Google · Google Cloud Fraud Defense

ML Transaction Fraud Risk Assessment

Google's models produce a transaction-specific fraud-risk assessment. Customer-configured policy can use that assessment for verification, review or payment rejection. Google does not independently reject payments.

Recorded characteristics

Function
Google's models produce a transaction-specific fraud-risk assessment (riskAnalysis.fraudPreventionAssessment.transactionRisk, with riskReasons). Google documents that Transaction defense "automatically trains behavior and transaction models to identify events that are likely fraudulent". Customer-configured policy can use the score for additional verification, manual review or payment rejection: "you can set thresholds on transactionRisk to contribute to your decision", including "directly rejecting likely fraudulent transactions". Google does not independently reject payments; enforcement is performed by the customer's own system. "You are responsible for the actions you take based on the assessment."
Data access
Transaction data supplied by the customer in the assessment request. Without the documented minimum data the response "won't contain a Transaction defense Assessment" (frontend integration: cardBin and cardLastFour, or accountId, email or phoneNumber); API-only integration requests without the minimum data fail with a 400 error.
Actions
Can take actions
External actions
Conditional
Human confirmation
Not required
Permission basis
Not established
Administrative control
Transaction defense is enabled on the customer's Google Cloud project: "Click the Enable toggle, and click Save." The customer selects thresholds and the resulting action (allow, additional verification, manual review or block). Google's example thresholds (0.5 additional verification, 0.7 manual review, 0.9 reject) are examples, not defaults.
Default state
Not established
Availability
Google Cloud Fraud Defense tiers: Enterprise, Premium and Essentials. API-only transaction defense is Enterprise only. Tier availability of the frontend Transaction defense integration is not publicly established.
Licensing
"You must have an Enterprise subscription to use the API-only integration." Other commercial terms are not publicly established.
External model or provider
Not established
Limitations and uncertainty
Google's documentation describes the score as contributing to the customer's decision; the customer, not Google, determines and executes any enforcement. Activation requires setup (Enable toggle and minimum data); no documented disabled-by-default setting exists, so default state is not established. Which tiers include the frontend integration is not publicly established. The extent to which customers configure automatic rejection is not publicly established. No platform-enforced per-action human approval is documented; manual review is a customer option. Permission basis is not publicly established. No monitor is active.

Evidence