Skip to main content
Category: Fraud Detection Analytics

Manual Review

Also known as: Manual Order Review, Human Review
Simply put

Manual review is when a human analyst examines a specific transaction or case that has been flagged as potentially suspicious, rather than letting automated systems decide on their own. The reviewer looks at the available information and chooses an outcome, such as approving the order, asking for more verification, declining it, or escalating it for further investigation. It is typically used for orders that automated fraud tools cannot clearly classify.

Formal definition

Manual review is a human-in-the-loop control in which an analyst investigates a case triggered by rules, scoring models, or risk indicators and renders a disposition, commonly approve, step up (additional verification), decline, or escalate. It is most often applied to card-not-present orders flagged as potentially fraudulent, where human judgment supplements automated decisioning to resolve cases that fall outside clear approve or decline thresholds. Manual review is intended to help reduce both false positives (legitimate orders wrongly declined) and false negatives (fraudulent orders wrongly approved), but it introduces operational cost and latency and does not eliminate fraud; outcomes depend on analyst skill, available data, and case volume. Handling of any cardholder data during review must follow applicable PCI DSS controls, and note that sensitive authentication data must not be retained after authorization.

Why it matters

Automated fraud tools, whether rules-based or model-driven, are effective at handling the clear cases at either end of the risk spectrum, but they leave a band of ambiguous transactions that cannot be cleanly classified as approve or decline. Manual review exists to resolve that middle ground. Without a human-in-the-loop step, a merchant must either accept those borderline orders and risk fraud losses and chargebacks, or decline them and risk turning away legitimate customers. Manual review is intended to help reduce both false positives (legitimate orders wrongly declined) and false negatives (fraudulent orders wrongly approved) by applying human judgment where automated thresholds are inconclusive.

The trade-off is that manual review is not free. It introduces operational cost and latency, since each flagged case consumes analyst time and delays order fulfillment. Outcomes depend heavily on analyst skill, the data available at the time of review, and case volume, so the same control can perform very differently across organizations. Manual review supplements automated decisioning; it does not eliminate fraud, and its value is closely tied to how well cases are triaged so that reviewers focus on genuinely ambiguous orders rather than being overwhelmed.

Manual review also carries data-handling responsibilities. When an analyst examines a transaction, any cardholder data involved must be handled under applicable PCI DSS controls, and sensitive authentication data such as full track data, card verification values, and PIN blocks must not be retained after authorization. This means review workflows and the tools that support them fall within the same scope considerations as other systems that touch payment data.

Who it's relevant to

Fraud analysts and merchant risk teams
These teams are the direct operators of manual review, investigating flagged cases and choosing among approve, step up, decline, or escalate. Their skill and the data available to them directly shape whether the process reduces false positives and false negatives without adding unnecessary latency.
E-commerce and card-not-present merchants
Because manual review is most often applied to card-not-present orders flagged as potentially fraudulent, merchants running online or remote sales rely on it to resolve ambiguous orders that automated tools cannot cleanly classify, balancing fraud loss against declining legitimate customers.
Compliance officers and PCI DSS stakeholders
Manual review workflows that access cardholder data fall under applicable PCI DSS controls. Compliance staff need to ensure that review tooling and procedures handle cardholder data appropriately and that sensitive authentication data is not retained after authorization.
Payment processors and acquirers
Providers that offer fraud decisioning services or support merchant risk operations need to understand where automated scoring hands off to human review, since manual review is a supplement to, not a replacement for, automated decisioning and carries its own operational cost and latency.

Inside Manual Review

Order and transaction data
The transaction details a reviewer examines, which may include order amount, items purchased, billing and shipping addresses, and the timing and velocity of related orders. Reviewers should handle any cardholder data encountered under defined access controls and avoid storing sensitive authentication data such as CAV2/CVC2/CVV2/CID or full track data after authorization.
Risk signals and fraud scores
Outputs from automated screening, such as fraud scores, rule-based flags, address verification results, and device or behavioral indicators, that route a transaction to manual review rather than automatically approving or declining it. These signals help focus reviewer attention but carry false-positive and false-negative trade-offs.
Reviewer decision and disposition
The human analyst's action on a queued transaction, typically to approve, decline, or request additional verification. The disposition and its rationale are recorded to support consistency, auditing, and later feedback into automated rules.
Verification steps
Optional follow-up actions a reviewer may take, such as contacting the customer, requesting further documentation, or corroborating identity signals. These are intended to reduce uncertainty on borderline transactions but do not by themselves eliminate fraud.
Case notes and audit trail
A documented record of the signals reviewed, the decision reached, and the reasoning, which supports repeatability, quality assurance, and evidence for chargeback disputes. Chargeback outcomes are governed by card brand and network rules, which change and vary by region.

Common questions

Answers to the questions practitioners most commonly ask about Manual Review.

Does manual review guarantee that fraudulent transactions will be caught?
No. Manual review is intended to help reduce fraud losses on transactions flagged as higher risk, but it does not guarantee detection. Human reviewers can produce both false positives (declining legitimate orders) and false negatives (approving fraudulent ones). Its effectiveness depends on the quality of the data available to the reviewer, the reviewer's training, and the rules or scores that route cases for review. It should be treated as one layer among several rather than a control that eliminates fraud.
Is manual review a PCI DSS requirement or control?
No, manual review is a fraud-management practice, not a control defined by PCI DSS. PCI DSS governs the protection of cardholder data and the security of the environment that stores, processes, or transmits it. Fraud screening and manual review decisions are driven by merchant risk strategy and by card brand and network rules, which are separate from PCI DSS. Any cardholder data that a reviewer accesses during manual review remains subject to PCI DSS scope and controls, and sensitive authentication data must not be retained after authorization to support review.
What data should reviewers have access to during a manual review, given PCI DSS constraints?
Reviewers typically work with order and risk-signal data such as billing and shipping details, device and behavioral indicators, order history, and fraud scores. Access to cardholder data should follow least-privilege principles, and displayed PAN is commonly masked so that only permitted digits are visible unless a documented business need justifies otherwise. Sensitive authentication data such as full track data, card verification values, and PINs must not be stored after authorization, so it should not be available to reviewers from stored records. Confirm data-handling requirements against the current published PCI DSS.
How should transactions be routed into manual review?
Routing is usually driven by risk rules, model scores, or thresholds that flag transactions warranting closer inspection, for example unusual order values, mismatched geolocation, or velocity patterns. Setting thresholds involves a trade-off: a wider net increases review volume and the chance of declining legitimate customers, while a narrower net may let more fraud through. Queues should be sized to reviewer capacity, and routing logic should be monitored and tuned over time based on outcomes.
How can the outcomes of manual review be measured and improved?
Common practice is to track review outcomes against later signals such as chargebacks and confirmed fraud, then compare approve and decline decisions to actual results to estimate false-positive and false-negative rates. Feeding these outcomes back into rules and scoring models helps refine routing over time. Exact fraud and false-positive figures depend on the source, period, and methodology, so they should be measured within your own program rather than assumed from external benchmarks.
How does manual review fit alongside automated controls and authentication mechanisms?
Manual review typically handles the subset of transactions that automated screening cannot decide with sufficient confidence, and it operates after or alongside controls such as fraud scoring. It is distinct from authentication mechanisms like 3-D Secure or strong customer authentication, which address whether the legitimate cardholder is present rather than whether an order should be approved on risk grounds. Because liability and chargeback treatment are governed by card brand and network rules that vary by region and change over time, review decisions should account for those rules rather than rely on any single control.

Common misconceptions

Manual review catches fraud that automated systems miss, so it prevents fraudulent transactions.
Manual review is intended to help reduce fraud on flagged transactions, but it does not prevent or guarantee against fraud. Human reviewers are subject to error, inconsistency, and the same false-positive and false-negative trade-offs as automated screening, and sophisticated schemes such as synthetic identity or first-party (friendly) fraud can evade review.
Approving a transaction in manual review protects the merchant from chargebacks and shifts liability.
A manual approval reflects the merchant's own risk decision and does not by itself alter liability. Liability shift and chargeback rules are set by card brand and network rules that vary by region and change over time; reviewer decisions do not override those rules.
Manual reviewers need full access to complete card data to make good decisions.
Effective review generally relies on order context and risk signals rather than full card data. Any cardholder data accessed should be limited under defined access controls, and sensitive authentication data must not be stored after authorization even when encrypted.

Best practices

Use automated screening to route only borderline transactions to manual review, so analysts focus on cases where human judgment adds value while managing false-positive and false-negative trade-offs.
Restrict reviewer access to cardholder data on a need-to-know basis, apply masking or truncation where full values are not required, and ensure sensitive authentication data is never retained after authorization.
Document each review decision with the signals examined and the rationale to support consistency, quality assurance, and evidence for chargeback disputes under the applicable card brand and network rules.
Feed confirmed outcomes back into automated rules and scoring models to refine future routing and reduce avoidable manual workload.
Define clear escalation and verification procedures for high-risk or high-value orders, and avoid implying that any single verification step eliminates fraud.
Monitor reviewer performance and decision quality over time, since exact fraud and false-positive rates depend on source, period, and methodology and should be measured against your own environment rather than assumed.