HomeBlogA Fraud-Review SOP Template for Your Team
Guide2026-06-208 min read

A Fraud-Review SOP Template for Your Team

Consistent fraud decisions come from a documented process, not gut feel. Here is a ready-to-adapt SOP — roles, review steps, decision criteria, and escalation — you can copy today.

A Fraud-Review SOP Template for Your Team

The difference between a store that handles fraud well and one that flails is rarely the tooling. It is whether decisions are repeatable. When every flagged order is handled by feel, two reviewers reach different conclusions on identical signals, decisions do not survive staff turnover, and you cannot improve a process you never wrote down.

A Standard Operating Procedure fixes that. Below is a complete, ready-to-adapt fraud-review SOP. Copy it, change the thresholds to fit your store, and put it where your team can find it.

Why an SOP beats intuition

  • Consistency: The same order gets the same decision regardless of who reviews it.
  • Speed: Reviewers stop re-deriving the process each time.
  • Onboarding: A new team member is productive in a day, not a month.
  • Improvement: A written process is a baseline you can measure and refine.
  • Defensibility: When you dispute a chargeback, a documented process strengthens your case.

Define the roles first

Even a two-person store benefits from clear roles. Assign these, even if one person wears multiple hats.

  • Reviewer — works the flagged-order queue, applies the decision criteria, records outcomes.
  • Escalation owner — handles the gray-area and high-value cases the reviewer escalates. Usually a senior team member or the owner.
  • Policy owner — owns the SOP itself: updates thresholds, reviews metrics, retrains the team. Reviews the SOP monthly.

The SOP template

Everything below is meant to be copied into your own doc. Bracketed values are the ones to tune.


1. Purpose and scope

This SOP governs how our team reviews and decides on flagged and high-risk orders on [store name] before fulfillment. It applies to all orders flagged by our fraud filter, orders over [$500], and any order a team member manually flags.

2. When a review is triggered

An order enters the review queue when any of these is true:

  • The fraud filter flags it (Tor, proxy, VPN, datacenter IP, geo mismatch, velocity).
  • Order value exceeds [$500].
  • Shopify's own risk indicator is medium or high.
  • Billing and shipping details differ significantly.
  • A team member flags it manually.

3. Review steps

Work each flagged order in this order and record findings as you go:

  1. Open the order and note the flag reason(s).
  2. Check location signals. Does the IP geolocation match the billing country? Is the IP a VPN, proxy, Tor node, or datacenter range? Does the shipping country match where the customer claims to be?
  3. Check the customer. New or returning? Prior successful orders? Does the email look legitimate (not a random-string address)? Does the name match the card and address?
  4. Check the order shape. Is the AOV normal for us? Multiple high-value items? Expedited shipping on a first order? Multiple failed payment attempts before success (card testing)?
  5. Check for velocity. Multiple orders from the same IP, email, or card in a short window?
  6. Cross-reference the blocklist. Does any detail match a previously confirmed-bad order?
  7. Score and decide using the criteria below.

4. Decision criteria

Count the risk signals present, then act by tier.

Green — Approve and fulfill. Zero or one low-severity signal (e.g. VPN only, on a normal order from a returning customer). Release for fulfillment.

Yellow — Hold and verify. Two or three signals, or one high-severity signal on a normal-value order. Contact the customer to verify (see template below). Do not fulfill until resolved.

Red — Escalate or cancel. Four or more signals, OR any combination of: Tor/proxy + high AOV + geo mismatch, OR a blocklist match, OR clear card-testing behavior. Escalate to the escalation owner; default action is cancel and refund.

High-severity signals: Tor exit node, anonymizing proxy, blocklist match, billing/IP on different continents, multiple failed payments then success.

Low-severity signals: Consumer VPN, minor billing/shipping mismatch within the same country, slightly-above-average AOV.

5. Customer verification template

Use this when an order is Yellow and you need confirmation before fulfilling:

Subject: Quick confirmation on your order #[number]

>

Hi [name], thanks for your order. Before we ship, we run a quick security check on some orders to protect our customers. Could you reply to confirm the billing address on the card used? If we don't hear back within [48 hours], we'll cancel and fully refund the order — no problem at all.

>

Thanks, [store] team

A genuine customer replies quickly. Silence or an evasive reply is itself a signal.

6. Escalation path

  • Reviewer escalates any Red order or any order over [$1,000] to the escalation owner.
  • Escalation owner decides within [4 business hours] to avoid fulfillment delays.
  • Any decision to override a hard rule (e.g. ship despite a Tor flag) must be logged with a reason and reviewed by the policy owner.

7. Logging

Record every reviewed order in the fraud log with: order ID, date, flag reason(s), signals found, decision tier, action taken, reviewer name. This log powers your KPIs and your chargeback disputes.


Adapting the template

  • Tune the thresholds ([$500], [$1,000], [48 hours]) to your AOV and margins. A store with a $40 AOV and one with a $400 AOV should not use the same numbers.
  • Adjust the signal weights to your history. If VPN traffic is common among your legitimate customers, downgrade it.
  • Automate the obvious tier. Green and hard-Red cases should not need a human. A checkout-level tool like Shieldy — Fraud Filter can block the clear-Red attempts before an order is even created, so your team only spends time on the genuine Yellow gray area — which is where human judgment actually adds value.

Keeping the SOP alive

A document that is written once and never revisited becomes fiction. The policy owner should:

  • Review it monthly against the KPIs (chargeback ratio, false-positive rate, review volume).
  • Update thresholds when the numbers drift.
  • Add new patterns to the blocklist and the criteria as attacks evolve.
  • Re-share it whenever it changes so nobody works from an old copy.

Put it to work

Copy the template, fill in your brackets, assign the three roles, and run your next flagged order through it. Consistency compounds — every logged decision makes the next one faster and better.

If you want to shrink the queue your team reviews in the first place, Shieldy — Fraud Filter handles the clear-cut blocks automatically. Start free and check the pricing tiers as your order volume grows.

Protect your Shopify store today

Install Shieldy free — block fraud, bots, and VPNs in under 5 minutes.

Install on Shopify — Free