What Is First Payment Default, and What Drives It


First payment default is the share of newly originated loans where the borrower misses the first scheduled payment. It is the earliest performance read a lender gets, and the one that tends to carry the most fraud information, because a default at the first instalment is less likely to reflect a change in circumstances than one twelve months in.
In this article we cover how it is measured, what moves it, how to bring it down in a new product, and how risk teams use it.
The calculation is straightforward – defaulted loans divided by loans originated in the same cohort, expressed as a percentage. The complications sit in the definitions, and they matter because they make cross-institution comparison unreliable.
Cure period is the first of them. There is no single convention. Contractual definitions in secured lending commonly use a thirty-day window and sometimes sixty; some securitisation definitions count anything from one to thirty days past due; operational systems in short-tenor lending often allow the position to cure up to the second scheduled payment. The labels below are the ones most used in digital lending, and the same portfolio produces materially different rates under each:
| Variant | Cure period | What it captures |
|---|---|---|
| FPD1 | 1 day past due | The strictest read. Includes operational failures such as a failed direct debit or a mistimed transfer, so it overstates genuine default. |
| FPD7 | 7 days past due | The common working definition. Filters most payment-processing noise while keeping the short feedback loop. |
| FPD30 | 30 days past due | Closest to a conventional delinquency read, and the definition most often found in contracts. The wider window lets more positions cure before being counted, moving the measure away from the application and toward ordinary delinquency. |
The denominator varies too. Counting loans and counting outstanding principal balance give different answers on the same cohort, and published figures rarely say which was used.
Three further conventions vary by institution:
Fixing one definition internally and holding it is more useful than matching a published benchmark, since benchmark figures rarely state which convention they used.
Two adjacent terms cover the far end of the same scale. A never-pay account makes no payment at all rather than missing the first one, and a straight roller describes a loan taken with no intention of repayment from the outset. FPD includes both, which is part of why it carries fraud information – but separating them within the cohort is more informative than the aggregate, since a never-pay rate moving independently of the overall FPD rate usually points at origination rather than at affordability.
Credit risk tends to emerge over time as circumstances shift. A borrower who never makes a single payment had either no capacity at origination or no intention of repaying, and both point back to the application rather than to events after it. Early default is also where misrepresented income, overextension across several credit lines and identity-related fraud that passed origination controls tend to surface.
That makes FPD the shortest feedback loop available to a risk team. For anyone tuning fraud controls, onboarding rules or a new data source, the difference between a six-week and a five-month verdict is the difference between iterating and waiting.
The two metrics answer different questions and are usually read together. NPL90 measures loans ninety or more days past due and describes portfolio credit performance; it needs at least three months plus reporting lag before a cohort is readable. FPD closes in weeks and is weighted toward the application rather than toward events after it.
For work on NPL ratios, FPD functions as the leading indicator. Elevated FPD in a cohort tends to precede elevated NPL90 in the same cohort, which means interventions tested against FPD can be validated months before their effect on the ninety-day figure becomes visible. The reverse does not hold: a portfolio can show acceptable FPD and deteriorate later through affordability rather than fraud.
An elevated FPD rate rarely has one cause. The usual candidates:
Separating these requires cutting the cohort by channel, product, segment and device signal rather than reading the headline figure, which on its own indicates that something moved without saying what.
A new product has no performance history, which removes the usual response of tightening a scorecard that has already been calibrated. What remains is a sequence, and the order matters more than any individual step.
FPD is the label that device and session attributes are most practically validated against, because the feedback arrives quickly enough to act on. Comparing FPD across cohorts split by device intelligence attributes – repeated/similar device environments across applications, environment integrity, connection consistency, behavioural markers during the application – shows whether those signals separate risk in a specific portfolio rather than in a vendor's.
What that separation looks like in practice: in the South Asian analysis we’ve mentioned above, JuicyScore evaluated 150,000+ web-channel applications against realised first-instalment outcomes. Ranking the flow on device, behavioural, connection and technical attributes divided it into six segments, with FPD running from 0.07% in the lowest to 4.49% in the highest. A narrower set of stop-markers isolated under 0.5% of applications carrying an FPD rate of around 20% – a segment small enough to route to manual verification rather than decline outright. The full analysis is published here.
After a decline, a repeat attempt under new credentials reaches the application layer as an unrelated case. What changes is the declared data. The technical environment the application arrives from – device configuration, connection, behavioural pattern during the session – usually does not. Recognising that recurrence at the point of application keeps the cohort clean and prevents the same environment from entering the FPD numerator twice under different declared identities.
JuicyScore evaluates attributes of the kind mentioned above without relying on direct user identifiers such as name, phone number or email, and returns them in a form risk teams can test against their own FPD outcomes.
To see how device and session signals separate FPD cohorts in your own portfolio, book a demo with our team. We walk through the attribute set, how it reaches an existing decisioning flow, and where data allows, a preliminary analysis against your outcomes.
First payment default, or FPD, is the share of newly originated loans where the borrower fails to make the first scheduled payment. It is calculated as defaulted loans divided by loans originated in the same cohort, and it is the earliest portfolio performance indicator available to a lender.
Divide the number of loans that missed the first instalment by the number of loans originated in that cohort. Some definitions use outstanding principal balance rather than loan count, which produces a different figure from the same data. The cure period applied – one day, seven days, thirty days, or cure up to the second scheduled payment – changes the result again.
FPD captures failure at the first instalment, usually readable within weeks. NPL90 captures loans ninety or more days past due and needs at least three months plus reporting lag. FPD is faster and weighted toward fraud; NPL90 reflects credit performance more broadly, and FPD generally moves first.
The three describe increasing seriousness. FPD covers a missed first scheduled payment. A never-pay account makes no payment at all. A straight roller generally refers to a loan where there are indications that repayment was not intended from origination, making it particularly relevant for fraud analysis. FPD is the broadest of the three and functions as the early warning; the other two are subsets worth tracking separately, because they move for different reasons.
Not by itself. Channel mix, scorecard changes and expansion into thinner-file segments all move the rate. Fraud tends to concentrate in specific cohorts, channels or device profiles rather than lifting the portfolio evenly, which is why segmentation is the diagnostic step. A useful first cut is by acquisition channel: organised application fraud arrives through a limited number of sources, so an elevated rate concentrated in one affiliate or traffic source points in a different direction from one distributed across the whole book. Device attributes give the second cut, since coordinated applications share environment characteristics that independent borrowers do not.
No single figure transfers across products, markets or definitions. Short-tenor unsecured lending and secured lending in mature markets operate at different levels, and the cure period chosen changes the number again. A consistent internal series is more useful than an external benchmark, since published figures rarely state which convention produced them. Where an external comparison is needed, it is worth confirming the cure period, the cohort basis and the treatment of partial payments before treating two rates as comparable.
Because the feedback loop is short. A device attribute or scorecard change can be evaluated against FPD cohorts in weeks, where waiting for NPL90 delays the verdict by months and allows several intervening changes to confound it. The practical method is a retrospective split: take originated volume with known first-instalment outcomes, divide it by the attribute being tested, and compare FPD across the resulting cohorts. If the attribute separates, the difference appears without any change to production decisioning. This also answers the question of whether a fraud score correlates with later delinquency, which is otherwise difficult to establish – the score is applied to historical applications and the cohorts are read against outcomes that have already occurred.
Analysis of device intelligence, fraud patterns and risk decisioning – research, case data and regulatory changes worth knowing about. Subscribe to the JuicyScore newsletter.

Alternative credit scoring gives fintechs and lenders a smarter, privacy-safe way to assess risk and reach thin-file customers. Here's how it works – and why it’s gaining traction.

When personal data stops explaining credit risk, scoring needs a new lens. How device intelligence restores visibility in digital lending.

How credit risk analysis works in digital lending – from expected loss and traditional methods to device signals for thin-file borrowers.
Get a live session with our specialist who will show how your business can detect fraud attempts in real time.
Learn how unique device fingerprints help you link returning users and separate real customers from fraudsters.
Get insights into the main fraud tactics targeting your market — and see how to block them.
Phone:+971 50 371 9151
Email:sales@juicyscore.ai
Our dedicated experts will reach out to you promptly