Skip to content

Work / ŌURA

ŌURA · 2024 – present · owned end to end

Challenge instead of decline.

A 3DS and SCA step-up pipeline. A fraud flag is a question, not a verdict. $59.6M GMV recovered in seven months.

Recovered
$59.6M GMV
7 months
Challenge conversion
57%
flagged orders that authorized
Liability shift
65.6%
of challenged volume

The problem

Checkout was losing good orders. The fraud stack (Kount 360, Forter, hCaptcha) is supposed to stop stolen cards. It was also stopping customers. The default path was decline. Decline is safe. Decline is also expensive.

The decision

Step up instead. If the risk engines flag an order, challenge the cardholder under 3DS and SCA. Keep the PAN out of our PCI scope. Measure conversion and liability shift, not just fraud rate. A flag is an input to a control loop. It is not a chargeback.

The system

Fraud signals in. Challenge out. 3DS where the card and issuer support it. Email OTP as a second layer when we need a challenge that is not bound to a single processor. That layer recovered $64.6K in the first two weeks. 91.5% end-to-end completion. 99.1% submit-to-verify.

The card lives in Basis Theory. Adyen and Braintree run the authorization. Webhooks are idempotent: a retry is not a second charge, and a second challenge completion is not a second order. We did not expand PCI scope to buy a second processor.

What $59.6M means

GMV of card orders the fraud stack would have declined, subsequently authorized through 3DS, over seven months. It is not profit. It is not a claim that every recovered order is a perfect incremental counterfactual. It is the money that was about to be a decline and became an authorization.

What I still watch

Abandon on challenge. Issuer timeout. Soft declines after a passed challenge. Chargebacks on the recovered cohort versus baseline. Those are the next questions I ask in any payments room. Recovery that manufactures fraud is not recovery.