On this page
False-decline reduction with no degradation in catch rate, proven in shadow mode.
Per year in directly attributable P&L, against $90M of restored customer spend.
False declines eliminated per year at the committed 40%.
Audit coverage of scoring decisions.
Challenge
Turn the dial too loose and fraud gets through. Turn it too tight and the bank declines its own customers at the checkout. The bank is asked to do both contradictory things at once: catch more and block less.
- False declines cost the payments industry $213B in 2025. On track for $297B by 2029 (Datos Insights, The Smart Approval Advantage, 2026). On most card portfolios, the revenue lost to wrongly blocked legitimate transactions exceeds the money lost to actual fraud.
- A meaningful share of card declines comes from fraud rules, not from insufficient funds. And the majority of those are false positives. Each one is a lost interchange fee, a sale completed on a competitor's card, and a customer who hesitates before reaching for yours next time.
- The damage compounds downstream. 78% of financial institutions say failed payments critically hurt customer experience, and a third have already lost between 2% and 5% of customers to it (Datos Insights, 2026). Every false decline also seeds a complaint or dispute handled at roughly $10.
- The fraud side is getting more expensive too. US ecommerce and retail merchants now incur an all-in cost of $4.61 for every $1 of fraud, up from $3.16 in 2022 (LexisNexis Risk Solutions, True Cost of Fraud Study, 2025). Issuers do not carry that exact ratio, but they sit on the other side of the same transactions.
- Appetite is not the constraint. 90% of financial institutions already use AI somewhere in fraud and financial-crime prevention, on a survey of 562 practitioners run by the vendor Feedzai in 2025. Any model good enough to move both numbers has to score live payment data at authorization latency, somewhere the security function will approve. That is where these projects stop.
One threshold, pulled both ways
- $213B lost to false declinesIn 2025, and on track for $297B by 2029.
- Fraud rules, not fundsThe majority of those declines are false positives.
- The damage compounds78% say failed payments hurt the relationship.
The decline threshold
Loosen it and fraud lands. Tighten it and customers do.
- Fraud costs more each year$4.61 spent for every $1 of fraud, up from $3.16.
- Appetite is not the blocker90% already run AI somewhere in fraud.
Solution
CreateOS deploys a real-time fraud-scoring agent crew inside the bank's own environment, tuned to cut false declines without loosening the catch rate.
- Scores inside the authorization window. The scoring agent runs as a persistent warm service rather than cold-starting per transaction, so the decision lands in time to matter.
- Behavioural, device, and counterparty signals on every transaction. Genuinely suspicious activity is challenged or blocked. Everything else is approved.
- Every score carries a defensible reason. A declined transaction has the reasoning attached to it rather than a rule number.
- Scoring runs inside a hardware-isolated boundary. Each agent has its own guest kernel, so scoring executes against sensitive payment data without sharing a host.
- Action is bounded in the kernel, not requested of the model. Egress is allowlisted, so the action agent reaches sanctioned payment-system paths and nothing else. An agent that is wrong or manipulated cannot move money, because the path does not exist. VM suspension is the kill switch.
- The fraud model stays the bank's to own and document. Control plane and storage sit inside the bank's own infrastructure and region, so payment data never leaves the boundary. CreateOS is SOC 2 Type II and ISO 27001 certified.
Outcome Derived
The commitment is deliberately asymmetric: a 40% reduction in false declines with no degradation in catch rate, proven in shadow mode before a single live decision.
- 1.8M false declines eliminated a year. At the committed 40%, restoring roughly $90M of legitimate purchase volume and about $2.25M of directly attributable P&L.
- Cutting false alarms only counts if the catch rate holds. A vendor who leads with the false-positive number and stays quiet about the catch rate is selling half a result.
- 100% audit coverage of scoring decisions. Every score is replayable, with unauthorized money movement held at zero and enforced in-kernel.
Modelled on a Representative Mid-Size Card Issuer
| Assumption | Figure |
|---|---|
| Annual card transactions | 500 million |
| Average ticket | $50 |
| Annual purchase volume | $25.0B |
| Overall decline rate | 10% (50M declined transactions) |
| Declines driven by fraud rules | 15% of declines (7.5M) |
| Share of those that are legitimate | 60% (4.5M false declines, 0.9% of all transactions) |
How 4.5 million false declines arise
500M
Card transactions a year
10%
Declined overall
15%
Of those, by a fraud rule
60%
Of those, actually legitimate
4.5M
Good customers refused a year, 0.9% of all transactions
What the bank loses today
- 4.5 million legitimate transactions blocked per year
- $225M in legitimate purchase volume wrongly declined
- Roughly $3.4M in direct interchange forgone, at a blended 1.5% take rate
- Plus the complaint and dispute volume every false decline generates, handled at ~$10 per case
What the agent recovers, at the committed 40%
| Outcome | Figure |
|---|---|
| False declines eliminated | 1.8 million per year |
| Legitimate purchase volume restored | $90M per year |
| Direct interchange recovered | ~$1.35M per year |
| Downstream case-handling avoided | ~$0.9M per year |
| Catch rate | Held flat, proven in shadow mode |
| Unauthorized money movement | Zero, enforced in-kernel |
| Audit coverage of scoring decisions | 100% |
Headline: ~$2.25M per year in directly attributable P&L, against $90M of restored customer spend.
The customer-retention effect sits on top of this and is deliberately kept separate. A third of financial institutions have lost between 2% and 5% of their customers to failed payments (Datos Insights, 2026). Recovering 40% of false declines protects a proportionate share of that base, which on most portfolios is worth more than the interchange line above. We do not headline it, because it is a model rather than a benchmark, and a sharp finance reviewer should discount any number they cannot trace. We size it against the bank's own churn data during the pilot.
The fraud-loss side is treated the same way. Better real-time detection prevents losses before they occur, but the size of that gain depends on the bank's current loss rate, so we validate it in champion-challenger testing on the bank's own transaction history rather than quoting a portable percentage.
What We Would Prove, and How
| We commit to | We validate on your data |
|---|---|
| 40% false-decline reduction | Fraud-loss reduction from improved detection |
| No degradation in catch rate | Customer-retention value of recovered approvals |
| 100% audit coverage of every score | Interchange take rate and downstream dispute volume |
| Zero unauthorized money movement | Peak-concurrency scoring latency |
The first deliverable of the engagement is not the agent. It is the bank's own measured baseline: current false-decline rate, current catch rate, current cost per case. Everything above is then re-run against real numbers, and that baseline becomes the contract's yardstick. It protects both sides.
Highlights
- 40% false-decline reduction with no degradation in catch rate, proven in shadow mode before a single live decision.
- ~$2.25M per year in directly attributable P&L, against $90M of restored customer spend.
- 1.8 million false declines eliminated per year; $90M legitimate purchase volume restored.
- 100% audit coverage of scoring decisions; unauthorized money movement zero, enforced in-kernel.



