Answer
CVV fraud protocols are security rules that card networks, banks, and merchants use to verify card-not-present transactions. The main checks are CVV2 verification, Address Verification System (AVS), 3-D Secure authentication, tokenization, and fraud scoring.
CVV and CVV2
A CVV is a 3-digit code on the back of most Visa, Mastercard, and Discover cards. American Express uses a 4-digit code on the front. The CVV2 is the code used for online and phone orders. The code is not stored on the magnetic stripe. It is not the same as a PIN.
CVV verification protocol
The merchant sends the card number, expiration date, and CVV2 to a payment processor. The processor routes the data to the card issuer. The issuer compares the CVV2 to its records. It returns one of three codes: match, no match, or not processed. A match means the code is correct for that card number. A match does not prove the buyer is the cardholder. Stolen card data often includes the CVV2.
Address Verification System
AVS compares the billing address and ZIP code from the order to the address on file with the issuer. The issuer returns a single-letter code. Codes show if the street address matches, the ZIP code matches, both match, or neither matches. AVS works in the United States, Canada, and the United Kingdom. It does not work for all international cards.
CVV Fraud Best Practices: How to Stop Card-Not-Present Fraud
3-D Secure
3-D Secure adds an authentication step. The cardholder enters a password or one-time code with the issuer. Visa calls it Visa Secure. Mastercard calls it Identity Check. American Express calls it SafeKey. Version 2.0 uses risk-based checks. Low-risk orders pass without a challenge. High-risk orders require a code. A successful 3-D Secure check shifts fraud liability from the merchant to the issuer.
Tokenization
Tokenization replaces the card number with a random token. The token works only for a specific merchant or device. Apple Pay and Google Pay use tokenization. If a token is stolen, it cannot be used at another merchant. The real card number stays hidden.
Fraud scoring
Banks and processors use machine learning to score each transaction. The score uses data such as IP address, device ID, time of day, order amount, and merchant history. A high score triggers a block or a manual review. A low score allows the order to proceed.
Limits of protocols
CVV checks fail when the issuer does not support the code. AVS fails for many international cards. 3-D Secure can be bypassed by social engineering. Fraudsters use phishing and malware to steal card data. No protocol stops all fraud. Merchants combine several checks to reduce risk.
Chargebacks and liability
If a cardholder reports fraud, the merchant may receive a chargeback. The merchant loses the sale amount and pays a fee. Liability rules depend on the protocol used. A 3-D Secure authentication shifts liability to the issuer. A CVV mismatch often shifts liability to the merchant. AVS mismatch can also shift liability.