Manual Review
Manual review is when a human analyst examines a specific transaction or case that has been flagged as potentially suspicious, rather than letting automated systems decide on their own. The reviewer looks at the available information and chooses an outcome, such as approving the order, asking for more verification, declining it, or escalating it for further investigation. It is typically used for orders that automated fraud tools cannot clearly classify.
Manual review is a human-in-the-loop control in which an analyst investigates a case triggered by rules, scoring models, or risk indicators and renders a disposition, commonly approve, step up (additional verification), decline, or escalate. It is most often applied to card-not-present orders flagged as potentially fraudulent, where human judgment supplements automated decisioning to resolve cases that fall outside clear approve or decline thresholds. Manual review is intended to help reduce both false positives (legitimate orders wrongly declined) and false negatives (fraudulent orders wrongly approved), but it introduces operational cost and latency and does not eliminate fraud; outcomes depend on analyst skill, available data, and case volume. Handling of any cardholder data during review must follow applicable PCI DSS controls, and note that sensitive authentication data must not be retained after authorization.
Why it matters
Automated fraud tools, whether rules-based or model-driven, are effective at handling the clear cases at either end of the risk spectrum, but they leave a band of ambiguous transactions that cannot be cleanly classified as approve or decline. Manual review exists to resolve that middle ground. Without a human-in-the-loop step, a merchant must either accept those borderline orders and risk fraud losses and chargebacks, or decline them and risk turning away legitimate customers. Manual review is intended to help reduce both false positives (legitimate orders wrongly declined) and false negatives (fraudulent orders wrongly approved) by applying human judgment where automated thresholds are inconclusive.
The trade-off is that manual review is not free. It introduces operational cost and latency, since each flagged case consumes analyst time and delays order fulfillment. Outcomes depend heavily on analyst skill, the data available at the time of review, and case volume, so the same control can perform very differently across organizations. Manual review supplements automated decisioning; it does not eliminate fraud, and its value is closely tied to how well cases are triaged so that reviewers focus on genuinely ambiguous orders rather than being overwhelmed.
Manual review also carries data-handling responsibilities. When an analyst examines a transaction, any cardholder data involved must be handled under applicable PCI DSS controls, and sensitive authentication data such as full track data, card verification values, and PIN blocks must not be retained after authorization. This means review workflows and the tools that support them fall within the same scope considerations as other systems that touch payment data.
Who it's relevant to
Inside Manual Review
Common questions
Answers to the questions practitioners most commonly ask about Manual Review.