Fraud & Identity

Consumer information is at the center of our economy. It connects us to the right products and services, helps companies innovate and expand, and allows consumers to make smarter choices throughout their lives. While the use of consumer information is becoming more important to businesses and consumers, there is a growing concern among policy makers that the laws governing consumer privacy are not keeping up. Over the last year, the FTC and the Department of Commerce have been studying these issues and each released preliminary reports looking at the changing privacy landscape. Although much of the discussion has focused on online data, the reports take a broader look at the privacy practices of organizations both online and offline, offering a number of recommendations that challenge policy makers and companies to better protect consumer information. As regulatory agencies and Congress continue to examine business practices around consumer privacy, I thought it might be helpful to take a look at recent comments Experian filed with the FTC and highlight a few areas that will be important for policy makers to consider going forward. A flexible and adaptive regulatory system is essential to an innovative economy Consumer privacy expectations are continuing to evolve and, as a result, standards must not be rigid. Along with existing regulations, new challenges should be dealt with robust and evolving self-regulation – not new laws – to ensure consumers are protected now and in the future. Consumer privacy should be viewed from multiple perspectives The recent debate around commercial information sharing has centered on consumer privacy; however there are other viewpoints that should be considered. For example, how are businesses using information in a responsible manner to innovate and increase productivity or how does the overall economy benefit from consumer information that makes us more competitive in a global marketplace.   Incorporating consumer privacy into all aspects of a business is a powerful consumer benefit The FTC report recommends a “privacy by design” framework – meaning that companies incorporate privacy into every aspect of their business operations. This framework could potentially evolve into a useful tool for companies to evaluate their privacy and data security policies. In the coming months, we’ll likely see a number of Congressional hearings as federal regulators craft a final privacy report. And in future posts, we’ll explore how the new proposals impact your business.  

February 25, 2011 by Guest Contributor

Exciting research leveraging Experian’s fraud analytics and credit risk modeling are now enabling deposit institutions to understand the impacts of first party fraud and identity theft on their portfolios. Historically, deposit institutions have not considered application fraud to be a major concern and legislation regarding overdraft fees and the opt-in provision for overdraft services will reduce a deposit customer’s ability to spend the bank’s money; however, a determined thief can still: kite checks to commit first party fraud perpetrate an account takeover/identity theft   The result is that deposit institutions will continue to face losses that can be prevented using fraud best practices. The challenge for the institution is knowing whether it is facing first party fraud or identity theft. Increasingly, deposit institutions are turning to Experian to analyze customers that create losses early in the account life cycle in order to make the right modifications to their acquisitions strategies.  Using a combination of fraud analytics built to target specific types of fraud trends, deposit institutions can get a clear picture of the type of behavior that is generating their losses. This type of analysis is quickly climbing the list of fraud best-practices. Armed with the right diagnosis, deposit institutions can respond by prioritizing the right set of fraud alerts.    

February 15, 2011 by Chris Ryan

By: Kristan Frend Imagine you’re on the #1 ranked relay swim team at the World Championships and you’re leading off. You finish your leg of the race with the team in first place. As your third teammate approaches the wall, your team is in first by a full body length. You’re on pace to set a new world record. Yet the anchor of your team is nowhere to be found, ultimately resulting in your team being disqualified.   If only your fourth teammate would have made it to the blocks in time…. When you take a step back and look at your fraud risk management solutions, do you ever feel like you have all of the tools and processes available yet feel like the anchor is missing? Perhaps it’s time to reexamine your internal resources. You may have an assembly of sophisticated and robust online fraud detection tools from vendors, but you may be missing a critical piece if you’re not also effectively leveraging internal data. Through our work with clients, we’re found that it is not uncommon for organizations to manage the customer relationship through different departments or silos within the organization.   All too often there is less than optimal coordination between these functional areas in taking advantage of their own internal negative data to combat application fraud. Additionally some organizations may have negative internal data but do not incorporate the check within their verification or risk based authentication tool, creating multiple steps and operational inefficiencies. One of the ways to overcome some of these issues is by incorporating internal negative data within an automated front-end check.  Once loss data is loaded into a historical database, the next time that name, phone, address, driver’s license or SSN reappears on a new application, the data element is immediately identified as one associated with a previous loss. The negative data is securely stored for only your organization’s use and is not shared with users outside of your organization.

February 11, 2011 by Guest Contributor

For companies that regularly extend credit, the need to establish an identity theft protection program is finally here. After almost two years of delay, the Red Flags Rule is now in force. For readers of the Experian Decision Analytics blog, the Rule has been a familiar topic since passage. If you want to skip ahead to find out what you need to know, we’ve made it easy by boiling it down to three main things. (You’ll find the “3 Things Telcos Should Know About the Rule” towards the end.) However, some background might be helpful to better understand the issues behind the delay. Discussion about Red Flags requirements first began when Congress passed the Fair and Accurate Credit Transactions Act in 2003, requiring the Federal Trade Commission to write and enforce the Rule as the nation’s consumer protection agency. The Red Flags Rule was actually enacted on Jan 1, 2008, but enforcement was delayed until December 31, 2010 to better clarify the terms of compliance and who had to follow them. Why the Red Flags Rule matters A “red flag” is something that signals possible identity theft, including any suspicious activity suggesting crooks might be using stolen information to establish service. The regulation now requires companies to develop a written “red flags program” to detect, prevent and minimize damage that could result from a security breach. Establishing a Red Flags program Companies that regularly extend credit or use consumer reports in connection with a credit transaction need to have a risk-based security program in place. The program must detail the process for detecting red flags, describe how to respond to prevent and mitigate identity theft, and spell out how to keep the program current.   Decision to delay: the definition of “creditor” At the center of the FTC’s decision to delay enforcement was a broad definition Congress gave to the term “creditor.” The Rule broadly captured a number of non-financial companies (many of them small businesses) that didn’t know whether it applied to them, and if they did, didn’t have time or expertise to establish proper procedures to comply. And failure to comply could lead to costly fines or civil actions. New Red Flags exemptions To resolve the issue, Congress approved legislation providing exemptions for businesses that provide goods or services and then accept payment later. The bill redefines the term “creditor” to apply only to businesses that advance funds to, or on behalf of a customer, based upon an obligation to repay. 3 things telcos should know about the Red Flags Rule: 1. Telcos are covered by the Rule For companies, like telcos, that obtain consumer reports, directly or indirectly, in connection with a credit transaction the requirement to comply hasn’t changed. In fact, under regulatory guidance, the FTC specifically lists telecommunications companies among those who need to comply. 2. Your company needs a written Red Flags program The FTC Rule requires that organizations identify and address the “red flags” that could indicate identity theft and update the program periodically. The program must address certain “covered accounts,” which includes a consumer account with frequent transactions or those that have a risk of identity theft.  An annual report must also be created for senior management or the board of directors.   3. How to comply is up to you The good news is that the Rule doesn't require any specific practice or procedures. Companies have the flexibility to tailor compliance programs to the nature of their business and the risks they face. The FTC will assess compliance based upon whether a company is taking “reasonable policies and procedures” to prevent identity theft.    

February 7, 2011 by Guest Contributor

Let’s face it – not all knowledge based authentication (KBA) is created equal. I, too, have read horror stories of consumers forced to answer questions about a deceased relative or ex-spouse, or KBA sessions that went on far too long for anyone’s benefit. I have to attribute this to vendor inexperience and a lack of consulting with clients. An experienced vendor will use a fraud best practice such as a fraud analytics model to determine that some consumers do not even need questions and then a “Progressive Question” feature, which uses consumer performance on an initial question set to determine if it is necessary for the consumer to answer additional questions. This way, the true consumer completes the process quickly, improving the customer experience. The product of choice should also use a question mix that balances three factors: ·         how easily the true consumer can answer the question; ·         the fraud separation of the question (effectively the measured delta over time between how well true consumers answer the question vs. how well fraudsters do); ·         how many consumers overall the question can be generated.  A list of hundreds of possible questions doesn’t mean much if the questions can only be generated for one quarter of one percent of the population, as is the case for something like airplane ownership or pilot’s license. Ultimately, out of wallet questions should be generated for a large part of the population, easily answered by the true consumer but difficult for a fraudster; and not offensive or what a consumer would consider “creepy” (such as their child’s birthday or name). Well designed questions will be personal but not intrusive and mindful of personal relationships that may have changed.  The purpose of a knowledge based authentication session is risk management and/or consumer authentication for fraud prevention and compliance purposes – not to cause the loss of business because the fraud tool crossed the line in the mind of your customer.

February 7, 2011 by Guest Contributor

Experian Decision Analytics has recorded increased demand from the marketplace for service integrations with interactive voice response (IVR), a phone technology that allows for automated detection of both voice and touch–tones. In the past quarter, there has been a more than 70 percent increase in IVR interest and it continues to grow. Why is there a demand for knowledge based authentication through IVR? Besides consumer acceptance of out of wallet questions, there is a dramatic increase in the need for remote authentication and fraud analytics that are accurate, not a burden to the consumer, cost–effective for organizations and part of an overall risk based authentication approach. Consumers stay connected in a number of ways — phone, online, mobile and short message service (SMS) — and are demanding the means to remain safe without compromising convenience. Knowledge based authentication through IVR provides this safety. Organizations must consider all the tools at their disposal to keep consumer data protected while preserving and promoting a positive customer experience. Given the interactive nature of knowledge based authentication, it is quite adaptable to various customer access channels, such as IVR, and it enables full automation of both inbound and outbound authentication calls. We know from both our own experience and from working with clients that consumers are more connected, more mobile and more networked than ever before - and fraud trends demonstrate this increases risk. As consumers continue to expand online profiles and fraud artists continue to seek out victims, successful fraud prevention will become paramount to financial survival. Leveraging products already in use by combining the technology capitalizes on an existing investment and is good business.

January 24, 2011 by Guest Contributor

Cybersecurity is back in the news, thanks in no small part to a number of government reports and developments with WikiLeaks. It’s also becoming increasingly important to businesses and lawmakers alike. Although not a new concern for the telecommunications industry, cybersecurity is quickly becoming a priority for the new Congress as pressure increases to develop a national plan. What should cybersecurity protect? A national cybersecurity plan would likely entail setting baseline security standards to protect critical networks – many of which are run by private organizations. For policymakers, the challenge will be to craft guidelines that protect consumer data and still allowing technological innovation. Last year, we saw a number of legislative proposals debated before Congress that would place new requirements on network infrastructure and strengthen coordination between federal regulators. So far, the proposals have been broad and have only raised additional questions. The hurdle for lawmakers will be addressing how existing data protection laws fit within new proposals in order that businesses do not face over burdensome requirements. Where does the FCC fit in? When it comes to cybersecurity, the role of the FCC is even more undefined – however that’s changing. Last summer, the FCC asked for public comments about the creation of a Cybersecurity Roadmap to identify vulnerabilities to communications networks and to develop countermeasures and solutions to cyber threats. The roadmap was first recommended as part of a broader strategy to create a National Broadband Plan that required the FCC to identify the five most critical security threats and establish a two-year plan to address them. While the Commission has accepted public comments, it’s unclear when a final Roadmap will be introduced. A national breach notification standard As part of a comprehensive plan, policymakers are also looking at what happens after a breach occurs. Currently, 46 states have passed laws requiring companies to notify consumers after a security breach. As a result, policymakers have begun to examine whether a national data breach law is necessary given the varying degrees of consumer notification. The FCC has indicated their support of a uniform law and has recommended that Congress include telecoms in the legislative discussion. Despite the uncertainty, one thing is sure: cybersecurity will be increasingly important to monitor during 2011. One way to stay current is to subscribe via email or RSS as we continue to look at the latest legislative or regulatory developments concerning the wireless and telecommunications industry. In the near future, we’ll be taking a look at recent data privacy recommendations by federal regulators and the privacy agenda of the new Congress. Meanwhile, if you’d like more information on Data Breach Notification or Fraud Management Compliance, your Experian representative can help. Let us know your concerns regarding cybersecurity and pending legislative issues so that we can address them in future posts.

January 24, 2011 by Guest Contributor

Many compliance regulations such the Red Flags Rule, USA Patriot Act, and ESIGN require specific identity elements to be verified and specific high risk conditions to be detected. However, there is still much variance in how individual institutions reconcile referrals generated from the detection of high risk conditions and/or the absence of identity element verification. With this in mind, risk-based authentication, (defined in this context as the “holistic assessment of a consumer and transaction with the end goal of applying the right authentication and decisioning treatment at the right time") offers institutions a viable strategy for balancing the following competing forces and pressures:   Compliance – the need to ensure each transaction is approved only when compliance requirements are met;   Approval rates – the need to meet business goals in the booking of new accounts and the facilitation of existing account transactions;     Risk mitigation – the need to minimize fraud exposure at the account and transaction level. A flexibly-designed risk-based authentication strategy incorporates a robust breadth of data assets, detailed results, granular information, targeted analytics and automated decisioning. This allows an institution to strike a harmonious balance (or at least something close to that) between the needs to remain compliant, while approving the vast majority of applications or customer transactions and, oh yeah, minimizing fraud and credit risk exposure and credit risk modeling. Sole reliance on binary assessment of the presence or absence of high risk conditions and identity element verifications will, more often than not, create an operational process that is overburdened by manual referral queues. There is also an unnecessary proportion of viable consumers unable to be serviced by your business. Use of analytically sound risk assessments and objective and consistent decisioning strategies will provide opportunities to calibrate your process to meet today’s pressures and adjust to tomorrow’s as well.

January 21, 2011 by Keir Breitenfeld

Experian’s Fraud and Identity Solutions team recently conducted a webinar entitled: “A risk-based approach to finding opportunity in today’s market: New approaches to fraud, compliance, and operational efficiency in an evolving economy.” I specifically discussed the current business drivers and fraud trends we, as a consumer and commercial authentication services provider, hear most often from our existing and potential clients. I was encouraged to have the following forces validated by our audience, and I thought they’d be worth sharing with you via this forum. In what I believe to be rank order with most influencing first:   Customer experience is king. The addressable market for most of our clients is effectively an ever more limited pool of viable consumers. From the consumer’s perspective it’s a ‘buyer’s market’. ‘Good’ consumers know they are ‘good’ and those 750 scorers don’t tolerate poor customer service.   Risk seeking credit policies may be making a comeback. Many of our clients are starting to heal from the past few years, and are ready to get back on the bike. However, this does open the door more widely for application fraud activity and risk.     New products and associated solicitations and access channels translate to higher risk as fraud prevention and fraud detection processes may be less robust in the early launch stages and certainly less time-tested.     Human & IT resources are still in short supply. As these new channels open and fraud risk increases, necessary fraud prevention and authentication oriented resources are still overly constrained and often significantly lagging in proportionality behind the recovery-minded marketing minds.     Regulatory pressures continue to equate to higher operational costs, in the form of fraud referral rates, in process engineering and human intervention and activities, not to mention the opportunity costs associated with denial of service to those ‘good’ consumers I just mentioned.     So, hosted services and solutions are where it’s at these days. Our clients want their vendors, including us at Experian, to save their IT resources, deliver quicker to market services, such as fraud models, knowledge based authentication, and other authentication tools, and provide collective capabilities that would otherwise be years away if left to the mercy of their internal development queues.     All products and processes are under review, as you might imagine. Cost control is no longer a back-burner policy and focus. ROI is the key metric these days, and likely above any other. Our clients demand flexible tools that can be deployed in multiple process points and across multiple business units. Blanket policies (including fraud prevention and authentication) are no longer good enough. Our clients’ tailored products, access channels, and market segmentations require the same level of unique design in the products we deliver.    

January 14, 2011 by Keir Breitenfeld

Many compliance regulations such the Red Flags Rule, USA Patriot Act, and ESIGN require specific identity elements to be verified and specific high risk conditions to be detected. However, there is still much variance in how individual institutions reconcile referrals generated from the detection of high risk conditions and/or the absence of identity element verification. With this in mind, risk-based authentication, (defined in this context as the “holistic assessment of a consumer and transaction with the end goal of applying the right authentication and decisioning treatment at the right time") offers institutions a viable strategy for balancing the following competing forces and pressures: Compliance – the need to ensure each transaction is approved only when compliance requirements are met; Approval rates – the need to meet business goals in the booking of new accounts and the facilitation of existing account transactions; Risk mitigation – the need to minimize fraud exposure at the account and transaction level. A flexibly-designed risk-based authentication strategy incorporates a robust breadth of data assets, detailed results, granular information, targeted analytics and automated decisioning. This allows an institution to strike a harmonious balance (or at least something close to that) between the needs to remain compliant, while approving the vast majority of applications or customer transactions and, oh yeah, minimizing fraud and credit risk exposure and credit risk modeling. Sole reliance on binary assessment of the presence or absence of high risk conditions and identity element verifications will, more often than not, create an operational process that is overburdened by manual referral queues. There is also an unnecessary proportion of viable consumers unable to be serviced by your business. Use of analytically sound risk assessments and objective and consistent decisioning strategies will provide opportunities to calibrate your process to meet today’s pressures and adjust to tomorrow’s as well.

January 10, 2011 by Keir Breitenfeld

When we think about fraud prevention, naturally we think about mininizing fraud at application. We want to ensure that the identities used in the application truly belong to the person who applies for credit, and not from some stolen identities. But the reality is that some fraudsters do successfully get through the defense at application. In fact, according to Javelin’s 2011 Identity Fraud Survey Report, 2.5 million accounts were opened fraudulently using stolen identities in 2010, costing lenders and consumers $17 billion. And these numbers do not even include other existing account fraud like account takeover and impersonation (limited misusing of account like credit/debit card and balance transfer, etc.). This type of existing account fraud affected 5.5 million accounts in 2010, costing another $20 billion. So although it may seem like a no brainer, it’s worth emphasizing that we need to continue to detect fraud for new and established accounts. Existing account fraud is unlikely to go away any time soon.  Lending activities have changed significantly in the last couple of years. Origination rate in 2010 is still less than half of the volume in 2008, and booked accounts become riskier. In this type of environment, when regular consumers are having hard time getting new credits, fraudsters are also having hard time getting credit. So naturally they will switch their focus to something more profitable like account takeover. Does your organization have appropriate tools and decisioning strategy to fight against existing account fraud?

January 10, 2011 by Matt Ehrlich

By: Kristan Frend According to the 2011 Identity Theft Assistance Center Outlook (ITAC), new forms of small business identity theft are emerging. This shouldn’t be a surprise that criminals view small business accounts as a lucrative funding source. What is surprising is that the ‘new’ form of small business identity theft consists of the U.S. Postal Inspection Service reporting a surge in criminal rings using small business information from stolen mail, check writing software and other tactics to counterfeit checks. That’s the new wave of small business identity theft??? I consider this one of the least sophisticated types of fraud that can easily be eliminated by small business owners not leaving mail unattended. Reading this report makes me realize that we have a long way to go in identifying and reporting the more sophisticated types of small business fraud.  As I’ve mentioned before, the industry has come a long way in advancing consumer fraud solutions.  Yet, as fraud has migrated into business accounts, we as an industry still have a ways to go in reporting the latest business fraud trends and tracking statistics.  I’m adding this to my wish list for 2011… What’s on your wish list? On a side note, I’ve noticed nearly all of the articles posted in our blog include no reader comments. I’d like to think that this means our readers are too busy to add comments and/or our articles are so well-written that they answer all of your questions. One can dream right? Seriously though, as we approach 2011 and plan our topics, we’d love to hear from you- if you can think of any topic you’d like us to cover more in depth, please let us know.

December 16, 2010 by Guest Contributor

By: Kristan Frend As my colleague Margarita Lim discussed in her December 3rd article, the SSA announced that it will change how social security numbers (SSNs) will be issued, with a move toward a random method of assigning SSNs. For organizations that currently incorporate the validation of an applicant’s SSN issue date and state as a part of their risk-based decisioning, they will lose this piece of applicant authentication post-randomization. But there is some good news - first, this validation piece won’t be entirely terminated on day one of the SSN randomization for organizations. All the change means is that the newly issued SSNs will be randomized. In other words, the only SSNs that the issue data and state won’t be validated on day one are the SSNs that have just been issued to the recently born or immigrants. Given that its likely newborns won’t be applying for credit for another 18 years, the bulk of the newly issued SSNs that organizations will see for a while are those belonging to adults who were recently issued a SSN…A growing number of applicants, but not the majority of applicants. The other bit of good news is this may actually be a good thing for all of us in the long run.   While we’ll end up losing the ability to validate an applicant’s SSN issue data and state, the criminals will be at an even greater disadvantage. Consider this- Last year researchers* were able to “identify all nine digits for 8.5 percent of people born after 1988 in fewer than 1,000 attempts. For people born recently in smaller states, researchers sometimes needed just 10 or fewer attempts to predict all nine digits.” I don’t expect this change to drastically reduce third party fraud rates but over time it should eliminate one component of identity theft and ultimately benefit an organization’s Customer Information Program. *The National Science Foundation, the U.S. Army Research Office, Carnegie Melon Cylab, and the Berkman Faculty Development Fund provided support for the research.  To view the entire study, please visit http://www.pnas.org/content/106/27/10975.full.pdf+html.

December 15, 2010 by Guest Contributor

By: Ken Pruett The majority of the customers I meet with use some sort of Velocity Checks to assist with their Fraud and Compliance process. However, there are still quite a few that do not, especially when opening up New Business Accounts. Historical data checks have proven to be an effective form of identity theft prevention for both Consumer fraud and Commercial Fraud. We see scenarios where a perpetrator will have one successful penetration of a business and opens up a fraudulent account.  They then try and replicate this against the same business. All of the information may be different, with the exception of one element, often the phone number. Without velocity checks, this may not be identified at the time the account is being opened. More sophisticated rings try to be more creative in their fraudulent attempts. They may gain access to a consumers information and then go and apply at a variety of entities. They are more careful, so they never attempt to target the same business twice. They are aware that many companies have velocity checks, so they do not want to take a chance of having their information questioned. At a minimum, the use of in-house velocity checks should be a standard process for you fraud detection measures. Typical data elements to check against are; name (business or consumer), address, phone number, and Social Security Number. A fraud best practice would be to use a tool that provides velocity checks and incorporates the information into a fraud prevention tool. There are tools that provide checks across multiple businesses and this typically provides the best level of protection. By looking at inquiry information across multiple businesses, you are able to help prevent being a victim of some of the more sophisticated rings. Don’t find yourself being the easiest target. Once you get hit, it could snowball and you may be victimized multiple times. We all know there is no way to stop all of the fraud, but let’s not make it too easy on the perpetrators. Try and find a way to use some sort of velocity checks in your process to at least minimize your fraud risk.

December 14, 2010 by Guest Contributor

By: Andrew Gulledge Bridgekeeper: “What is the air-speed velocity of an unladen swallow?” King Arthur: “What do you mean?  An African or European swallow?” Here are some additional reasons why the concept of an “average fraud rate” is too complex to be meaningful. Different levels of authentication strength Even if you have two companies from the same industry, with the same customer base, the same fraudsters, the same natural fraud rate, counting fraud the same way, using the same basic authentication strategies, they still might have vastly different fraud rates.  Let’s say Company A has a knowledge-based authentication strategy configured to give them a 95% pass rate, while Company B is set up to get a 70% pass rate.  All else being equal, we would expect Company A to have a higher fraud rate, by virtue of having a less stringent fraud prevention strategy.  If you lower the bar you’ll definitely have fewer false positives, but you’ll also have more frauds getting through.  An “average fraud rate” is therefore highly dependent on the specific configuration of your fraud prevention tools. Natural instability of fraud behavior Fraud behavior can be volatile.  For openers, one fraudster seldom equals one fraud attempt.  Fraudsters often use the same techniques to defraud multiple consumers and companies, sometimes generating multiple transactions for each.  You might have, for example, a hundred fraud attempts from the same computer-tanned jackass.  Whatever the true ratio of fraud attempts to fraudsters is, you can be confident that your total number of frauds is unlikely to be representative of an equal number of unique fraudsters.  What this means is that the fraud behavior is even more volatile than your general consumer behavior, including general fraud trends such as seasonality.  This volatility, in and of itself, correlates to a greater degree of variance in fraud rates, further depleting the value of an “average fraud rate” metric. Limited fraud data It’s also worth noting that we only know which of our authentication transactions end up being frauds when our clients tell us after the fact.  While plenty of folks do send us known fraud data (thus opening up the possibility of invaluable analysis and consulting), many of our clients do not.  Therefore even if all of the aforementioned complexity were not the case, we would still be limited in our ability to provide global benchmarks such as an “average fraud rate.” Therefore, what? This is not to say that there is no such thing as a true average fraud rate, particularly at the industry level.  But you should take any claims of an authoritative average with a grain of salt.  At the very least, fraud rates are a volatile thing with a great deal of variance from one case to the next.  It is much more important to know YOUR average fraud rate, than THE average fraud rate.  You can estimate your natural fraud rate through a champion/challenger process, or even by letting the floodgates open for a few days (or however long it takes to gather a meaningful sample of known frauds), then letting the frauds bake out over time.  You can compare the strategy fraud rates and false positive ratios of two (or more) competing fraud prevention strategies.  You can track your own fraud rates and fraud trends over time. There are plenty of things you can do to create standardize metrics of fraud incidence, but good heavens for the next person to ask me what our average fraud rate is, the answer is “No.”

December 13, 2010 by Guest Contributor

Subscribe to our Newsletter

Enter your name and email for the latest updates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Subscribe to our Newsletter

Don't miss out on the latest industry trends and insights!
Subscribe