Almost every control in a fraud stack is built to answer one question: is this person who they claim to be?

The uncomfortable development of the last few years is that a growing share of losses now happen when the answer is yes. The customer is real. The device is recognised. The credentials are correct. The behavioural profile matches, because it is genuinely them. And the payment is fraudulent anyway, because somebody spent three weeks convincing them to send it.

Forrester's Andras Cser, who runs this coverage, has described the difficulty precisely. Scams involve customers who have been behaving perfectly well right up until the moment they do not, which makes accurate decisioning harder than it has ever been.

That is the structural problem sitting underneath a category most people still think of as chargeback prevention.

What digital fraud management covers

A DFM platform sits in the transaction path and decides, in the time it takes a page to load, whether to approve, decline, or challenge.

Underneath that decision sit several layers. Device intelligence and fingerprinting. Behavioural biometrics, meaning how someone types and moves rather than what they type. Identity signals drawn from email age, phone reputation, and address history. Consortium data, where a network of merchants contributes fraud outcomes so that patterns visible across the network catch what a single merchant would miss. Rules engines for the things you know. Machine learning for the things you do not.

Then the operational half, which buyers consistently underweight. Case management for the analysts who review flagged transactions. Chargeback handling, including representment when a disputed transaction was legitimate. Reporting for the finance function that has to book the losses.

The category has also broadened considerably in scope. Providers that began with card payment fraud now cover account takeover, promotion and policy abuse, items-not-received claims, refund fraud, and increasingly cryptocurrency and peer-to-peer payment flows.

Two categories, two sides of one transaction

Forrester runs a separate evaluation called enterprise fraud management, and confusing the two produces a badly built shortlist.

Enterprise fraud management is defined around integrating data from multiple payment and non-payment transaction processing systems, online portals, and threat intelligence sources, delivering transaction monitoring, risk scoring, case management, and reporting across online and offline and payment and non-payment activity.

Read carefully and the difference is who is asking. EFM is built for the institution holding the account, typically a bank, covering both digital and physical channels and frequently sitting next to anti-money-laundering obligations. DFM is built for the business accepting the payment, typically a merchant, and lives almost entirely online.

Same fraudulent transaction. Two different customers, two different regulatory contexts, two different definitions of a good outcome. A bank wants to avoid reimbursing a loss and failing an examination. A merchant wants to ship the order.

Several vendors compete in both and place differently in each. Sift was named a Leader in the digital fraud management evaluation and a Strong Performer in the enterprise fraud management one, which is a reasonable illustration of how little the tiers transfer.

The number that should govern the purchase

Here is the thing that separates people who have run fraud operations from people who have bought fraud software.

Fraud loss is visible. It arrives as chargebacks, as written-off transactions, as a line in a monthly report. It is measurable, attributable, and painful.

False declines are invisible. A legitimate customer gets refused, feels insulted, and buys the same thing somewhere else. Nothing lands in a report. Nobody is blamed. And in most merchant portfolios the revenue lost this way substantially exceeds the fraud that was prevented.

Which means the optimisation target is not minimising fraud. A fraud rate of zero is trivially achievable by declining everything. The target is maximising approved good transactions net of fraud loss, and those are different objectives that pull in opposite directions.

This matters when evaluating vendors because every platform will demonstrate its detection rate. Fewer will lead with their false positive rate, and fewer still will let you test both against your own historical transaction data with known outcomes. That test is the only one that predicts what the platform will do to your business.

Inside The Forrester Wave: Digital Fraud Management, Q3 2023

The evaluation scored fifteen providers against twenty two criteria.

Two Leaders. LexisNexis Risk Solutions took the highest possible score in thirteen of the twenty two criteria, including user management, rule management, statistical decisioning, customer authentication policies, integration, vision, roadmap, community, and innovation, with Forrester noting strength in both rule-based and AI-based risk scoring alongside behavioural biometrics. Its capability set reflects a decade of acquisition, with behavioural biometrics and email intelligence folded in to strengthen the authentication signal set.

Sift entered the Leaders for the first time, with top scores in chargeback management, non-payment fraud and policy abuse, roadmap differentiation, integrations, and community. Its trajectory is worth noting as a description of where the category went: it started as a retail-focused card payment tool for merchants and expanded into a full fraud platform covering cryptocurrency and peer-to-peer payments.

Six Strong Performers: Kount, TransUnion, Signifyd, Accertify, Forter, and Outseer.

Seven Challengers: Riskified, Experian, Cybersource, HUMAN, Radial, Appgate, and Callsign.

The spread there is instructive. This is not a market where the Challengers are weak products. Several of them are strong at something specific, chargeback guarantee models, bot mitigation, or authentication, and were being scored against a criteria set that rewarded breadth.

The inclusion criteria describe the market

As with several Forrester categories, the entry requirements tell you more than the scores.

To qualify, a vendor needed purpose-built chargeback management, support for flexible user authentication policies, and investigator-centric case management. It needed e-commerce and retail among its top three verticals. And it needed at least thirty million dollars in product revenue.

The vertical requirement is the revealing one. It means this evaluation deliberately centres the merchant use case, which is why several capable fraud vendors serving banks and telcos do not appear. If your fraud problem is not primarily a commerce problem, this is not the right document to shop from.

The case management requirement is the practically useful one. Investigator-centric is doing real work in that phrase. A platform can score transactions brilliantly and still be miserable for the analyst who has to work four hundred queued cases a day, and that experience determines your actual operating cost far more than the model does.

Why scams break the model

The expansion Cser described, from payment transactions into account takeover, scams, and policy abuse, is not just scope creep. It reflects a shift in how fraud is committed.

Working through individual stolen card numbers is inefficient. Taking over an established account with saved payment methods, order history, and a trusted profile lets an attacker transact repeatedly at scale before anything looks unusual. The economics favour it, so attackers moved.

Authorised scams go one step further and remove the attacker from the transaction entirely. Investment scams, romance scams, invoice redirection, purchase scams. The victim initiates the payment themselves, from their own device, on their own network, after passing every authentication challenge the institution can throw at them.

There is no signal in the transaction. The signal, if it exists, is in the pattern preceding it: an unusual payee, an account that suddenly starts behaving like it belongs to a different person, a customer who is on a phone call while making a transfer they have never made before.

Detecting that is a fundamentally different capability from verifying identity, and it is the axis on which this category will be judged for the next several years. The regulatory pressure is real too, with reimbursement obligations for authorised push payment fraud tightening in several jurisdictions, which converts a customer service problem into a balance sheet problem.

When evaluating vendors, ask specifically what they do about scams as distinct from fraud. The answers separate quickly.

Where the 2023 research has aged

Three years is a long time in this market, and the Q3 2023 Wave predates several things that now shape it.

Generative AI changed the attacker's cost structure. Convincing text at scale, voice cloning capable of defeating phone-based verification, and synthetic media good enough to pass document checks all became cheap in the period after this evaluation. Social engineering used to be labour-intensive, which limited its volume. That constraint is gone.

Synthetic identity fraud scaled correspondingly. Fabricated identities assembled from real and invented elements, nurtured over months to build credit history, defeat controls designed to detect stolen identities because there is no victim to report anything.

And agentic commerce is arriving, where software transacts on a consumer's behalf. Every behavioural signal in these platforms assumes a human at a keyboard. An agent buying legitimately on behalf of a real customer looks, to a behavioural model, exactly like automation attacking an account.

The vendor set from 2023 remains a fair map of who is serious in this market. Treat the tiers as historical and ask each vendor directly about deepfakes, synthetic identity, and agent-initiated transactions, because those answers are newer than the research.

What to test

Backtest against your own data. Take twelve months of historical transactions with known outcomes, run them through the platform, and compare both what it would have caught and what it would have wrongly declined. Every other test is a proxy for this one.

Ask about consortium data honestly. Network effects are real in this category, and a vendor with visibility across many merchants genuinely sees patterns a single merchant cannot. But ask what data you contribute, what you get back, and whether your competitors are in the same consortium. The answers vary more than the marketing suggests.

Sit with an analyst using the case management interface. Not a demo of it. The economics of a fraud operation are dominated by review time per case, and interface quality moves that number more than model accuracy does.

Establish who owns the rules. If every threshold change requires a vendor ticket, you cannot respond to an attack in progress, and attacks in this category arrive over hours rather than quarters.

And model the commercial structure carefully. Chargeback guarantee arrangements, where the vendor assumes liability for approved transactions that turn out fraudulent, are attractive and change the incentive structure completely. A guaranteeing vendor is optimising its own loss ratio, which is close to your interest but not identical to it, and the gap shows up as declines you would rather have approved.

Analyst Source

Forrester Research

Category definition, inclusion criteria, vendor placement, and market framing in this article draw on Forrester's coverage of digital fraud management, led by VP and principal analyst Andras Cser. Forrester evaluates the adjacent enterprise fraud management market separately, including a dedicated Asia Pacific evaluation.

Source research

Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.