Strict AVS and CVV checks create loss because they confuse bad data with bad intent. Customers enter wrong addresses or security codes, while fraudsters can still adapt around fixed rules. The result is unnecessary declines, abandoned carts, and lower lifetime value. In the cited analysis, that friction translated into measurable revenue leakage for merchants.
Why fixed AVS and CVV rules hurt card-not-present conversion
AVS and CVV are blunt verification checks, so they often fail on honest customers before they fail on fraud. In card-not-present commerce, that matters because checkout is already fragile: a small amount of friction can turn into a decline, a lost basket, or a customer who does not return. The revenue loss comes from the combined effect of false positives and lower completed order volume.
The core problem is that strict rules treat mismatched data as a reliable fraud signal even when the mismatch is normal. A customer may mistype a billing address, use a corporate card with a different postal code, or enter a CVV incorrectly on a mobile device. If the merchant responds with an immediate decline instead of a step-up path, the transaction can be lost even though the purchase was legitimate.
Strict rules also do not remove the fraudster’s adaptation problem. Fraud actors can test cards, shift to cleaner stolen data, or spread attempts across low-risk-looking transactions. That means tighter static checks often increase customer friction faster than they reduce successful abuse, which is why the economic outcome can worsen even when control strength appears to improve on paper.
Where the revenue leakage actually comes from
Revenue leakage is usually not one event, but several small losses that accumulate. The first is false decline, where a valid transaction is blocked because AVS or CVV does not match exactly. The second is abandonment, where the customer never completes checkout after repeated prompts or a hard fail. The third is lifetime value erosion, because a frustrated buyer may not come back after a failed first attempt.
This is especially pronounced in card-not-present flows because the merchant cannot see the cardholder, inspect the card, or resolve ambiguity at the counter. A strict rule set may improve rejection rates in a narrow sense, yet still underperform overall if it suppresses high-value repeat buyers, subscription signups, or cross-border orders. For many merchants, the hidden cost is not just the declined sale, but the lost relationship behind it.
Merchants also need to remember that AVS and CVV are verification signals, not final proof of legitimacy. They are useful inputs, but they are not strong enough to carry the entire approval decision when customer data quality, shipping behavior, or transaction context is noisy. That is why overreliance on either control tends to produce poor business outcomes in legitimate, high-friction segments.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| PCI DSS v4.0 | 7 — Restrict Access by Business Need to Know | Fraud control tuning must still preserve least-privilege handling of payment data and transaction access. |
| 8.6 — System and Application Accounts and Authentication Factors | Card-not-present payment flows rely on payment authentication and account controls that affect transaction trust. | |
| Recommendation — Align checkout and payment access decisions to least-privilege business need. Apply strong authentication controls to payment-facing accounts and automation. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | AVS and CVV are authentication-adjacent signals used in access and trust decisions for card-not-present payments. |
| Recommendation — Calibrate authentication and access decisions to reduce false declines without weakening fraud controls. | ||
| CIS Controls v8 | 6 — Access Control Management | Merchant payment operations need controlled access decisions that balance fraud reduction with customer conversion. |
| Recommendation — Tune access and verification controls to limit abuse while preserving legitimate transactions. | ||
Practitioner Guidance
What to prioritize: Treat AVS and CVV as one part of a risk decision, not the decision itself. If the strict rule is blocking materially valuable traffic, the better question is whether the merchant can preserve fraud screening while allowing a second-pass approval path for high-confidence customers.
What to verify: Separate approval loss caused by honest data-entry error from loss caused by genuine abuse. Review false-decline rates by channel, geography, device type, and customer cohort, then compare them to chargeback and fraud outcomes so the control is judged on net revenue impact, not just rejection volume.
Common mistake: Using a single mismatch threshold for every transaction. That approach is easy to operationalize, but it is usually too rigid for repeat customers, subscription renewals, and markets where billing and shipping data naturally diverge.
Practitioner takeaway: The merchant objective is not to maximize AVS or CVV pass rates, it is to maximize trusted revenue, which usually means tolerating some mismatch when the broader transaction context is still credible.
Related resources from NHI Mgmt Group
- Why do overly strict fraud rules create revenue loss and customer churn in ecommerce?
- Why does card-not-present fraud create such a persistent risk for ecommerce merchants?
- Why do card-not-present transactions create more false declines?
- Why do legally required identity checks still leave mobility platforms exposed to fraud and revenue loss?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 17, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org