Fraud prevention tools are often discussed as if they provide the same type of protection. They do not. Address Verification Service (AVS), Card Verification Value (CVV) checks, and 3-D Secure (3DS) each address a different part of the card-not-present fraud problem.
For merchants, the important question is not whether one tool is better than another. It is how each tool contributes to a broader risk strategy. Used correctly, these controls can help identify suspicious transactions before they become chargebacks. Used in isolation, they leave gaps.
What AVS Actually Does
AVS compares address information provided during checkout with information held by the card issuer. The merchant receives a response indicating whether the information matches.
A mismatch can be a useful risk signal. Visa describes AVS as a tool that can help merchants identify potential fraud when billing address information does not match the issuer’s records.
But AVS is not an authentication mechanism. A legitimate transaction can produce a mismatch for several reasons. Customers may enter an address differently from the way their bank stores it. International transactions can also complicate address verification.
For that reason, an AVS mismatch should not automatically result in a declined transaction. It is better treated as one input into a broader risk decision.
What CVV Verification Adds
CVV verification checks the security code associated with a payment card. During an online transaction, the merchant can submit the CVV provided by the customer for verification.
A successful match provides evidence that the person completing the transaction has access to information associated with the physical card. A failed match can indicate elevated risk.
Visa notes that merchants can use account-number verification services to check address information and CVV2 before requesting authorization; mismatches can provide an opportunity to request another card rather than proceed with a risky transaction.
CVV has an important limitation, however. It does not prove that the person making the purchase is the legitimate cardholder. Criminals may obtain card details and CVV information together. A successful CVV check therefore does not make a transaction automatically safe. It is another signal.
Where 3-D Secure Is Different
3-D Secure takes a different approach. Rather than simply checking information associated with the card, it allows data to be exchanged between the merchant, issuer, and cardholder to help authenticate the transaction.
Modern EMV 3DS can use transaction, device, and behavioral information to support risk-based authentication. Lower-risk transactions can often proceed without an additional customer challenge, while higher-risk transactions may require further verification.
This makes 3DS more than a simple data check. It introduces the card issuer into the authentication process.
For merchants, that can be valuable when dealing with card-not-present fraud. It can also support liability shifts for qualifying transactions under applicable network rules. The specific conditions depend on the card network, transaction, authentication outcome, and other factors.
Why Layered Fraud Prevention Matters
There is no universal winner because the tools solve different problems.
- AVS is useful for identifying discrepancies in billing information.
- CVV helps establish whether the customer supplied the security code associated with the card.
- 3DS provides a stronger authentication framework by allowing the issuer to participate in assessing and verifying the transaction.
The most effective approach is therefore layered, rather than selective.
Consider a transaction with a matching billing address and CVV. Those results may look reassuring. But they do not tell you everything about the person making the purchase.
Now add 3DS authentication. The issuer receives additional transaction data and can assess the payment through its own risk systems. Visa describes this enhanced data exchange as a way to improve authorization decisioning and fraud detection.
Additional signals can make the decision stronger still. Device information, transaction history, IP data, account behavior, velocity checks, and other risk indicators can provide context that AVS or CVV cannot.
This is particularly important because fraudsters do not necessarily trigger a single obvious warning sign. A fraudulent transaction may look legitimate when viewed through one data point but suspicious when several signals are considered together.
The Risk of Relying Too Heavily on One Tool
A common mistake is treating a positive result as proof that a transaction is legitimate.
An AVS match does not authenticate the customer. A CVV match does not establish that the cardholder is present. Even 3DS authentication does not guarantee that every fraudulent transaction will be prevented.
Visa explicitly notes that 3DS helps reduce unauthorized use but does not prevent all fraud.
Risk teams should therefore avoid binary decision-making based on individual controls. Instead, the question should be whether the overall transaction profile is consistent with legitimate customer behavior.
Balancing Security With Customer Experience
More fraud controls do not necessarily mean better fraud prevention.
Every additional challenge can create friction for legitimate customers. If a merchant declines or challenges too many legitimate transactions, it can lose revenue that would otherwise have been generated.
Modern 3DS implementations are designed to support risk-based authentication. Mastercard, for example, describes an approach in which low-risk customers can experience a frictionless flow while higher-risk transactions receive additional scrutiny.
This is an important distinction. The goal should not be to challenge every customer. It should be to identify which transactions actually require additional verification.
Use the Results as Part of a Risk Decision
AVS, CVV, and 3DS should feed into a broader decision framework.
A merchant might treat a transaction with matching AVS and CVV results as relatively low risk. But if the same transaction involves a new account, an unusual device, a high-value order, and an unfamiliar shipping address, the overall picture changes.
Conversely, a customer with a long transaction history and consistent behavior may not warrant additional friction simply because one data point produces an unusual result.
This is where rules engines, fraud scoring, and machine learning can add value. They allow merchants to evaluate multiple signals rather than relying on a single pass-or-fail check.
What Risk Managers Should Measure
The effectiveness of these tools should be evaluated using business outcomes, not simply the number of transactions they flag.
Useful measures include:
- Fraud and chargeback rates
- Approval rates
- False-positive rates
- Authentication rates
- Challenge rates
- Conversion rates
- Revenue recovered or protected
These metrics should be reviewed together. A fraud control that reduces chargebacks but also rejects a large volume of legitimate transactions may not be producing the desired result.