Fraud Detection Tools Every Merchant Should Know About

Fraud detection tools for merchants

Card fraud doesn't just cost a business the value of a stolen transaction — it can also mean chargeback fees, higher processing rates over time, and in serious cases, the loss of a merchant account entirely. The good news is that most payment processors offer a layered set of fraud detection tools that catch a large share of suspicious activity before it turns into a loss. This article walks through the tools merchants should know about, what each one actually does, and how they work together.

Address Verification Service (AVS)

AVS checks whether the billing address a customer enters matches the address on file with their card-issuing bank. It's most relevant for card-not-present transactions — phone, mail, and online orders — where there's no physical card to inspect. An AVS mismatch doesn't automatically mean a transaction is fraudulent (customers move, use different billing and shipping addresses, or simply mistype), but it's a useful signal that, combined with other checks, helps flag orders that deserve a closer look before shipping goods or providing a service.

Most systems return a specific AVS response code rather than a simple pass or fail — for example, indicating that the street number matched but the ZIP code didn't, or vice versa. Merchants who process a meaningful volume of card-not-present orders benefit from understanding these partial-match codes rather than treating every AVS mismatch the same way, since a partial match carries meaningfully less risk than a complete mismatch.

CVV/CVC Verification

The three- or four-digit security code on the back (or front, for some cards) of a payment card is not stored in the card's magnetic stripe or chip data, which makes it a useful check specifically for card-not-present transactions. Requiring and verifying this code helps confirm the person entering the transaction likely has the physical card in hand, rather than just a stolen card number pulled from a data breach.

Real-Time Transaction Monitoring

Real-time monitoring tools evaluate transactions as they happen, checking factors like transaction size, frequency, location, and how a purchase compares to a customer's or business's typical patterns. Unusual combinations — a sudden spike in transaction volume, purchases from an unexpected location, or repeated attempts with slightly different card numbers — can trigger an automatic hold or flag for manual review before the transaction fully processes. This kind of monitoring is especially valuable because it can catch fraud patterns that a business owner reviewing statements after the fact would never notice in time to act. For a deeper look at how disputes happen even with strong fraud controls in place, see our breakdown of why chargebacks happen.

3D Secure Authentication

3D Secure (the technology behind programs like Visa Secure and Mastercard Identity Check) adds an extra authentication step to online transactions, typically requiring the cardholder to verify their identity through their bank — via a one-time code, a banking app prompt, or biometric confirmation — before the payment completes. For merchants, using 3D Secure on eligible transactions can shift liability for certain types of fraud-related chargebacks to the card-issuing bank instead of the merchant, which is a meaningful protection for online and high-ticket sales.

This liability shift is often the single biggest practical reason a business adopts 3D Secure. Without it, a merchant that ships a product or delivers a service based on a fraudulent transaction typically absorbs the loss directly through a chargeback, on top of losing the goods or labor involved. With 3D Secure properly implemented on an eligible transaction, that same fraudulent purchase becomes primarily the card issuer's problem to resolve, which changes the risk calculation considerably for merchants selling higher-ticket items online.

Velocity Checks and Rule-Based Filters

Velocity checks look at how many transactions are coming from the same card, IP address, or device in a short window of time — a hallmark of automated fraud attempts (sometimes called card testing) where stolen card numbers are run through in rapid succession to find ones that still work. Rule-based filters let a business or processor set specific thresholds — for example, flagging any single transaction over a certain dollar amount, or any order shipping to a country the business doesn't normally serve — so obviously atypical transactions get extra scrutiny automatically rather than relying on someone to catch them manually.

Card testing in particular is worth understanding on its own, since it often looks different from a single fraudulent purchase. Rather than one large transaction, a fraudster testing stolen card numbers will typically run many small-value charges in quick succession, looking for cards that go through without being declined. Velocity limits that flag or block a rapid sequence of small charges from the same source are one of the more effective ways to catch this pattern early, often before any of the tested cards are used for a larger, more damaging purchase.

No single tool covered so far catches everything on its own, which is why processors typically talk about fraud prevention in terms of layers rather than one silver-bullet solution. A practical starting point for most small businesses is to make sure AVS and CVV checks are turned on and actually being enforced (not just collected and ignored), add real-time monitoring or rule-based filters if the processor offers them, and use 3D Secure on higher-ticket or higher-risk online transactions where the liability shift is worth the small amount of extra friction at checkout. From there, it's worth periodically reviewing which flags are firing and how often — a rule set that's too loose lets fraud through, while one that's too strict starts declining legitimate customers, which has its own cost in lost sales and frustrated repeat buyers.

Tokenization and Encryption

While not a detection tool in the same sense as the others, tokenization and encryption reduce the damage a data breach can do by replacing sensitive card data with a non-usable token wherever it's stored or transmitted. Combined with the detection tools above, this means even if a system were compromised, the actual card numbers are far less useful to whoever obtained them — a meaningful layer of protection that complements active fraud monitoring rather than replacing it.

Some fraud prevention platforms also include chargeback alert services, which notify a merchant when a cardholder disputes a charge or contacts their bank about a transaction, often before the formal chargeback is filed. This early notice gives a business a window to investigate, issue a refund proactively if the complaint is legitimate, or gather evidence to contest the dispute if it isn't — rather than finding out about the dispute only after it's already been decided against them. Merchants processing a meaningful volume of card-not-present transactions tend to get the most value from these alerts, since disputes are more common in that channel than in face-to-face sales.

How Expedio Payments Helps

Fraud protection works best as a layered system rather than any single tool, and Expedio Payments' fraud detection and real-time transaction monitoring services are built to combine these checks — AVS, CVV, velocity rules, and ongoing monitoring — into one coordinated setup rather than leaving a merchant to piece it together. If you've had chargebacks creep up or you're setting up processing for a new online or card-not-present channel, our team can help configure the right combination of these tools for your specific business and risk profile.

Frequently Asked Questions

What's the difference between AVS and CVV checks?

AVS verifies that the billing address entered matches the address on file with the card issuer, while CVV verification confirms the card's security code, which isn't stored in the card's chip or magnetic stripe data. They check different things and are typically used together for card-not-present transactions.

Can fraud detection tools block legitimate customers by mistake?

Yes, it's possible — an AVS mismatch from a customer who recently moved, or a velocity flag from someone making several legitimate quick purchases, can trigger a hold. That's why most merchants use these tools as risk signals that prompt a manual review rather than as automatic, unappealable declines.

Does 3D Secure slow down checkout for customers?

It can add a short extra authentication step, such as a one-time code or a banking app confirmation, which takes a few seconds longer than a standard checkout. Many card issuers and processors have streamlined this over time so it runs in the background for lower-risk transactions and only prompts the customer directly when needed.

Do these fraud tools reduce chargebacks entirely?

No tool eliminates chargebacks completely, since some disputes are about issues other than fraud, like a customer not recognizing a charge or a dissatisfaction with a product. But a layered set of fraud detection tools meaningfully reduces the number of fraud-related chargebacks by catching suspicious transactions before they complete.

Is real-time transaction monitoring only useful for large businesses?

No — real-time monitoring tools are typically built into a processor's standard service and scale to businesses of any size. Small and growing merchants often benefit the most, since they may not have the staff to manually review transactions for suspicious patterns the way a larger business might.