AVS and CVV are two common security checks used in card-not-present payments. They are often mentioned together because both can help merchants assess whether the information entered during checkout is consistent with the legitimate cardholder or card account.

But AVS and CVV do not check the same thing. Address Verification Service (AVS) compares billing-address information with issuer records, while a Card Verification Value or Card Verification Code checks the security code associated with the card. Used together, they provide two different signals that can help reduce payment fraud without replacing issuer authorization or stronger authentication methods.

Quick answer: AVS checks billing-address information. CVV/CVC checks the card security code. A match on either one is useful, but neither proves that the shopper is the legitimate cardholder. The strongest fraud-prevention approach combines these checks with authorization, authentication and broader risk signals.

What Is AVS?

AVS stands for Address Verification Service or Address Verification System, depending on the provider. It compares billing-address data submitted with a card payment against address information available to the issuing bank.

In card-not-present transactions, a merchant may submit information such as the house number, street address and postal or ZIP code. The issuer or network returns an AVS result showing whether the available address elements matched, partially matched, did not match or could not be verified.

AVS is especially useful for online and MOTO payments because the merchant is not physically handling the customer's card. Adyen describes AVS as a fraud-prevention measure for card-not-present transactions and notes that it checks billing-address details against issuer records.

What Is CVV or CVC?

CVV means Card Verification Value. CVC means Card Verification Code. Different card networks and payment providers use slightly different names, including CVV2, CVC2 and CID, but the core concept is similar: the merchant asks for the card security code associated with the payment credential.

For ecommerce transactions, the code is commonly the short security value printed on the physical card or presented securely in a digital-card environment. The issuer or network can return a result indicating whether the submitted value matched, did not match or was not checked.

Visa, for example, documents separate CVV2 result codes for match, no match and not performed. Adyen likewise treats CVC as a separate post-authorization risk signal from AVS.

Promotional banner

AVS vs CVV: The Main Difference

Feature

AVS

CVV / CVC

What it checks

Billing-address information

Card security code

Typical data

Street/house number and postal or ZIP code

CVV/CVC/CID security value

Primary purpose

Compare address details with issuer records

Verify the submitted security code

Common use

Card-not-present transactions

Card-not-present transactions

Possible results

Full match, partial match, mismatch, unavailable

Match, no match, not performed/unavailable

Does it authenticate the shopper?

No

No

Does it guarantee approval?

No

No

How AVS Helps Reduce Payment Fraud

AVS can help identify transactions where the billing information entered at checkout is inconsistent with the issuer's records. A mismatch can be a useful warning signal, especially when it appears alongside other unusual transaction behavior.

  • A full address match can support confidence that the billing information is consistent with issuer records.
  • A partial match can signal that only the street address or postal code matched.
  • A no-match result can justify additional review or stronger authentication depending on the merchant's risk policy.
  • An unavailable result shows that AVS could not provide a reliable comparison and should not be treated as a confirmed match or mismatch.

AVS is not universal in exactly the same way across every country, issuer and card type, so merchants should use their processor's current documentation and avoid treating every mismatch as automatic fraud.

How CVV Helps Reduce Payment Fraud

A CVV/CVC check provides a different signal. It asks whether the card security code presented with the transaction matches the value expected by the issuer or network.

Because the security code is separate from the card number itself, requiring it can add friction for someone who has only obtained partial payment-card data. A no-match result can therefore be a meaningful risk signal.

However, a correct CVV does not prove that the person entering it is the legitimate cardholder. Criminals can sometimes obtain multiple pieces of card information through phishing, malware, data exposure or social engineering. That is why CVV should be used as part of a broader control set.

Promotional banner

Why Using AVS and CVV Together Is Stronger

AVS and CVV are complementary because they test different information. One checks billing-address consistency; the other checks the card security value.

A merchant can therefore receive combinations such as:

  • AVS match + CVV match: both signals are consistent, but normal authorization and fraud checks are still required.
  • AVS mismatch + CVV match: the security code matches, but the billing address does not. This may be legitimate or suspicious depending on context.
  • AVS match + CVV mismatch: the address matches, but the security code does not. This can justify additional scrutiny.
  • AVS unavailable + CVV match: the address could not be checked, so the merchant still lacks one of the expected signals.
  • AVS mismatch + CVV mismatch: multiple inconsistent signals can raise the overall risk assessment.

These combinations should inform risk decisions rather than serve as universal rules. Payment providers may process AVS and CVC checks after authorization, and merchants should understand how their processor exposes those results.

AVS and CVV Do Not Replace Payment Authorization

AVS and CVV are verification signals, while authorization is the issuer's decision about whether the payment can proceed. A card can produce a full AVS match and a correct CVV but still be declined for reasons such as insufficient funds, account restrictions or issuer risk controls.

Likewise, an issuer can authorize a transaction even when AVS does not fully match. Adyen notes that issuers can authorize payments despite incomplete AVS matches, which is why merchants receive the result separately for risk evaluation.

AVS and CVV Do Not Replace Strong Customer Authentication

Neither AVS nor CVV is equivalent to Strong Customer Authentication (SCA). SCA requires qualifying authentication elements, while AVS and CVV primarily verify pieces of payment information.

For applicable transactions, technologies such as 3-D Secure can support cardholder authentication. AVS and CVV can still contribute useful risk information, but they should not be treated as substitutes for required authentication.

Promotional banner

Can a Correct CVV and AVS Match Still Be Fraud?

Yes. A fraudster may sometimes possess enough compromised information to enter both the correct billing details and security code. A match only shows that the data provided corresponds with the expected values; it does not independently establish the identity or intent of the shopper.

This is why merchants should also consider account history, transaction value, device signals, behavioral patterns, shipping information, velocity, 3-D Secure results and issuer authorization.

Can Legitimate Payments Fail AVS or CVV?

Yes. Legitimate customers can produce mismatches or unavailable results for several reasons.

  • The customer recently moved and the issuer still has an older billing address.
  • The shopper accidentally enters a shipping address instead of the billing address.
  • Address formatting differs between the merchant and issuer systems.
  • The card issuer does not fully support the requested AVS check.
  • The customer mistypes the CVV/CVC or billing details.
  • A digital or replacement card uses updated credentials that the customer enters incorrectly.
  • Regional and issuer-specific payment behavior affects the availability of AVS results.

Overly rigid rules can therefore create false declines. Merchants should tune AVS and CVV policies using real transaction data and legitimate-customer outcomes.

AVS vs CVV vs 3-D Secure

Control

What it checks

Typical role

Authenticates cardholder?

AVS

Billing address

Risk signal

No

CVV/CVC

Card security code

Risk signal

No

3-D Secure / SCA

Customer authentication

Authentication and risk control

Yes, when successfully authenticated

Merchant Best Practices for AVS and CVV

  • Collect billing information accurately and explain clearly when it is required.
  • Use AVS and CVV as separate signals rather than treating one as a substitute for the other.
  • Avoid automatically declining every AVS mismatch without considering false-positive risk.
  • Treat a CVV mismatch as important, but still evaluate the full transaction context.
  • Use 3-D Secure or other authentication methods where appropriate or required.
  • Monitor chargebacks, false declines and fraud patterns to refine risk rules over time.
  • Follow the documentation for the actual payment gateway, acquirer and card networks used by the business.

What Consumers Should Know

For consumers, AVS is one reason online checkouts often ask for the billing address associated with a card, while CVV is why the card security code may be requested separately.

If a legitimate payment is declined because of one of these checks, confirm that the billing information and security code were entered correctly. Do not send card credentials, CVV values or authentication codes through insecure channels in an attempt to resolve a payment problem.

Frequently Asked Questions

What is the difference between AVS and CVV?

AVS checks billing-address information against issuer records. CVV/CVC checks the card security code associated with the payment credential.

Which is more important, AVS or CVV?

They measure different things, so neither should automatically replace the other. Using both can provide stronger transaction context than relying on one signal alone.

Does a CVV match mean the card is legitimate?

No. It means the submitted security code matched the expected value. It does not independently prove the shopper is the legitimate cardholder.

Does an AVS match mean the shopper is the cardholder?

No. An AVS match only shows that the billing-address information is consistent with issuer records.

Promotional banner

Can a payment be approved with an AVS mismatch?

Yes. AVS and authorization are separate results, and an issuer can authorize a transaction even when the address does not fully match.

Can a transaction be declined with AVS and CVV both matching?

Yes. Issuers can decline transactions for many reasons unrelated to AVS or CVV, including account status, funds, risk controls or regulatory requirements.

Is CVV the same as CVC?

They are network-specific names for the card security code concept. You may also see CVV2, CVC2 or CID.

Do AVS and CVV replace 3-D Secure?

No. AVS and CVV are verification signals, while 3-D Secure can support cardholder authentication and SCA requirements.

Should merchants store CVV values?

Merchants should follow PCI DSS and their payment provider's rules. Card verification codes are sensitive authentication data and should not be retained after authorization where prohibited by payment-security standards.

Final Thoughts

AVS and CVV are valuable because they answer two different questions. AVS asks whether the billing-address information is consistent with issuer records. CVV asks whether the card security code presented with the transaction matches the expected value.

Used together, they can strengthen card-not-present fraud screening, but neither one confirms the shopper's identity or guarantees that a transaction is safe. The best results come from combining AVS and CVV with issuer authorization, authentication, 3-D Secure where appropriate, transaction-risk analysis and other fraud-prevention signals.

Authoritative References

Editorial note: This article is educational and focused on payment-fraud awareness. AVS and CVV behavior varies by network, issuer, region and payment provider, so merchants should follow their own processor and PCI DSS guidance.