Address Verification Service compares billing-address information supplied at checkout with issuer records, while the card verification code checks the security digits provided by the customer. Both can add useful evidence for card-not-present fraud screening, but neither signal should be treated as conclusive proof of identity.
AVS compares billing address data with issuer records
Stripe's August 2026 AVS guide describes the service as comparing the billing address entered by the customer with information held by the card issuer. In the UK, postcode and address-line results can be returned through the processor.
AVS checks the billing address, not whether the goods are being shipped to a safe or legitimate destination. A fraudster can still know the real cardholder's billing address.
CVC checks the security code presented with the card
The issuer can return a result showing whether the supplied CVC matches its records. Merchants generally collect CVC during new card entry but should not store the code after authorisation in violation of PCI requirements.
A correct CVC is a positive signal, not proof the person using it is authorised. Stolen card details can include the security code.
Pass, fail and unavailable results need different treatment
Processors can return pass, fail, unavailable, unchecked or not-provided states depending on issuer support and transaction timing. A hard rule that blocks every unavailable result can reject legitimate international customers whose issuer does not support the check.
Use risk scoring rather than one global yes-or-no rule where the business has a diverse customer base.
Legitimate customers can mismatch
A customer can move house without updating the card issuer, type an old postcode or use a corporate card registered to a head office. AVS mismatch therefore creates false-positive risk.
Combine address results with device history, 3-D Secure, customer tenure, order value and shipping behaviour before cancelling a valuable order.
Use stronger action when several risk signals align
A new account, failed CVC, failed postcode and expensive order shipping to a different country is materially riskier than one isolated address mismatch for a repeat customer.
Fraud platforms can challenge, review or block based on combinations of attributes. Test the economic cost of false declines as well as fraud prevented.
Preserve fraud-check outcomes with the transaction
Store the AVS and CVC result codes exposed by the processor without storing prohibited sensitive data. These results can support fraud analysis and some dispute investigations.
Review trends by country and issuer. A rise in unavailable AVS results does not necessarily mean fraud increased; issuer support or traffic mix can change.
Worked example: a £2,000 first-time order has a correct CVC but postcode mismatch and ships to an address different from billing. The merchant should not automatically approve because CVC passed, or automatically decline because AVS failed. It can step up authentication or review the order using the combined evidence.
Use AVS more carefully for overseas traffic. Support varies by country, and domestic UK rules can perform differently on foreign-issued cards.
Keep PCI scope in mind. CVC can be collected for authorisation but should not become a field copied into CRM notes for future reference.
Worked example: a repeat UK customer places a £90 order from the usual device, CVC passes but postcode returns unavailable. That is a different risk profile from a new £2,500 order with failed CVC, failed postcode and overnight shipping. The merchant should let combined context drive the action instead of treating one AVS state as decisive.
Keep address data normalised before sending it for checks. Different formatting of flat numbers, spaces or abbreviations can increase false mismatches even where the customer supplied the correct billing address.
Use manual review sparingly for ambiguous responses. Staff should see order history, issuer results and delivery details in one place so they can make a consistent decision rather than call every AVS mismatch suspicious.
Measure decline recovery after rule changes. If relaxing one AVS rule increases genuine approvals without increasing chargebacks materially, the previous rule was probably too aggressive.
Review whether fraud rules treat corporate cards differently from consumer cards. A business card can legitimately use a head-office billing address while goods ship to a branch or employee, creating patterns that would look suspicious in ordinary consumer ecommerce.
Keep CVC failure rules stricter for first-time high-value orders than for low-risk recurring relationships where the merchant has other strong evidence. Risk controls should reflect transaction context.
Review AVS and CVC rules after major changes in customer geography. A rule calibrated to domestic UK traffic can create excessive declines when the business launches in markets where issuer support and address formats differ.
Editorial Verdict
AVS and CVC are valuable low-friction signals for ecommerce fraud, but they are not identity checks on their own.
Interpret issuer response codes in context, avoid blunt rules that create unnecessary false declines and combine them with authentication and behavioural evidence.
Sources
- Stripe, Address Verification Service guide, August 2026: https://stripe.com/gb/resources/more/what-is-address-verification-service
- Stripe, Radar rules and AVS/CVC response values: https://stripe.com/gb/guides/radar-rules-101
- Stripe Support, CVC collection requirements: https://support.stripe.com/questions/cvc-collection-requirements?locale=en-GB