What problem does it solve?
Every online order is a small bet. Approve it, and most of the time a genuine customer gets their package; occasionally the order was placed with a stolen card, a fake identity or a friendly fraud claim waiting to happen, and the merchant absorbs the chargeback, the lost goods and a fee on top. Decline it, and most of the time fraud was avoided; occasionally a loyal customer was turned away for looking unusual on paper, and a merchant that never checks its false decline rate has no way of knowing how many of those customers quietly stop coming back.
Manual review works at a small scale, but reviewers cannot see the patterns that only show up across thousands of merchants. Static rules age quickly: a rule written for last season's attack blocks genuine customers long after the attack has moved on. The shift is to a model that scores the whole order in the time a checkout page can wait, plus a guarantee from the vendor that puts its own money behind the call, which is what turns a fraud score into a decision a merchant is willing to automate.
How does it work?
- Score the order the instant it is placed. Device, browser, email, shipping and billing details, behaviour on the site and payment data feed a model trained across many merchants, not just this one's own history.
- Add the wider picture. The score is checked against known fraud rings, stolen identity lists and the buyer's own order history with this merchant and, where the vendor pools data across its network, with others.
- Decide inside checkout. The order is accepted, held for review or declined within the time the checkout page can wait, before the customer moves on to payment confirmation.
- Guarantee the call. Vendors that offer a chargeback guarantee cover the fraud and, often, "item not received" losses on orders they accepted, and take on the manual review and the chargeback dispute themselves.
- Learn from outcomes. Confirmed fraud, disputed chargebacks and false declines feed back into the model and the merchant's own risk policy.
- Audience
- Back office
- Autonomy
- Autonomous
- Adoption
- Mainstream
- Channels
- API and system to system
What is it worth?
Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.
No public deployment has disclosed a measurable outcome yet.
Value drivers: Risk and loss reduction, Revenue growth, Lower cost to serve.
Indicative value
An online retailer with 500,000 orders a year and an 80 USD average order value
USD 48,000 to USD 224,000
Annual fraud chargeback losses avoided per year
How this is calculated
Formula: orders * aov * chargebackRate * reduction. The low scenario uses every low input, the high scenario every high input.
| Input | Low | High | Basis |
|---|---|---|---|
| Orders per year orders, orders per year | 500,000 | 500,000 | The reference retailer. |
| Average order value aov, USD | 80 | 80 | Editorial assumption for a mid sized online retailer, replace with your own. |
| Fraud chargeback rate before screening chargebackRate, fraction of orders | 0.003 | 0.008 | Editorial assumption, replace with your own chargeback rate. |
| Share of fraud chargeback losses avoided reduction, fraction of chargeback losses | 0.4 | 0.7 | Editorial assumption, replace with your own. Neither evidence record on this page reports a reduction in fraud losses specifically: Signifyd's published figures for Cymbiotika and Rainbow Shops are reductions in the overall chargeback rate, which mixes fraud and non fraud or abusive chargebacks, not a clean before and after fraud loss number, so they are not used to set this range. |
What it leaves out: Gross avoided chargeback loss only. It leaves out the fee charged for the screening or guarantee service, any change in the approval rate for genuine customers, and the operational cost of running a checkout integration.
Who already uses it?
2 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.
Rainbow Shops
United States · Retail and ecommerce · 2022
Rainbow Shops is a US value apparel retailer for women and children. It ran a machine learning fraud tool that worked until it moved its checkout from Salesforce Commerce Cloud to Shopify and found its fraud provider had no strong Shopify integration. It switched to Signifyd for order screening, the chargeback guarantee and automated chargeback disputes, so its own staff no longer file disputes by hand.
No outcome disclosed.
Cymbiotika
North America · Retail and ecommerce · 2021
Cymbiotika is a supplements and wellness brand on Shopify, founded in 2018, with a large share of recurring subscription orders. As order volume grew, false positives led to many legitimate subscriptions being cancelled, causing friction for loyal customers and driving hundreds of support inquiries a day. Cymbiotika became a Signifyd customer in 2021, using order screening to decide in real time whether to accept each order, plus Complete Chargeback Protection, which Signifyd's own site describes as cover against both fraud and non fraud chargebacks.
No outcome disclosed.
How do you implement it?
A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.
Data you need
- Historical order, chargeback and refund data with fraud outcomes labelled
- Device, browser and behavioural signals captured at checkout
- Product catalogue and shipping data to flag high risk categories
Systems to integrate
- Ecommerce platform or checkout
- Payment service provider and card network chargeback feeds
- Order management system for holds and cancellations
- Customer account and order history
Complexity: Medium
A first launch is often quick because most vendors ship a ready made plugin for platforms such as Shopify. The real work is agreeing which categories, price bands and countries get a different policy, cleaning up the chargeback and refund history the model or the guarantee contract will be judged against, and rebuilding that baseline whenever the checkout platform changes.
- 1
Separate the policy from the model
Decide, as a business, which categories, countries and price bands need a stricter or looser policy, and write it down before choosing thresholds, so a change in the model does not silently change the business rule.
- 2
Agree what the guarantee actually covers
Read the contract for carve outs, for example policy abuse, promotion abuse or a cut off for filing a dispute, and keep a short internal note of what is and is not covered so support staff do not promise more than the guarantee delivers.
- 3
Feed it the full order context
Connect device, behaviour, shipping and account history, not just the payment details, so the model has as much signal as a human reviewer once had.
- 4
Watch the false decline rate as closely as fraud
Sample declined orders every week and call or message a portion of the customers to check whether they were genuine, since a merchant only sees the fraud it caught, not the customers it turned away.
- 5
Rebaseline after every checkout change
A platform migration changes the device and session signals the model sees; treat the weeks after a checkout replatforming as a fresh baseline for chargeback and false decline rates, not a continuation of the old ones.
Guardrails
- Every automatic decline is logged with the reasons and can be challenged by the customer
- A held order stops the shipment before a decision, never after
- The score and its inputs are retained for the length of the chargeback dispute window
- Payment and personal data reach the model only through the vendor's own pipeline, never typed into a general purpose prompt
KPIs to instrument
- Chargeback rate and chargeback win rate, before and after
- Approval rate, checked against a manually confirmed sample for false declines
- Fraud losses net of the fee paid for the guarantee
- Manual review queue depth and time to decision, where the merchant still reviews orders itself
Human in the loop
Once a guarantee is in place, individual orders are rarely reviewed by the retailer's own staff: that manual review sits with the vendor's analysts, who investigate borderline orders and defend disputed chargebacks with the merchant's evidence. On the retailer's side, a person still owns the risk policy, reviews declined and disputed orders in aggregate every month, and signs off before any threshold or policy change goes live.
Common failure modes
- Good customers declined at the worst moment
- Aggressive thresholds turn away genuine repeat customers, particularly on subscription renewals. Watch complaints and repeat purchase rate by segment, not only the chargeback number: at Cymbiotika, false positives cancelled legitimate subscriptions and drove hundreds of support inquiries a day, which is why it moved to a fraud vendor aimed at reducing false positives.
- The guarantee covers less than assumed
- Guarantee contracts vary by vendor and plan. Check yours for carve outs such as policy abuse, promotion abuse or a cut off for filing a dispute, and treat every declined chargeback type separately rather than assuming a single guarantee number covers all of them.
- Drift after a platform migration
- Moving checkout platforms changes the device and session signals the model sees; treat the weeks after a migration as a fresh baseline for chargeback and false decline rates, not a continuation of the old ones. Confirm the new platform has a proven integration with your fraud vendor before you commit to the move: a weak integration is what pushed Rainbow Shops to switch vendors when it replatformed onto Shopify.
What are the risks and rules?
EU AI Act
Minimal risk
Deciding whether to accept a commercial order is not listed in Annex III: it is not a creditworthiness, employment, essential service or biometric decision about a natural person. It stays minimal risk provided the decision is limited to a commercial transaction and does not extend into scoring the buyer's general creditworthiness or blocking access to an essential service.
Guidance
- Guidelines on automated individual decision making and profiling (WP251rev.01) (Article 29 Working Party, endorsed by the European Data Protection Board, Europe). The supervisory guidance behind Article 22: it explains when a solely automated decision, which a firm outright order decline can be, has a legal or similarly significant effect, and what that gives the customer a right to, including human intervention and a way to contest the decision.
Controls to put in place
- A documented risk policy with an owner, reviewed whenever thresholds or the model change
- A route for a declined customer to reach a human and contest the decision
- Regular checks of decline rates across regions, price bands and payment methods for unfair bias
Frequently asked questions
- How is order fraud screening different from card fraud scoring?
- Authorization fraud scoring runs in milliseconds while the card authorization is still open, done by the issuer, the network, the acquirer, or a merchant side payment tool such as Stripe Radar. Order fraud screening also runs at checkout, but decides on the whole order, not just the card: it can pull in shipping, account and behavioural history alongside the payment data, and is often paired with a chargeback guarantee that shifts the fraud risk onto the vendor.
- How much can order fraud screening reduce chargebacks?
- It depends heavily on the merchant's starting point and product mix, and on which product actually moved the number. Signifyd's own case study on the supplement brand Cymbiotika credits a chargeback reduction to Complete Chargeback Protection, a guarantee product that covers both fraud and non fraud chargebacks, not to the order screening decision on its own, so it is not a clean read on what screening by itself achieves for any specific business.
- Does a chargeback guarantee remove the retailer's own fraud risk entirely?
- No. A guarantee only covers what its contract says: commonly fraud and, on some plans, "item not received" chargebacks on orders the vendor accepted. Check your own contract for carve outs such as policy abuse, promotion abuse or a cut off for filing a dispute, rather than assuming it covers every chargeback type.
- Can an online retailer decline an order by AI alone under GDPR?
- A solely automated decision with a significant effect on a customer, which an outright decline can be, gives EU customers a right under Article 22 to ask for human review. In practice, offer a support channel so a declined customer can ask a person to look again, rather than routing every single decision through a human up front.
How to cite this page
Blits.ai AI Use Case Library, "AI order fraud screening for ecommerce checkout", last verified 29 September 2026, https://www.blits.ai/ai-use-cases/ecommerce-order-fraud-screening. Licensed under CC BY 4.0. Method: how we verify use cases.
Changelog
- 29 September 2026: First published