts. You can filter out more known fraud before it reaches the issuing bank and provide deeper context on the transactions you do send for authorization.
Signifyd’s Authorization Rate Optimization solution (ARO), for example, shares additional transaction intelligence directly with participating issuers. That gives the bank more context during its own fraud analysis and helps it make a better-informed authorization decision.
4. Pre-auth reduces false declines and protects conversion
Issuer fraud controls can stop bad transactions, but they can also block legitimate ones when they don’t have enough context.
A shopper might place an unusually large order from a new device after moving to a new address, or make a purchase from another country while traveling. Each change can look risky on its own, even when the transaction is legitimate. If the issuer falsely declines it, the transaction stops before it can move forward to you for merchant approval.
You lose the sale and your customer hits a roadblock at checkout. On top of that, you risk losing future revenue from that shopper. According to Signifyd data, 82% of ecommerce shoppers say they won’t tolerate two bad experiences from a merchant.
Pre-authorization screening gives you a chance to improve that authorization decision before it happens. Because Signifyd evaluates the transaction while the shopper is still at checkout, it can share additional transaction and fraud intelligence with participating issuers before they decide whether to approve or decline the payment. That extra context can help the issuer recognize a legitimate transaction that might otherwise look risky.
5. Pre-auth creates a better checkout experience
If an order contains inconsistent checkout details, for example, you can prompt the shopper to review or correct that information before completing the purchase. That gives a legitimate customer a chance to resolve the issue in the moment instead of getting routed into a slower review process or turned away altogether.
You can also apply friction more selectively. Rather than challenging every shopper with the same verification step, you can reserve additional checks for transactions that actually show signs of risk.
The result is a checkout experience that adapts to the transaction: Low-risk shoppers can move through with minimal friction, while higher-risk orders get the additional scrutiny they need.
How does pre-auth fraud protection work with Signifyd?
Signifyd’s ARO evaluates transaction risk and stops fraud before it reaches the issuer for authorization.
- Evaluate the transaction: Signifyd analyzes each order in real time using machine learning and signals from the Commerce Network.
- Filter out fraud: Transactions identified as fraudulent are stopped before they enter the authorization flow.
- Send cleaner traffic forward: Transactions that pass fraud screening move to the issuer for authorization, with participating issuers receiving additional Signifyd intelligence to inform their decision.
What results can merchants see from pre-auth fraud screening?
Leveraging ARO for pre-auth fraud screening can improve conversion and prevent false declines. Signifyd customers have reported:
- More than 200 basis points higher conversion for one of the world’s largest electronics retailers after moving to pre-auth fraud screening with Signifyd.
- Roughly 300 basis points higher conversion for a fast-fashion retailer.
- Decline reversal rates above 50% among Signifyd’s issuing partners, meaning additional Commerce Network data helped issuers overturn more than half of the fraud declines they reassessed.
Want to prevent fraud before authorization? Book a demo to see how Signifyd’s Authorization Rate Optimization solution works to improve authorization rates, reduce false declines and protect conversion.