Merchants should use the AVS and CVV2 card features as part of a best practices policy to mitigate fraud.
How AVS and CVV2 work
AVS and CVV2 responses are displayed after the transaction is authorized. As long as the authorization request is approved (the card is in good standing and the purchase amount is available), then the transaction can be submitted for deposit regardless of the AVS or CVV2 result codes.
However, merchants can use AVS and CVV2 as tools to help make business decisions on whether to proceed with the sale and delivery of goods and services based on responses codes.
Each merchant will set their own AVS and CVV2 acceptance policies. If merchants don't gain a comfort level with the responses to these card security features then they should not proceed with the sale and should void the transaction.
Merchants can either make business decisions on individual transactions, or depending on the payment processing technology used, automatically filter out transactions when AVS and CVV2 responses are unacceptable.
Address Verification Service (AVS) is a fraud prevention service developed to help merchants who accept card payments in a card-not-present environment (non-swiped transactions). During a transaction, AVS compares the address information that the cardholder provides to what is on record for that credit card number at the issuing bank.
There are many possible AVS responses:
Card verification is typically used in card-not-present situations (like Mail Order/Telephone Order and eCommerce) to help verify that the customer actually has the card in their possession.
CVV2 (Visa's Card Validation Value), CVC2 (MasterCard's Card Verification Code), and CID (American Express' and Discover's Card Identification) are fraud prevention services for card-not-present environments. During a transaction, the 3- or 4-digit security code collect at the time of sale is compared to what is on record for that credit card.
For Visa, MasterCard, and Discover credit cards, look on the back of the card. The last three digits of the string of numbers below the magnetic strip are the numbers to use. For an American Express card, look on the front of the card for a four digit number.
There are many possible CVV2 responses: