Fraud prevention is essential in iGaming, but protecting the business shouldn’t come at the expense of legitimate players. As fraud becomes more sophisticated, risk teams are moving beyond static rules and traditional identity checks toward behavioural signals, dynamic risk assessment, and smarter decision-making.
As Fraud & Risk Manager at Solverde PT, Mario Cardoso works at the intersection of security, player experience, and business performance. In this interview, he explores how operators can reduce false positives, use AI and machine learning to identify emerging threats, and bring Risk and Acquisition closer together to understand the real value of acquired players.
Fraud prevention is essential, but every additional security step can add friction to the player journey. How do you find the right balance between protecting the business and keeping the experience seamless for legitimate users?
I think the key is to move away from the idea that every player should go through the same level of security. The objective shouldn’t be to remove friction completely, but to make sure that friction is applied where it actually adds value.
If a player behaves consistently and presents a low-risk profile, there is very little reason to keep challenging that player throughout the journey. On the other hand, when we see signals that indicate increased risk, that’s where we should be comfortable introducing additional checks.
So, for me, the balance comes from risk-based decisioning: low risk should mean a seamless experience, while higher risk should justify more scrutiny.
And that leads directly into something that has become increasingly important for us: knowing who the player really is, beyond simply checking an ID document.
The industry is moving beyond traditional ID checks toward a broader understanding of digital identity. What does “knowing your player” mean from a fraud and risk perspective today?
For me, Know Your Player is really the evolution of traditional KYC.
A document can tell us that someone is a particular person, but it doesn’t necessarily tell us whether the behaviour we’re seeing is consistent with that identity.
So we’re looking at a much broader picture: device information, account history, behavioural patterns, payment behaviour, IP and geolocation signals, connections between accounts, and increasingly the way the player interacts with the platform.
The important thing is that none of these signals should necessarily be decisive on their own. It’s the combination of signals and the context around them that gives us a much better understanding of risk.
And that also means we can often detect something suspicious without immediately asking a legitimate player to prove their identity again.
What signals beyond traditional identity verification are becoming most valuable for detecting suspicious behaviour without unnecessarily interrupting genuine players?
I would say behavioural and relational signals are becoming particularly important.
Things like device reuse across multiple accounts, unusual changes in behaviour, velocity, payment patterns, links between accounts, or inconsistencies between the player’s declared information and how they actually behave.
What I find particularly interesting is that these signals allow us to move from a very binary approach — verified or not verified — towards a much more dynamic assessment of risk.
For example, you may have a perfectly valid identity document, but if the same device, payment instrument or behavioural pattern is appearing across a network of accounts, that tells you something completely different.
And this is where false positives become critical, because if we act on every individual anomaly, we can very quickly start treating legitimate customers as fraudsters.
A legitimate user who is incorrectly flagged can quickly lose trust in a platform. How should operators think about false positives, and what can be done to minimize their impact on the customer experience?
I think false positives should be treated as a business problem, not just a risk problem.
From a risk perspective, blocking fraud is obviously important. But if we’re blocking legitimate players at the same time, we’re effectively creating another form of loss — through abandoned deposits, reduced retention and damage to trust.
That’s why I think the quality of the decision is more important than simply increasing the number of alerts.
We need to ask: how confident are we that this behaviour is actually suspicious?
This is where better data, better segmentation and better models can make a significant difference. Instead of creating a rule that says “this behaviour equals fraud”, we can look at the overall risk profile and determine whether additional friction is really justified.
And this is also an area where AI and machine learning can make a real difference, because they allow risk teams to identify patterns that are much harder to capture through traditional rules alone.
Fraud tactics evolve extremely quickly. How are AI and machine learning changing the way risk teams identify new patterns and respond to threats in real time?
The biggest advantage, in my view, is the ability to identify patterns at a scale and speed that would be very difficult to achieve manually.
Fraudsters don’t necessarily change one thing at a time. They change devices, payment methods, behaviours, accounts and sometimes entire networks. Machine learning can help us identify relationships between those signals and detect patterns that aren’t obvious when you look at each account individually.
But I don’t think AI should replace the risk team. It should augment the risk team’s ability to make decisions.
The other important point is that models need to evolve with the threat. A model that was very effective six months ago may not be as effective today because fraudsters adapt.
And that’s why I think the next step isn’t just better fraud detection. It’s making sure that the insights we’re generating are connected to the rest of the business.
Acquisition teams typically optimize around conversion, CPA or first deposits, while risk teams look at very different signals. What could companies gain by bringing those teams and datasets closer together?
I think there is a huge opportunity there.
If Acquisition is looking at CPA and conversion, but Risk is looking at the quality and behaviour of those players after they arrive, you can end up optimizing for the wrong outcome.
A channel may look extremely successful because it generates a lot of registrations and first deposits, but if a disproportionate number of those players subsequently generate fraud losses, bonus abuse or payment risk, then the real value of that channel is very different.
So I think we need to move from “How much did it cost us to acquire this player?” to “What is the quality and lifetime value of the player we acquired?”
And that requires Acquisition and Risk to work with the same data and, ideally, some of the same KPIs.
Ultimately, fraud prevention shouldn’t sit at the end of the funnel as a function that simply says yes or no. It should help the business understand which players, behaviours and acquisition sources are actually creating sustainable value.
Subscribe to our newsletter