The ideal amount of fraud is not zero

Fraud control has an [[optimal-error-rate|optimal error rate]]: beyond a point, catching more abuse destroys more legitimate activity than the remaining abuse costs. The target should preserve the system’s purpose, not satisfy the fantasy of zero fraud.

Suppose an AI could drive a credit-card company’s fraudulent transactions from 2–3% to zero. That sounds irresistible—until you ask how: the surest way to eliminate fraud is to approve no transactions at all.

R1

Every fraud filter is also a trust filter

Fraud prevention separates suspicious transactions from legitimate ones, but the boundary is imperfect. Increase sensitivity—the share of fraud caught—and the filter usually rejects more genuine customers too. Those false positives create their own losses: abandoned purchases, inconvenience, and less trust extended through the system.

The real calculation therefore has two cost curves. Fraud that slips through costs money; controls cost money and suppress legitimate activity. Tightening the filter helps only until the next unit of prevention costs more than the abuse it removes. Zero is not an optimum merely because it is a morally satisfying number.

E1 R1

Where it shows up

The declined honest purchase

A payment system can catch more stolen-card transactions by becoming more suspicious, but some real transactions will be blocked with them. The relevant score is not fraud caught in isolation; it is fraud caught without making the payment network unusable.

E1

Trust with a loss budget

Fraud is an abuse of trust, so abolishing it completely requires abolishing trust completely. Different businesses can rationally tolerate different loss rates because convenience, transaction value, and the cost of a mistaken rejection differ.

R1

Tolerance is not indifference

A nonzero optimum is not permission to ignore preventable abuse. If fraud threatens the system’s survival, concentrates severe harm on vulnerable people, or can be reduced cheaply without blocking legitimate use, stronger controls are justified. The claim is about marginal trade-offs, not moral acceptance.

Give the filter two price tags

For one rule you operate tomorrow—payment screening, access approval, spam filtering—record both what a missed bad case costs and what a rejected good case costs. Set the threshold by minimizing their combined damage, then name the tolerated error rate explicitly.

Episodes that teach this