Shopify fraud analysis is a built-in risk-scoring system that evaluates every incoming order against payment, location, device, and behaviour signals — then assigns it a low, medium, or high fraud risk level before you fulfil anything.
For South African merchants running card-based checkouts, that signal is worth understanding clearly: SA card fraud losses reached R1.466 billion in 2024, a 26.2% rise year-on-year, with card-not-present (CNP) transactions — exactly the kind your online store processes — driving the bulk of that increase according to SABRIC data cited by Stitch Money. Understanding what Shopify's tool is telling you, and what to do about it, is a practical operating skill — not an optional extra.
This guide is for Shopify store owners and operators who want to read risk signals correctly, build a workable response workflow, and reduce the compound cost of fraud without blocking the legitimate customers who fund the business. It links to the Shopify South Africa pillar for wider platform context, and covers the payment gateway detail that makes SA fraud risk genuinely different from the global defaults in Shopify's own documentation.
Quick Answer
Shopify fraud analysis scores every order as low, medium, or high risk using machine learning trained across all stores on the platform. Low-risk orders can generally be fulfilled without additional verification — though an unusually large first order or external fraud signals (such as a known-bad email domain) still warrant a quick check. Medium-risk orders should be verified with the customer before shipping; high-risk orders warrant a hold, investigation, or cancellation.
Because Shopify Payments is not available in South Africa, 3D Secure authentication depends entirely on your chosen payment gateway — PayFast and Peach Payments both carry 3DS2, while bank-transfer methods like Ozow are structurally immune to chargebacks. Reading fraud signals well, and automating your response with Shopify Flow, cuts both fraud losses and the time cost of manual review.
In This Guide
How Shopify Fraud Analysis Works
The Three Risk Levels and What They Tell You
Reading Risk Signals in a South African Context
A Decision Framework for SA Merchants
Getting more high-risk flags than feels right?
Send us your current Shopify setup and we'll review where your payment flow and fraud settings may be creating unnecessary friction for good customers.
Get a free flow reviewHow Shopify Fraud Analysis Works
Shopify fraud analysis is a machine-learning system trained on historical transactions across all stores on the platform — it is not a simple rule set. Shopify fraud detection operates at the order level: when an order arrives, the system evaluates a set of fraud indicators and produces both a risk recommendation and a set of colour-coded signals for your review.
The indicators the system checks fall into five categories:
| Indicator Category | What It Checks | Why It Matters |
|---|---|---|
| AVS (Address Verification System) | Whether the billing address entered at checkout matches the address on file with the card issuer | A mismatch is the single most common fraud signal — also common in legitimate gift orders |
| CVV (Card Verification Value) | Whether the customer provided the correct three- or four-digit security code | Stolen card numbers often circulate without the CVV; failure here raises risk sharply |
| Location alignment | Whether the customer's geographic location matches the origin of the payment method | A Johannesburg IP placing an order with a UK card billing address is an elevated signal |
| Device and network patterns | Whether an anonymous proxy or VPN is in use; whether activity is unusual for the device | Proxy use combined with a location mismatch is the strongest compound signal |
| Order velocity | Whether the same customer, device, or card has placed multiple orders in quick succession | Rapid-fire orders on slightly different card numbers are a classic card-testing pattern |
Crucially, no single indicator determines the overall risk level. A single AVS mismatch on an otherwise clean order often produces a low or medium score; an anonymous proxy combined with both an AVS and CVV failure is almost always high. The system weighs the combination, not the individual flag.
Indicators appear in the order detail view colour-coded: signals associated with fraudulent behaviour are marked negatively, signals associated with legitimate behaviour positively, and neutral details appear separately for context. The overall recommendation — Shopify's summary verdict — sits at the top of the fraud analysis panel for that order.
Key Point
Shopify's fraud analysis is a prompt to verify, not a verdict to execute blindly. One industry analysis estimated that roughly 5% of legitimate orders receive a false positive flag — blanket auto-cancellation of every flagged order would forfeit real revenue. The risk system is a triage tool; your workflow decides what happens next.
The Three Risk Levels and What They Tell You
Shopify expresses its fraud assessment as one of three risk levels, each carrying a specific recommendation from the platform. Understanding what the platform is actually saying at each level prevents both over-reaction and under-reaction.
| Risk Level | Shopify's Recommendation | What It Means in Practice |
|---|---|---|
| Low | "You can fulfill this order" | No significant fraud signals detected. Proceed with normal fulfilment — no additional verification needed. |
| Medium | "Confirm with the customer before fulfilling" | At least one fraud indicator is present but the overall pattern is inconclusive. Hold fulfilment until you verify the customer is real. |
| High | "Consider canceling this order" | Multiple compounding signals detected. The order carries a meaningful probability of being fraudulent — investigate, contact the customer, or cancel before shipping. |
Medium-risk orders require a judgement call. A single AVS mismatch on a large gift order from a new customer with matching CVV and a local IP might be entirely legitimate — someone has simply moved house and not updated their bank details. A medium-risk flag on a first-time order for a high-value electronics product from an address three provinces from the billing city deserves more scrutiny.
High-risk orders are not automatically fraudulent. They warrant a pause and a question. Contacting the customer via a channel independent of the order (phone number from the account, not from the order itself) and asking them to confirm the purchase detail is usually enough to distinguish a legitimate order from a fraudulent one within minutes.
Reading Risk Signals in a South African Context
Ecommerce fraud analysis in South Africa has a distinct profile from global defaults: several features of the local market mean that some flags fire more frequently here than Shopify's official fraud analysis documentation might suggest — and some of the highest-risk signals you will see are shaped by the SA payment gateway landscape.
Location mismatches are structurally more common in SA
South Africa has significant internal migration patterns and a large percentage of workers whose registered bank addresses differ from their current location. A Limpopo-issued card billing address on a Johannesburg-based delivery is not inherently suspicious — it is routine. This means location mismatch signals fire more often on legitimate SA orders than on equivalent orders in markets with more stable residential registration.
CNP fraud makes online merchants the primary target
Card-not-present fraud — the category that encompasses every online transaction — accounts for 68% of gross card fraud losses in South Africa according to SABRIC data via Netcash, and 85.6% of gross fraud losses specifically on SA-issued credit cards per SABRIC's 2024 data cited by RCS Group. Online store owners are the merchants most directly exposed. The practical implication: your fraud flag rate will be higher than physical retail's, and your exposure when a flag is missed is immediate — goods ship before any dispute lands.
The cost of getting it wrong runs deeper than the order value
A 2023 LexisNexis True Cost of Fraud study found that South African retailers absorb an estimated R3.10 in total costs for every R1 of direct fraud loss — covering internal labour for dispute management, investigation costs, fees, and merchandise that cannot be recovered. On a R2,000 order, the total estimated cost of shipping a fraudulent order is R6,200 in cumulative losses, not R2,000. That multiplier is the reason a few minutes of manual verification on a high-risk order is worth every second.
No Shopify Payments means 3DS2 is gateway-dependent
Because Shopify Payments is not available in South Africa, the 3D Secure 2 (3DS2) authentication layer — which shifts chargeback liability back to the issuing bank on verified transactions — only applies where your chosen gateway implements it. PayFast and Peach Payments both carry 3DS2 authentication. If you are running a gateway that does not, your store carries full chargeback liability on every card-not-present transaction. Shopify's fraud analysis scores remain useful regardless, but 3DS2 coverage on your gateway reduces the volume of chargebacks you will face even when analysis misses a fraudulent order.
A Decision Framework for SA Merchants
Shopify fraud analysis gives you a risk level — what you do next is the operator's call. A consistent decision process for each level prevents both the revenue loss of over-rejection and the fraud loss of under-scrutiny. The table below maps each risk level to practical SA operator actions.
| Risk Level | Default Action | Escalate if… | Cancel if… |
|---|---|---|---|
| Low | Fulfil normally | Order is unusually large for a first-time customer | Other external signals raise concern (e.g. known fraudulent email domain) |
| Medium | Pause fulfilment; contact customer via phone or WhatsApp to confirm order details | Customer is unresponsive after 4 hours on a time-sensitive shipment | Customer changes delivery address, provides inconsistent details, or does not respond within your SLA window |
| High | Hold payment capture; do not ship; attempt phone verification | Customer provides plausible explanation and matches account history | No contact made within 24 hours, or verification fails on two or more details |
Build your verification SLA into your fulfilment workflow explicitly. A 4-hour window for medium-risk orders and 24 hours for high-risk orders gives legitimate customers a fair chance to respond while keeping your fulfilment timeline viable. Documenting the outcome of every manual review — a simple internal tag in Shopify — creates a shopify order risk analysis record that helps you calibrate your thresholds over time.
The High-Risk Contact Script
When calling or messaging on a high-risk order: confirm the order total, the delivery address, and ask the customer to name one product in the cart — three facts a legitimate buyer knows instantly. A fraudster rarely has this information to hand. Keep the call under three minutes. If details match, fulfil. If they do not, cancel.
Managing High-Risk Orders Automatically
Shopify Flow lets you automate your response to shopify fraud analysis results so that high-risk orders trigger a workflow the moment analysis completes — without waiting for a staff member to notice a flag in the orders list. One critical implementation detail separates stores that get this right from those that do not.
Use the correct trigger
Fraud analysis in Shopify takes a short time to process after an order is created. Workflows built on the "Order risk analyzed" trigger wait for the analysis to complete before firing — workflows built on "Order created" fire before the risk score exists. Using the wrong trigger means every workflow runs on a null risk level, effectively bypassing your fraud automation entirely. Use "Order risk analyzed" as your Flow trigger without exception.
Recommended Flow setups for SA merchants
| Workflow Name | Trigger | Condition | Actions |
|---|---|---|---|
| High-Risk Hold | Order risk analyzed | Risk level = High | Hold payment capture; tag order "fraud-review"; send internal email to operations team |
| High-Risk Auto-Cancel | Order risk analyzed | Risk level = High AND order value < threshold you set | Cancel order; restock items; tag customer; send cancellation email |
| Medium-Risk Alert | Order risk analyzed | Risk level = Medium AND order value > threshold | Send internal Slack/email alert; tag order "verify-customer" |
The distinction between the Hold workflow and the Auto-Cancel workflow matters. For high-value orders, holding payment capture and reviewing manually protects you from cancelling a large legitimate order based on an algorithm score. For low-value orders where the cost of manual review exceeds the order value, automated cancellation is economically rational. Set your value threshold deliberately — do not apply the same automation to a low-value order and a high-value one.
Ready to build a fraud workflow that fits your store?
Tell us your current setup — order volumes, payment gateway, and average basket size — and we will map the right Flow configuration for your risk profile.
Book a Shopify strategy sessionHow SA Payment Gateways Change Your Risk Equation
Because South African Shopify stores must use a third-party payment gateway, your fraud exposure and chargeback liability profile are shaped directly by which gateway you run. Shopify's fraud analysis scores apply equally regardless of gateway, but the downstream consequences of a fraudulent order differ significantly.
| Gateway Type | 3DS2 Status | Chargeback Liability | Fraud Analysis Relevance |
|---|---|---|---|
| PayFast (card) | Yes — 3DS2 built in | Shifts to issuing bank on 3DS2-verified transactions | High — 3DS2 reduces but does not eliminate chargebacks; analysis still needed |
| Peach Payments (card) | Yes — 3DS2 available | Shifts to issuing bank on verified transactions | High — same dynamic as PayFast |
| Ozow / bank EFT | Not applicable | Irrevocable — confirmed bank transfers cannot be charged back | Lower for chargeback risk; account fraud (stolen banking credentials) remains a concern |
| Other card gateways without 3DS2 | No | Merchant bears full chargeback liability on all CNP transactions | Critical — fraud analysis is your primary and only automated defence |
The structural immunity of bank-transfer EFT (such as payments through Ozow) to conventional chargebacks is a genuine risk-reduction lever for SA merchants. A customer who pays via instant bank transfer cannot dispute the charge the way a cardholder can — the payment is irrevocable once confirmed. Offering EFT as a checkout option does not eliminate fraud risk (account takeover fraud is a separate exposure), but it does eliminate the chargeback liability that makes card-not-present fraud so costly for merchants.
Consider your payment method mix in the context of your fraud exposure. Stores selling high-value electronics or limited-release products — categories with elevated fraud rates — benefit from promoting EFT options and making them friction-low at checkout. Stores with lower average order values and strong repeat customer bases may find that 3DS2 on a card gateway provides sufficient protection without the checkout conversion trade-off of additional authentication steps.
The SA Fraud Landscape in a Single Paragraph
South African retailers face a concentrated card-not-present fraud problem: SA card fraud losses hit R1.466 billion in 2024, with CNP transactions accounting for the majority of losses. The cost to a retailer goes well beyond the order value — a 2023 LexisNexis study estimated SA retailers absorb R3.10 in total costs for every R1 of direct fraud loss. Because Shopify Payments is unavailable locally, 3DS2 depends on your gateway; Ozow-style bank transfers remove chargeback liability entirely. Shopify's fraud analysis is a useful first filter — but gateway choice and a clear response workflow are what actually control your risk.
Why South African Shopify Stores Work with Growth Pulse Media
Shopify fraud prevention and payment gateway configuration work better when the person setting up your store has made the same operational calls on real South African orders — that is the specific experience Growth Pulse Media brings to each engagement. Founder Dirk van Greuning built and scaled a large South African ecommerce business before founding the agency, and works as a registered Shopify Partner based in Johannesburg.
The agency runs a limited client load so that every store receives senior attention, not a junior account manager working from a template. Work is executed in-house across Shopify setup, email automation (Omnisend Certified Partner), paid acquisition on Meta and Google, and organic search — so the fraud and payment configuration decisions made for your store sit inside a broader commercial strategy rather than in isolation.
If you are setting up a new Shopify store, reviewing your payment gateway configuration, or want help building Shopify Flow fraud automation that fits your actual order volume and product category, the Shopify marketing agency page covers what a working engagement looks like in practice.
Who This Is NOT For
Not sure which fraud gaps your store has?
Share your current gateway and Shopify plan and we will identify the specific chargeback and CNP exposure points in your checkout setup.
Get a free auditFrequently Asked Questions
What does it mean when Shopify marks an order as high risk?
A high-risk Shopify order has triggered multiple fraud indicators simultaneously — typically a combination of AVS and CVV mismatches, an anonymous proxy or VPN, and a mismatched location between the customer's IP and their billing address. Shopify's recommendation is "consider canceling this order," but high risk does not mean definitely fraudulent. Hold the order, attempt to contact the customer by phone to verify the purchase details, and cancel only if the customer cannot confirm basic order facts or does not respond within your review window.
Can Shopify fraud analysis catch all fraudulent orders?
No fraud analysis system — Shopify's or any other — catches every fraudulent order. Machine-learning scores are probabilistic, not deterministic. One widely cited industry estimate puts the false-negative rate (fraudulent orders that pass with low risk) at a non-trivial level, and sophisticated fraud operations specifically engineer orders to avoid triggering standard signals. Shopify's analysis is a useful first filter that catches the majority of fraud attempts; it works best in combination with 3DS2 on your payment gateway and a clear manual review process for flagged orders.
How does 3D Secure affect Shopify's fraud risk levels in South Africa?
3D Secure and Shopify's fraud analysis are separate layers. 3DS2 is a transaction authentication step at the gateway level — when the card issuer verifies via 3DS2, chargeback liability shifts to the issuing bank rather than your store. Shopify's fraud analysis evaluates order signals independently of gateway, and because Shopify Payments is unavailable in South Africa, 3DS2 only applies if your chosen gateway (PayFast, Peach Payments) implements it. A 3DS2-authenticated order that Shopify scores high risk still warrants investigation — but any resulting chargeback will typically be handled by the bank, not your store.
Should I cancel every high-risk order automatically?
Blanket auto-cancellation of all high-risk orders is not recommended. A portion of high-risk orders are legitimate, and cancelling them damages the customer relationship and forfeits revenue. The better approach is to auto-cancel high-risk orders below a value threshold you set — where the cost of manual review exceeds the order value — and hold high-risk orders above that threshold for manual verification. Configure this using Shopify Flow with the "Order risk analyzed" trigger and separate workflows for different value bands.
What SA payment method reduces chargeback risk the most?
Bank EFT payments processed through instant-payment gateways such as Ozow are irrevocable once confirmed — customers cannot initiate a chargeback on a completed bank transfer the way they can dispute a credit or debit card charge. This makes EFT the payment method with the lowest chargeback exposure for SA merchants. Card payments through PayFast or Peach Payments with 3DS2 enabled offer meaningful chargeback liability reduction on authenticated transactions, but they do not eliminate chargebacks entirely. Promoting EFT as a checkout option alongside a 3DS2-enabled card gateway gives your store the broadest fraud coverage.
Build a Shopify Fraud Setup That Actually Protects Your Revenue
Growth Pulse Media is a registered Shopify Partner based in Johannesburg. We configure payment gateways, Shopify Flow fraud automation, and checkout flows for SA merchants who need a setup that works for local payment methods, local fraud patterns, and local customer behaviour. All work is executed in-house by senior operators — no juniors, no subcontractors.
No obligation — we will get back to you within 24 hours.
Talk to a Shopify specialist

