What are risk signals (telemetry)? | Transmit Security

Glossary

What are risk signals (telemetry)?

Risk signals are the data points a fraud engine collects and combines to assess risk. Learn what signals matter and why fusing them beats relying on any one.
by Transmit Security

Risk signals (or telemetry) are the individual data points a fraud and identity system collects about a user, device, session, and behavior (device fingerprints, behavioral patterns, network characteristics, identity attributes, and transaction details) and combines to assess the risk of an interaction. They’re the raw inputs that feed risk scoring and decisioning; the quality and breadth of the signals set the ceiling on how accurately fraud can be detected.

No single signal reliably identifies fraud. The power comes from collecting many signals and fusing them, so that patterns invisible in any one become clear in combination.

The main categories of risk signals

  • Device signals: fingerprint, device identity, emulator/VM/anti-detect-browser indicators, tampering.
  • Behavioral signals: behavioral biometrics (interaction) and behavioral analytics (activity patterns).
  • Network signals: IP intelligence, geolocation, proxy and data-center detection, velocity.
  • Identity signals: how the identity was verified, its history, and consistency of provided data.
  • Transaction signals: amount, payee, timing, and deviation from normal.

Together these form the telemetry a fraud engine reasons over.

Why fusing signals matters

The central principle of modern fraud detection is that fused signals beat isolated ones. A new device alone is weak (people get new phones); unusual behavior alone is weak (people act unusually); a proxy IP alone is weak (people use VPNs). But a new device, exhibiting non-human behavior, behind a residential proxy, acting on an account with a thin identity history, that combination is a strong fraud signal. Fusing telemetry lets the system distinguish a genuine-but-unusual customer from a fraudster, which is what keeps false positives down while catching more fraud. This is precisely why siloed point tools underperform: each sees only its own slice of the telemetry.

From signals to decisions

Risk signals don’t act on their own; they feed a risk engine (increasingly ML-driven) that weighs them into a risk score and a recommendation (commonly Trust, Allow, Challenge, or Deny) which orchestration then acts on. The richer and more diverse the telemetry, the more accurate that decision. It’s also why collecting signals across the whole lifecycle (onboarding, login, transactions) and sharing them (rather than gathering them in disconnected tools) is so valuable: the same signal gathered at one stage sharpens decisions at another.

Passive vs. active signals

Risk signals divide usefully into passive and active. Passive signals are collected silently in the background: device fingerprint, behavioral patterns, network characteristics, and telemetry the user never notices. Active signals require some user action or friction, completing a step-up challenge, verifying an identity document, entering a code. The strong preference in modern fraud prevention is to lean on passive signals as much as possible, because they add security without taxing the user, reserving active friction only for cases where passive telemetry indicates real risk. This is the mechanism behind "invisible" security: gather rich passive telemetry continuously, decide from it, and only interrupt the customer when the signals warrant it. The breadth of passive telemetry a platform can collect and fuse is therefore a key determinant of how much fraud it can catch while keeping the experience frictionless.

Frequently asked questions

What’s the difference between passive and active risk signals?

Passive signals are collected silently (device, behavior, network); active signals require user action (a step-up or verification). Modern fraud prevention favors passive signals to minimize friction.

What are risk signals?

The data points (device, behavioral, network, identity, and transaction) a fraud system collects and combines to assess the risk of an interaction.

Why combine multiple risk signals?

No single signal reliably identifies fraud; fusing them reveals patterns invisible in any one, cutting false positives while catching more fraud.

How are risk signals used?

They feed a risk engine that produces a risk score and a decision (Trust, Allow, Challenge, or Deny), which orchestration acts on.

Related: Risk Scoring · Device Fingerprinting · Behavioral Analytics · IP Intelligence & Geolocation · Fraud Detection · Risk-Based Authentication

Request a Demo

By clicking the button, you agree to the Terms and Conditions