Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM Why do strict AVS and CVV checks create…
Identity Beyond IAM

Why do strict AVS and CVV checks create revenue loss for card-not-present merchants?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Identity Beyond IAM

Strict AVS and CVV checks create loss because they confuse bad data with bad intent. Customers enter wrong addresses or security codes, while fraudsters can still adapt around fixed rules. The result is unnecessary declines, abandoned carts, and lower lifetime value. In the cited analysis, that friction translated into measurable revenue leakage for merchants.

Why fixed AVS and CVV rules hurt card-not-present conversion

AVS and CVV are blunt verification checks, so they often fail on honest customers before they fail on fraud. In card-not-present commerce, that matters because checkout is already fragile: a small amount of friction can turn into a decline, a lost basket, or a customer who does not return. The revenue loss comes from the combined effect of false positives and lower completed order volume.

The core problem is that strict rules treat mismatched data as a reliable fraud signal even when the mismatch is normal. A customer may mistype a billing address, use a corporate card with a different postal code, or enter a CVV incorrectly on a mobile device. If the merchant responds with an immediate decline instead of a step-up path, the transaction can be lost even though the purchase was legitimate.

Strict rules also do not remove the fraudster’s adaptation problem. Fraud actors can test cards, shift to cleaner stolen data, or spread attempts across low-risk-looking transactions. That means tighter static checks often increase customer friction faster than they reduce successful abuse, which is why the economic outcome can worsen even when control strength appears to improve on paper.

Where the revenue leakage actually comes from

Revenue leakage is usually not one event, but several small losses that accumulate. The first is false decline, where a valid transaction is blocked because AVS or CVV does not match exactly. The second is abandonment, where the customer never completes checkout after repeated prompts or a hard fail. The third is lifetime value erosion, because a frustrated buyer may not come back after a failed first attempt.

This is especially pronounced in card-not-present flows because the merchant cannot see the cardholder, inspect the card, or resolve ambiguity at the counter. A strict rule set may improve rejection rates in a narrow sense, yet still underperform overall if it suppresses high-value repeat buyers, subscription signups, or cross-border orders. For many merchants, the hidden cost is not just the declined sale, but the lost relationship behind it.

Merchants also need to remember that AVS and CVV are verification signals, not final proof of legitimacy. They are useful inputs, but they are not strong enough to carry the entire approval decision when customer data quality, shipping behavior, or transaction context is noisy. That is why overreliance on either control tends to produce poor business outcomes in legitimate, high-friction segments.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
PCI DSS v4.07 — Restrict Access by Business Need to KnowFraud control tuning must still preserve least-privilege handling of payment data and transaction access.
8.6 — System and Application Accounts and Authentication FactorsCard-not-present payment flows rely on payment authentication and account controls that affect transaction trust.
Recommendation — Align checkout and payment access decisions to least-privilege business need. Apply strong authentication controls to payment-facing accounts and automation.
NIST CSF 2.0PR.AA — Identity Management, Authentication, and Access ControlAVS and CVV are authentication-adjacent signals used in access and trust decisions for card-not-present payments.
Recommendation — Calibrate authentication and access decisions to reduce false declines without weakening fraud controls.
CIS Controls v86 — Access Control ManagementMerchant payment operations need controlled access decisions that balance fraud reduction with customer conversion.
Recommendation — Tune access and verification controls to limit abuse while preserving legitimate transactions.

Practitioner Guidance

What to prioritize: Treat AVS and CVV as one part of a risk decision, not the decision itself. If the strict rule is blocking materially valuable traffic, the better question is whether the merchant can preserve fraud screening while allowing a second-pass approval path for high-confidence customers.

What to verify: Separate approval loss caused by honest data-entry error from loss caused by genuine abuse. Review false-decline rates by channel, geography, device type, and customer cohort, then compare them to chargeback and fraud outcomes so the control is judged on net revenue impact, not just rejection volume.

Common mistake: Using a single mismatch threshold for every transaction. That approach is easy to operationalize, but it is usually too rigid for repeat customers, subscription renewals, and markets where billing and shipping data naturally diverge.

Practitioner takeaway: The merchant objective is not to maximize AVS or CVV pass rates, it is to maximize trusted revenue, which usually means tolerating some mismatch when the broader transaction context is still credible.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org