How Address Verification and CVV Checks Actually Reduce Fraud

Address Verification Service (AVS) and CVV checks are two of the oldest fraud tools in card payments, and they're still running quietly behind almost every card-not-present transaction. Neither one is a fraud-proof gate on its own, and understanding exactly what each one checks — and what it doesn't — helps merchants set up rules that catch real fraud without rejecting good customers over a typo.
What AVS Actually Verifies
Address Verification Service compares the numeric portion of the billing address and ZIP code the customer enters at checkout against the billing address on file with the card issuer. It does not verify the shipping address, and it does not confirm that the person entering the information is the actual cardholder — it only confirms whether the billing address entered matches issuer records closely enough to be considered a match.
AVS returns a response code rather than a simple yes or no: a full match, a ZIP-only match, an address-only match, or no match at all, along with codes for addresses outside the U.S. and Canada where AVS coverage is inconsistent. That nuance matters, because a full mismatch on an otherwise legitimate order might simply mean the customer moved and hasn't updated their billing address with their bank — not that the transaction is fraudulent.
What CVV Checks Actually Verify
The CVV (the 3-digit code on the back of most cards, or 4 digits on the front of American Express cards) exists specifically to confirm the person entering payment details is holding the physical card, or at least has seen it, since the code is not stored in card magnetic stripe data and (when merchants follow PCI rules correctly) is never stored by the merchant after authorization. A correct CVV match indicates the number wasn't lifted purely from a stolen card number list or a data breach where only the primary account number was exposed.
Like AVS, a CVV check returns a match, a no-match, or an indication that the check wasn't performed at all (some card issuers don't participate in CVV verification for certain transaction types). A CVV mismatch is generally treated as a stronger fraud signal than an AVS mismatch, because there are fewer legitimate reasons for a correct card's CVV to fail to match than there are for a billing address to be slightly out of date.
Why Neither Check Is a Complete Fraud Solution
AVS and CVV are both point-in-time data matches, not identity verification. Neither one confirms the transaction is being made by the legitimate cardholder, and both can be defeated by a fraudster who has the full card number, expiration date, CVV, and billing address — which happens routinely when that full data set is exposed together in a breach. AVS coverage is also inconsistent internationally, and some legitimate international orders will show a mismatch simply because the issuing bank doesn't return detailed AVS data.
This is why relying solely on AVS and CVV responses to auto-approve or auto-decline every order leaves gaps in both directions: real fraud gets through when the fraudster has complete stolen data, and legitimate customers get declined over address formatting differences, recent moves, or international billing quirks.
Setting Practical Rules Instead of All-or-Nothing Rejection
Most gateways let merchants configure how strictly to enforce AVS and CVV results rather than treating every mismatch as an automatic decline. A common, practical approach is to decline outright on a CVV mismatch (since that's a stronger fraud signal) while treating a partial AVS mismatch as a flag for manual review rather than an automatic rejection — particularly for higher-value orders where the cost of a false decline (losing a genuine sale) has to be weighed against the cost of a missed fraud signal.
Layering AVS and CVV results together with other signals — order velocity, device and IP information, whether the shipping and billing addresses match, and whether the customer is a repeat buyer — produces a far more reliable fraud picture than any single check alone. This layered approach is the basis of most modern real-time fraud scoring.
Where AVS and CVV Fit Alongside Broader Fraud Tools
AVS and CVV are typically the first and cheapest layer of a broader fraud-prevention stack. 3D Secure (which shifts liability to the card issuer for authenticated transactions), device fingerprinting, IP geolocation, and machine-learning-based risk scoring all build on top of the basic AVS/CVV response rather than replacing it. For businesses processing meaningful volume, real-time monitoring that combines all of these signals catches patterns — like the same stolen card data being tested against multiple merchants in a short window — that AVS and CVV alone were never designed to detect.
Card testing is a good example of why layering matters. Fraudsters who obtain a batch of stolen card numbers often run a series of small, low-value transactions across many merchants in quick succession, purely to find out which cards are still active before attempting a larger fraudulent purchase elsewhere. A single AVS or CVV check on one of those small transactions might return a match if the fraudster also has correct billing and CVV data from the same breach, meaning the check alone won't catch it. It's the pattern — unusual velocity, a string of small authorizations, or the same device attempting multiple cards — that flags the activity, which is why AVS and CVV work best as one input into a broader system rather than a final answer on their own.
What Different Business Types Should Weigh Differently
How strictly to enforce AVS and CVV results reasonably varies by business type. A digital goods or subscription business with instant delivery and no physical shipping carries more exposure to card testing and stolen-card fraud, since there's no shipping delay or physical address to cross-check, and often benefits from stricter CVV enforcement paired with velocity limits. A retailer shipping physical goods has a natural secondary check available — comparing the shipping address to the billing address, and to any AVS response — that a pure digital-goods seller doesn't.
Higher-ticket B2B sellers taking phone or mail orders face a different trade-off: false declines on a legitimate high-value order are costly to the relationship, so many choose to treat address or CVV mismatches on large orders as a trigger for a quick manual verification call rather than an automatic decline, accepting a small amount of manual review overhead in exchange for not turning away real customers over a data-entry mismatch.
How Expedio Payments Helps
Configuring AVS and CVV rules well — strict enough to stop obvious fraud, flexible enough not to punish good customers over an address mismatch — is easier with the right tools behind the checkout. Our fraud detection services help merchants set sensible AVS/CVV thresholds as part of a layered rule set rather than an all-or-nothing filter, and our real-time transaction monitoring adds velocity checks, device signals, and pattern detection on top of the basic address and code checks so genuine fraud gets caught without turning every mismatch into a lost sale.
Frequently Asked Questions
Does a failed AVS check mean a transaction is fraudulent?
Not necessarily. AVS only compares the billing address entered against issuer records, and a mismatch can happen for legitimate reasons, such as a customer who recently moved or an international billing address the issuer doesn't return detailed data for. It's a signal to weigh, not proof of fraud on its own.
Is a CVV mismatch more serious than an AVS mismatch?
Generally yes. There are fewer legitimate reasons for a correct card's CVV to fail to match than for a billing address to be slightly out of date, which is why many merchants treat a CVV mismatch as a stronger decline signal than a partial AVS mismatch.
Can merchants store a customer's CVV for future purchases?
No. PCI DSS rules prohibit storing the CVV after a transaction is authorized, specifically because its value as a fraud check depends on the cardholder providing it fresh at the time of each purchase.
Should every AVS or CVV mismatch be auto-declined?
Not always. Many merchants configure stricter rules for CVV mismatches and more flexible, review-based rules for partial AVS mismatches, since automatically declining every mismatch can reject legitimate customers along with fraudulent ones.
Do AVS and CVV checks work the same way for international orders?
Not consistently. AVS coverage outside the U.S. and Canada is less standardized, and some international issuers don't return detailed AVS data at all, which is why international mismatches are often treated differently than domestic ones.