Risk analysis

Shopify Fraud Analysis: Reading the Recommendation and the Individual Signals

Computer security lock and payment.
Photo: Shopify Photos / Burst

Read Shopify's overall fraud recommendation and its individual signals as different layers of information. A reassuring address check does not cancel a concerning payment pattern, and an indicator grouped under high-risk signals is not itself the overall order recommendation. Your first job is to understand what each field says before turning the findings into a merchant decision.

A useful review produces a short explanation of the order: the displayed recommendation, the important supporting observations, any conflicting facts, and the questions still unanswered. It should not produce a homemade probability that Shopify never supplied or a verdict based on counting green and red indicators.

Separate the recommendation from its inputs

Shopify distinguishes the overall recommendation from individual indicators in its fraud-analysis documentation. Record both. Copying only the most alarming signal into an internal note makes it difficult for the next reviewer to understand the actual context.

Treat an indicator as an answer to a limited question. A billing check addresses particular payment information. An IP observation describes a connection associated with checkout. A multiple-card observation concerns payment attempts. None of these alone tells you whether the merchant can meet the delivery promise or whether a customer will later dispute product quality.

The recommendation also has a scope. It concerns fraud risk; it is not a guarantee that every aspect of the order is satisfactory. Keep service issues in their own fields. A low-risk order can still have an unavailable item, a misleading arrival expectation, or a support problem that needs action.

Read conflicts without inventing a scoring system

Use a worksheet with four columns: displayed fact, what it can help explain, what it cannot establish, and unresolved question. This prevents staff from treating an observation as stronger evidence than it is.

Displayed fact Useful interpretation Limit
Billing check passes Particular billing information matched the check Does not establish every aspect of authorization
Connection location differs Checkout connection deserves contextual review Does not locate the person with certainty
Several cards were attempted Payment sequence needs explanation Does not prove all retries were malicious
Existing order history Prior purchasing context is available Does not make this purchase identical to earlier ones

Do not assign arbitrary points and call the total Shopify's risk score. If the store maintains its own review rules, label them as merchant rules and document why they exist. A rule can direct a case to review without pretending to recreate the platform's recommendation.

Three hypothetical orders

In the first hypothetical order, the overall recommendation is low, the billing check is reassuring, and the connection location differs from the delivery country. The useful note is: “Low overall recommendation; connection geography differs; no explanation yet recorded.” A reviewer can investigate context without rewriting the order as high risk based on geography alone.

In the second, the recommendation is high even though the CVV result is reassuring. Several card attempts appear in the sequence. The useful note preserves both: “High overall recommendation; CVV result reassuring on the recorded check; multiple attempts require sequence review.” It would be misleading to write “CVV passed, therefore safe.”

In the third, the overall recommendation is medium, a prior customer relationship exists, and the order requests a new destination. The relevant conflict is between familiar history and changed current facts. The review should identify which earlier facts still apply and which need fresh consideration. It should not assume that a customer label authenticates a new destination or payment.

These examples are invented. They demonstrate interpretation, not Shopify's algorithm or a formula for changing risk levels. The subsequent hold, release, or cancellation decision needs its own documented merchant process.

Write an interpretation another employee can use

Use this reusable note:

Order reference: [reference]. Review time: [time]. Overall recommendation displayed: [value or unavailable]. Material signals: [factual observations]. Conflicting context: [specific difference]. Information absent: [field or fact]. Questions for the decision owner: [questions]. Source checked: [Shopify order or relevant provider record].

Keep the language neutral. Write “customer supplied a different destination” rather than “customer tried to redirect stolen goods” unless the latter is independently established. Observations are useful; unsupported accusations can distort the next decision.

Use Shopify's fraud-review guidance when locating the supported review context. Restrict access to customer information to staff who need it, and avoid copying unnecessary personal details into a broad operations channel.

Before handing the order onward, ask whether the note distinguishes facts from explanations. Has an unavailable check been mistaken for a pass? Has a customer statement been labeled as confirmed authorization? Has a low recommendation hidden a separate fulfillment issue? Correct those interpretation errors before the decision owner assesses what the merchant should do with the order.

Explore how Lower Chargeback presents Shopify risk signals for merchant review.

Explore risk visibility

Related reading in this collection:

  • Shopify Fraud Analysis Is Missing or Pending: What Your Team Should Do
  • An Address Change After Payment: When to Reopen the Fraud Review