Manual Review in Fraud: A Working Guide
Automated rules score every order in a second. Manual review is where a person looks at the odd ones before the box ships.
Your fraud rules score every order in a blink. Most get approved or blocked without you. A few land in between. Manual review is the step where a person, not a rule, looks at those odd orders and decides. This guide covers what it is. It shows how the review queues in Stripe Radar and Adyen case management work. It also shows how to run a workflow that catches bad orders before they ship. It is not a promise that nothing gets through. A person looking at a payment catches things a rule cannot, and misses things a rule would catch. Used well, the two cover each other.
What manual review is
Manual review is a human step inside an automated fraud system. Rules and risk scores sort payments first. Anything odd goes into a queue. A reviewer opens the case, reads the details, and makes a call: approve, refund, or reject. The point is to catch the odd orders that scoring cannot settle on its own. And to catch them before the goods leave. It is not a way to inspect every payment. Stripe's documentation says the review queue lets you examine unusual payments without reviewing each payment individually. If you tried to review everything, you would have no time to run the store.
How a payment gets flagged
Rules you write put payments in a queue. On the Stripe side, Radar scores a charge using its AI models. It weighs hundreds of risk factors to do it. You can also write your own triggers. Stripe's documentation says you can create rules that automatically place payments in review based on your business needs. Say you sell gift cards, and any order over a certain amount of them is worth a look. A rule sends those to the queue.
Adyen works the same way at heart. The merchant writes custom risk rules with the Review action. Those rules send transactions to case management. Adyen's docs say a transaction is sent to case management for manual review when it matches the criteria that you define. So the queue is not a mystery. It holds what your rules asked it to hold. If you want a deeper look at how those triggers get built, see our page on Adyen risk rules.
Inside the queue: Stripe Radar
Stripe Radar's review queue sits in the Dashboard. Each payment that enters it gets a review object. Stripe's documentation says review.opened means a transaction was added to the review queue. It says review.closed means a review object is closed, and gives the reason. Those events matter if you tie the queue to your own systems. A review opens, and your own systems can react, such as holding the shipment. For a broader picture of the tool, our page on Stripe Radar for fraud teams covers how it fits a small team.
One limit to know early. Stripe's documentation says you cannot manually review ACH or SEPA direct debit payments. If you take those methods, plan a different check for them.
Inside the queue: Adyen case management
Adyen calls its queue case management. Adyen's docs say the case management queue lets you manually review cases, assign cases to reviewers, and accept or reject cases. Assignment matters once more than one person is reviewing, so cases do not sit unclaimed. Adyen's docs say case management is only there when you turn on premium features. Check your account setup before you plan a workflow around it. There is also a method limit: Adyen's docs say zero-value auth transactions cannot be sent to case management.
A reviewer works in the Customer Area. Adyen's docs say a reviewer accesses the case in the Customer Area and accepts or rejects the transaction. You can accept or reject from the opened case or from the list of cases. Adyen's docs say you can set up webhooks for case management. They fire when a case is accepted, rejected, or expired. That helps if your shipping system must react to the decision.
What the reviewer sees
The case holds the payment details and the risk data behind the flag. Adyen's docs say the case contains the payment details, the available risk information like shopper DNA and risk results, and fraud control options. The case details show which custom risk rule sent it there. So you know why the order is in front of you.
The shopper view is where a trained eye earns its keep. Adyen's docs say the shopper DNA visualization contains data from shoppers for all merchant accounts within your company. Hover over any node to make it bigger. You get a detailed tooltip, and its direct links light up. That map answers the reviewer's best question. Has this shopper, device, or email been seen before? Next to what? The Attributes sidebar lists every verified ID for the shopper. The Payments sidebar tracks live transaction counts across the payment lifecycle. One note on privacy: Adyen's docs say your user must have the Merchant view PII user role to view unmasked shopper details.
On the Stripe side, Stripe's guide says the risk insights section shows how Stripe Radar came up with a score for a charge. That tells you which signals pushed the score, so you are not guessing. Stripe's guide also says you can pass customer or order details as metadata. They then show up in the Dashboard at review time. Use that. Say the order is a first purchase, a bulk buy, or a repeat customer. Put that in metadata. The reviewer sees it without switching screens.
Decisions you can make
The choices are simple. Stripe's documentation says you can approve a payment, refund it, or refund it and mark it as fraudulent. Approving releases the order to ship. Refunding sends the money back before the goods go out. Refunding and reporting fraud does more: Stripe's documentation says refunding and reporting fraud adds the card fingerprint and customer email to your block lists. Our page on the Stripe Radar block list explains how those lists work.
One caution before you refund. Stripe's documentation says a completed refund is permanent and cannot be undone, so you must process a new payment. If you are unsure, hold the order and ask the customer a question. That beats refunding a good sale by mistake.
In Adyen the choice is accept or reject. Adyen's docs say you can update the status of a closed case by selecting either Fraud or Genuine.
Timing: hold the shipment
A review only helps if it finishes before the box leaves. Adyen's docs say you can delay shipment until the manual review has occurred. Build that delay into your fulfillment process, so nothing ships while a case is open. On the payment side, Adyen's docs say you can enable a separate capture delay for transactions sent to case management when you want more time to review payments. A capture delay keeps the funds uncaptured while you look, which pairs well with a shipment hold.
What happens when a case expires
Queues do not wait forever. Adyen's docs say if you do nothing, the transaction is automatically accepted, the funds are captured, and the case is logged as expired. The same happens if the merchant does nothing. The transaction is accepted on its own. The funds are captured based on capture settings. That is the quiet failure mode of manual review: an unstaffed queue does not block anything. It approves. If you send orders to review, someone must work the queue every day. If not, the whole setup is just for show.
Turn judgment into rules
The best reviewers get promoted into rules. Stripe's guide says reviewers' intuitions for fraud prevention can be translated into better rules. Look back over closed cases for patterns. If every bad order came from one country with a mismatched billing address, write a rule for it. The queue shrinks. The obvious cases get caught on their own. The reviewer's time goes to the odd ones left over.
Stripe's documentation says Smart Refunds gives recommendations about payments to refund based on the likelihood they will result in a fraudulent dispute. It points to payments worth refunding before they turn into a dispute. For orders where you want to push back on the shopper, our page on Stripe Radar 3DS covers when to step up checks.
The limits
Be honest about what this step does. Manual review catches some suspicious orders a rule would miss, and it will not catch them all. A reviewer can be wrong, slow, or out sick. A queue no one works just expires. The orders get approved. Some payment methods cannot be reviewed at all. Treat manual review as one layer. Rules score. A person looks at the doubtful ones. Shipment waits for the answer. A fraudulent sale that slips through can still turn into a chargeback later. Run the queue daily, write down what you learn, and let the rules take over the patterns. That is the whole job.