Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should merchants tune AVS and CVV filters…
Identity Beyond IAM

How should merchants tune AVS and CVV filters so they reduce fraud without rejecting good orders?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Identity Beyond IAM

Merchants should treat AVS and CVV as one input, not the final decision. Static rules work poorly when fraud tactics change and customers mistype details on mobile. Review decline reasons regularly, test how much revenue is lost to false positives, and use fraud controls that adapt to behavior patterns instead of freezing legitimate shoppers out at checkout.

How AVS and CVV should actually be used in fraud decisioning

AVS and CVV are best treated as signal checks, not stand-alone approval gates. They help separate obvious card-not-present abuse from low-risk orders, but they are weak proxies for intent on their own because they do not tell you whether the customer, the device, or the purchase pattern looks normal. The tuning goal is balance, not perfection.

That balance is easier when you score the signals in context. A full AVS mismatch with a matching device, repeat customer history, and normal basket size may deserve a softer response than a partial mismatch paired with rapid checkout attempts, unusual shipping changes, or other fraud indicators. Good tuning means aligning the filter with the merchant’s actual loss pattern, not with a generic rulebook.

It also matters that AVS and CVV fail for non-fraud reasons. Mobile shoppers mistype addresses, use saved cards with outdated billing details, or enter CVV correctly but still trip a strict address rule. If the filter cannot distinguish those cases, it will shift losses from fraud to false declines and push legitimate revenue out of the funnel.

How to tune the rules without freezing out good customers

The most effective approach is to tune by decline reason, channel, and transaction type rather than applying one threshold everywhere. High-value or high-risk orders may justify stricter checks, while repeat customers, low-risk geographies, or low-risk baskets often benefit from a lighter touch. The important part is to measure whether each rule is actually reducing bad approvals or simply adding friction.

Practically, that means testing thresholds in small steps and watching both fraud rate and approval rate. If a rule blocks too many legitimate orders, relax the condition or move it from a hard decline to a step-up review. If a rule catches almost no fraud, it is only creating friction and should be weakened or retired.

Merchants should also review the false-positive side of the ledger. A filter that performs well in a fraud summary can still be expensive if it suppresses repeat buyers, subscription renewals, or mobile checkout traffic. The right tuning outcome is usually a narrower hard-decline set, with more ambiguous cases routed to review or secondary checks rather than rejected outright.

For broader control design, it helps to anchor this work in established security and decisioning practices. NIST Cybersecurity Framework 2.0 is useful for framing governance and continuous improvement, while OWASP Cheat Sheet Series offers practitioner guidance on building layered controls instead of relying on a single check. For a payment-specific control lens, merchants should also align rules with the intent of card security controls in NIST SP 800-53 Rev 5 Security and Privacy Controls.

Risk and Threat Considerations

Overly strict AVS and CVV filtering creates two kinds of exposure: preventable fraud can still pass when criminals adapt, and legitimate orders can be blocked when customer data is messy or checkout friction is high. The business risk is not just lost revenue, it is also customer abandonment, support load, and reduced trust in the checkout experience.

Failure mechanism: Static rules overfit to one fraud pattern and one customer behaviour profile. Attackers vary tactics, while real customers introduce address mismatches, mobile typing errors, and payment data drift, so a rigid filter can miss abuse and reject good orders at the same time.

Impact: Merchants absorb chargebacks or manual review costs on the fraud side, then lose conversion and repeat business on the false-decline side. At scale, the worst outcome is a filter that appears “safe” because it is strict, but actually reduces net revenue without materially improving fraud loss.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OV-01 — Outcomes and Governance OversightFraud rule tuning needs ongoing oversight and measurable outcomes.
PR.AA-01 — Identity Proofing and CredentialsAVS and CVV are credential-like authentication signals in payment flows.
Recommendation — Track fraud and false-decline outcomes together and adjust controls through continuous governance. Require stronger verification when card authentication signals are weak or mismatched.
CIS Controls v85.3 — Account ManagementCheckout decisioning depends on reliable account and transaction signals.
Recommendation — Use account and transaction signals to support risk-based fraud decisions.

Practitioner Guidance

What to prioritise: Use the decline reason as the unit of tuning. If AVS or CVV is the only failing signal, treat that as a weaker decision than a multi-signal fraud pattern, and reserve hard declines for combinations that genuinely indicate elevated risk.

What to verify: Confirm how many rejected orders later proved legitimate, then segment that by device, channel, basket value, repeat customer status, and shipping behaviour. That view shows whether your filter is protecting margin or just pushing good customers away.

Decision rule: If a rule reduces fraud only by materially increasing false positives, move it from an automatic decline to a softer step-up path or manual review. If it barely changes fraud outcomes, retire it instead of keeping it for comfort.

Practitioner takeaway: AVS and CVV work best as inputs to a broader fraud model, not as binary gates, because the right tuning standard is net loss reduction after false declines are counted.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org