Online businesses can reduce card-not-present (CNP) fraud by using layered security rather than relying on a single check. Effective controls include EMV 3-D Secure, AVS, CVV verification, payment tokenization, device and behavioral risk signals, velocity rules, secure payment-page controls, manual review for high-risk orders, and PCI DSS-aligned handling of card data. The goal is to challenge risky transactions while allowing legitimate customers to check out with as little friction as possible.

Card-not-present fraud is one of the central security challenges of digital commerce because the merchant cannot physically inspect the card or verify the buyer face-to-face. In an online transaction, the customer enters or provides payment credentials remotely, so the business must decide whether the person placing the order is the legitimate cardholder using digital signals rather than a physical card interaction.

The most effective response is a layered merchant security strategy. No single tool can reliably distinguish every legitimate payment from every fraudulent attempt. Instead, online businesses should combine authentication, verification, payment-data protection, transaction monitoring and secure website practices. The strongest systems also adapt controls to risk so that low-risk customers move through checkout quickly while suspicious transactions receive additional scrutiny.

This guide explains practical ways merchants can reduce CNP fraud in 2026 while protecting customer experience, lowering chargeback exposure and strengthening payment security.

What Is Card-Not-Present Fraud?

Card-not-present fraud occurs when someone attempts or completes a remote payment without the legitimate cardholder being physically present with the payment card. E-commerce checkout, in-app purchases, subscriptions and some mail-order or telephone-order transactions are common card-not-present environments.

Because the merchant does not read a physical chip at the point of sale, the transaction depends on remote credentials and supporting signals. That makes identity verification, device intelligence, issuer authentication and transaction context especially important. CNP fraud can involve compromised card details, account takeover, stolen login sessions or other forms of unauthorized payment activity.

Why CNP Fraud Requires Layered Security

A merchant that relies only on a card number and expiration date has very little information about whether the person checking out is authorized to use the account. Adding one extra check helps, but fraud prevention becomes much stronger when independent controls work together.

For example, AVS can compare address information, CVV can help verify that the buyer has access to card security data, 3-D Secure can involve the card issuer in authentication, and device or behavioral signals can detect unusual activity. Tokenization reduces exposure of sensitive card numbers, while payment-page security controls help protect the checkout itself from malicious scripts or tampering.

Layering matters because each signal answers a different question. A good fraud strategy looks at the entire transaction rather than treating a single match or mismatch as proof of legitimacy or fraud.

10 Ways Online Businesses Can Reduce Card-Not-Present Fraud

1. Use EMV 3-D Secure for Risk-Based Authentication

EMV 3-D Secure, commonly called 3DS, allows the merchant, card issuer and supporting payment infrastructure to exchange transaction data so that the issuer can help assess whether the purchase is being initiated by the legitimate account holder. Modern 3DS is designed to support risk-based authentication: many lower-risk transactions can proceed with little or no visible interruption, while higher-risk transactions may trigger a challenge such as an in-app approval, passcode or biometric verification.

Promotional banner

For merchants, 3DS can improve the quality of authentication data available during checkout and can reduce CNP fraud. In some markets and transaction types it can also support regulatory authentication requirements. Implementation should be coordinated with the merchant’s payment service provider or acquirer so that exemptions, challenges and fallback behavior are handled correctly.

2. Use AVS as a Risk Signal, Not a Standalone Decision

Address Verification Service (AVS) compares numeric parts of the billing address submitted at checkout with information held by the card issuer. Depending on the region and issuer, the result may indicate whether the street number, postal code, both, or neither matched.

AVS can be useful because a mismatch adds context to the transaction, but merchants should avoid automatically declining every mismatch. Legitimate customers can enter an old billing address, abbreviate an address differently or make a typing mistake. A better approach is to combine AVS results with other signals such as order value, device history, 3DS outcome, customer tenure and shipping behavior.

3. Request CVV/CVC When Appropriate - and Never Store It After Authorization

The card verification code - commonly called CVV, CVC, CID or similar terms - is widely used in card-not-present payments to help verify that the customer has access to card security information. It is an additional signal, not a guarantee that the transaction is legitimate.

Promotional banner

Merchants must treat card verification codes as sensitive authentication data. Under PCI DSS, they must not be stored after authorization, even if encrypted. Systems should be designed so the value is collected only when needed for authorization and is not retained in logs, databases, analytics platforms or customer-service notes.

4. Tokenize Stored Payment Credentials

Payment tokenization replaces sensitive card details with a token that can be used within an approved payment ecosystem. For merchants that support subscriptions, saved cards or returning-customer checkout, tokenization can reduce the amount of raw card data stored or transmitted by merchant systems.

Network tokens can also improve the resilience of card-on-file payments because the token may be managed within the card network ecosystem instead of relying on a static PAN stored by the merchant. Tokenization does not replace authentication or fraud screening, but it reduces the consequences of data exposure and can strengthen the overall payment architecture.

5. Use Device, Session and Behavioral Risk Signals

A modern fraud system should evaluate more than payment credentials. Device and session signals can help identify whether the transaction resembles normal customer behavior or a potentially risky pattern. Useful categories can include device consistency, account age, IP reputation, login history, shipping changes, session behavior and the relationship between the device and previous legitimate orders.

The goal is not to collect unnecessary personal data. It is to use proportionate, privacy-aware signals that help distinguish routine customer behavior from suspicious activity. Merchants should document what signals they use, why they use them and how long they retain them.

6. Apply Velocity Controls and Transaction Limits

Velocity controls identify unusual bursts of activity over a defined period. Examples include repeated payment attempts, an unusual number of cards tried on one account, a sudden surge in orders from a single device, or repeated high-risk actions in a short time window.

These controls are especially useful for detecting automated abuse and account-testing patterns. However, thresholds should be tuned to the merchant’s real customer behavior. Rules that are too strict can block families, shared networks, corporate buyers or legitimate high-volume customers. Rules should therefore trigger proportional responses such as additional verification, temporary holds or review rather than indiscriminate blocking.

7. Protect the Checkout Page From E-Skimming and Script Attacks

CNP fraud prevention is not only about deciding whether a buyer is legitimate. Merchants must also protect the payment page itself. Malicious scripts can be used to capture payment data entered into compromised e-commerce pages, a threat commonly associated with e-skimming or web skimming.

Under PCI DSS v4.0.1, payment-page security and script-related controls are an important part of e-commerce security. Merchants that outsource payment processing still need to understand which parts of their own website can affect the security of the checkout experience. Embedded payment forms, third-party scripts, tag managers and software dependencies should be managed carefully, monitored for unauthorized changes and kept to the minimum necessary for business operations.

8. Use Manual Review Selectively for High-Risk Orders

Automation is essential at scale, but a small percentage of ambiguous orders may benefit from human review. The purpose of manual review is not to inspect every transaction. It is to examine cases where automated signals conflict or where the financial impact of a wrong decision is unusually high.

A reviewer can assess order history, account changes, customer contact information, unusual shipping requests, authentication outcomes and previous legitimate behavior. Review processes should be documented and consistent so that decisions are explainable and do not depend on arbitrary assumptions about a customer.

9. Secure Customer Accounts Against Account Takeover

Card-not-present fraud can begin before checkout if an attacker gains control of a legitimate customer account. A stored payment method, loyalty balance or trusted account history may make an account attractive for misuse.

Online businesses should protect customer accounts with strong password practices, optional or risk-based multi-factor authentication, secure password-reset flows, login anomaly detection and alerts for significant account changes. Changes to shipping addresses, passwords, email addresses or saved payment methods may deserve additional verification when combined with other risk signals.

10. Build Fraud Controls Around Customer Experience

The objective of fraud prevention is not to make every transaction difficult. Excessive friction can create false declines, abandoned carts and support costs. Merchants should measure both fraud losses and the cost of rejecting legitimate customers.

Promotional banner

Risk-based controls offer a better balance. Low-risk returning customers can often receive a streamlined experience, while unusual transactions receive stronger verification. Merchants should monitor approval rates, fraud rates, chargebacks, challenge rates, review rates and false-positive feedback to keep the system balanced over time.

Card-Not-Present Fraud Prevention: A Layered Control Model

Layer

Primary purpose

Examples

Merchant goal

Authentication

Confirm that the payer is authorized

EMV 3-D Secure, step-up authentication

Challenge risky transactions without adding friction to every checkout

Verification

Compare submitted payment details

AVS, CVV/CVC result, account consistency

Add independent evidence to the risk decision

Risk analysis

Evaluate transaction context

Device signals, behavioral patterns, velocity checks

Detect unusual behavior and automated abuse

Data protection

Reduce exposure of sensitive payment data

Tokenization, secure hosted payment components

Limit the value of data if systems are compromised

Site security

Protect the payment page and dependencies

Script controls, change detection, patching, PCI DSS processes

Prevent checkout tampering and e-skimming

Operations

Handle ambiguous or high-impact cases

Manual review, customer alerts, incident response

Make consistent decisions and recover quickly

How Should Small and Medium-Sized Businesses Prioritize CNP Fraud Controls?

Small businesses do not need to build a bank-grade fraud platform from scratch. A sensible approach is to use the security capabilities already available through a reputable payment service provider, then add merchant-specific rules based on real fraud patterns.

A practical starting sequence is:

  1. Use a PCI DSS-aligned payment provider and minimize direct handling of raw card data.
  2. Enable EMV 3-D Secure or the provider’s risk-based authentication capability where appropriate.
  3. Collect AVS and CVV results as risk signals and configure sensible responses to mismatches.
  4. Use tokenized credentials for saved cards and recurring payments rather than storing raw PAN data unnecessarily.
  5. Enable basic device, velocity and account-risk rules through the payment platform.
  6. Review website scripts, plugins and third-party integrations that can affect checkout security.
  7. Create a short manual-review process for unusually high-risk orders.
  8. Monitor fraud, chargebacks and false declines monthly and tune controls using real outcomes.

How Larger Merchants Can Improve CNP Fraud Detection

Larger e-commerce businesses usually need more granular controls because transaction volume, product diversity and regional exposure create more complex fraud patterns. Mature programs often combine payment-service-provider tools with internal data and specialized risk platforms.

Important capabilities can include risk scoring, entity linking across accounts and devices, behavioral analytics, real-time rules, account-takeover detection, chargeback analytics and model governance. Large merchants should also establish a feedback loop that connects confirmed fraud and legitimate-customer outcomes back into the decision system.

Governance matters as much as technology. Fraud rules should have owners, thresholds should be documented, model changes should be tested, and high-impact decisions should be reviewed for unintended consequences. A fraud program that cannot explain why legitimate transactions are being declined is difficult to improve.

Which Customer Verification Methods Help Reduce CNP Fraud?

The best verification method depends on the transaction, market and risk level. Merchants should avoid treating any single method as universally sufficient.

  • EMV 3-D Secure: issuer-supported authentication and risk-based challenge flows.
  • AVS: comparison of billing-address information with issuer records where supported.
  • CVV/CVC verification: confirms access to card security information, but the code must not be stored after authorization.
  • Account authentication: secure login, MFA or step-up checks for sensitive account changes.
  • Device and behavioral consistency: assesses whether the transaction resembles trusted customer activity.
  • Customer confirmation: used selectively for unusual or high-value orders, rather than as routine friction for every buyer.

How to Reduce False Declines While Fighting Fraud

A false decline occurs when a legitimate transaction is rejected because the fraud system interprets it as risky. False declines can be expensive because the merchant may lose the immediate sale, future customer value and trust.

To reduce false declines, merchants should combine signals instead of using single-factor hard rules. An AVS mismatch alone, for example, may not justify rejecting a long-standing customer using a recognized device and passing issuer authentication. Conversely, several moderate-risk signals appearing together may justify a challenge even when individual checks appear normal.

Merchants should also measure decisions after the fact. Chargebacks and confirmed fraud reveal where controls were too weak, while customer support contacts, successful reattempts and manual-review outcomes reveal where controls were too strict. The objective is continuous calibration, not a one-time rule set.

Promotional banner

PCI DSS and CNP Fraud Prevention

PCI DSS is a payment-data security standard, not a complete fraud-detection system. Compliance does not guarantee that a transaction is legitimate, and fraud tools do not replace PCI DSS obligations. The two are complementary: PCI DSS focuses on protecting account data and the cardholder-data environment, while fraud prevention focuses on determining whether a transaction should be trusted.

For e-commerce merchants, PCI DSS v4.0.1 places particular importance on payment-page security. Even businesses that outsource payment processing need to understand whether scripts and systems on their own site can affect the security of the payment experience. Merchants should work with their acquirer, payment provider and qualified security resources to determine the correct validation approach for their environment.

Merchant CNP Fraud Prevention Checklist

  • ☐ Use a reputable PCI DSS-aligned payment provider.
  • ☐ Minimize storage and direct handling of raw PAN data.
  • ☐ Use tokenization for saved credentials and recurring payments.
  • ☐ Enable EMV 3-D Secure where appropriate.
  • ☐ Use AVS and CVV/CVC results as part of a broader risk decision.
  • ☐ Never store CVV/CVC after authorization.
  • ☐ Use device, account and behavioral signals proportionately.
  • ☐ Configure velocity controls for repeated or automated activity.
  • ☐ Monitor and control third-party scripts that can affect checkout.
  • ☐ Keep e-commerce software, plugins and integrations patched.
  • ☐ Use strong account security and protect password-reset flows.
  • ☐ Create a documented manual-review process for ambiguous high-risk orders.
  • ☐ Monitor fraud rate, chargebacks, approval rate and false declines.
  • ☐ Provide customers with alerts or easy reporting for suspicious account activity.
  • ☐ Review fraud rules regularly as customer behavior and attack patterns change.

Frequently Asked Questions

What is the best way to prevent card-not-present fraud?

There is no single best control. The strongest approach combines issuer authentication, verification checks, transaction risk analysis, payment-data protection and secure e-commerce operations. 3-D Secure, AVS, CVV, tokenization, device signals and velocity controls work best as layers.

Does 3-D Secure stop all CNP fraud?

No. 3-D Secure can add valuable issuer-supported authentication and reduce CNP fraud, but no authentication technology eliminates every form of payment fraud. Merchants still need transaction monitoring, secure account practices and payment-page security.

Does AVS prevent card-not-present fraud?

AVS can help by comparing billing-address information with issuer records, but it should be treated as a risk signal rather than proof that a transaction is legitimate or fraudulent.

Should merchants require CVV for online payments?

CVV or CVC is commonly used in card-not-present authorization as an additional verification signal. Merchants must not store the code after authorization, even if encrypted.

How does tokenization reduce online payment risk?

Tokenization replaces sensitive card details with a token for supported transactions. This can reduce exposure of raw card numbers and lower the usefulness of data if merchant systems are compromised.

What is CNP fraud detection?

CNP fraud detection is the process of evaluating remote-payment transactions for signs that the person making the purchase may not be the authorized account holder. It can use authentication outcomes, payment verification, device and behavioral signals, account history and transaction patterns.

How can a small online store reduce fraud without blocking good customers?

Start with the fraud and authentication tools in a reputable payment platform, use risk-based rather than blanket rules, tokenize stored credentials, secure the checkout page and review only the small subset of transactions that present meaningful risk.

Can PCI DSS compliance stop online fraud?

PCI DSS helps protect payment data and systems, but it does not determine whether every transaction is legitimate. Merchants need both PCI DSS-aligned security and a separate fraud-management strategy.

Authoritative Sources and Further Reading

PCI Security Standards Council: PCI DSS v4.0.1 merchant and e-commerce guidance, including payment-page security and rules concerning sensitive authentication data.

Visa Secure with EMV 3-D Secure: Visa merchant guidance describing risk-based authentication and the role of 3DS in reducing card-not-present fraud.

Visa Tokenization: Visa guidance on replacing sensitive payment details with tokens to help reduce fraud and protect account data.

EMVCo 3-D Secure: Industry specifications and background for modern EMV 3-D Secure authentication.