Work / ŌURA
ŌURA · 2024 – present · owned end to end
Challenge instead of decline.
A 3DS and SCA step-up pipeline. A fraud flag is a question, not a verdict. $59.6M GMV recovered in seven months.
- Recovered
- $59.6M GMV
- 7 months
- Challenge conversion
- 57%
- flagged orders that authorized
- Liability shift
- 65.6%
- of challenged volume
The problem
Checkout was losing good orders. The fraud stack (Kount 360, Forter, hCaptcha) is supposed to stop stolen cards. It was also stopping customers. The default path was decline. Decline is safe. Decline is also expensive.
The decision
Step up instead. If the risk engines flag an order, challenge the cardholder under 3DS and SCA. Keep the PAN out of our PCI scope. Measure conversion and liability shift, not just fraud rate. A flag is an input to a control loop. It is not a chargeback.
The system
Fraud signals in. Challenge out. 3DS where the card and issuer support it. Email OTP as a second layer when we need a challenge that is not bound to a single processor. That layer recovered $64.6K in the first two weeks. 91.5% end-to-end completion. 99.1% submit-to-verify.
The card lives in Basis Theory. Adyen and Braintree run the authorization. Webhooks are idempotent: a retry is not a second charge, and a second challenge completion is not a second order. We did not expand PCI scope to buy a second processor.
What $59.6M means
GMV of card orders the fraud stack would have declined, subsequently authorized through 3DS, over seven months. It is not profit. It is not a claim that every recovered order is a perfect incremental counterfactual. It is the money that was about to be a decline and became an authorization.
What I still watch
Abandon on challenge. Issuer timeout. Soft declines after a passed challenge. Chargebacks on the recovered cohort versus baseline. Those are the next questions I ask in any payments room. Recovery that manufactures fraud is not recovery.