What a credit card security check does
A credit card security check is a group of tests that runs between the moment a customer submits a payment and the moment the issuer approves or declines it. Each test compares one data point against a record held by the bank, the card network, or the merchant. A failed test does not always stop the sale. It adds weight to a risk score.
Card verification codes
Visa calls the code CVV2. Mastercard calls it CVC2. American Express prints 4 digits on the front of the card and calls it CID. The code sits on the card and does not appear in the magnetic stripe or the chip. A merchant that asks for the code is checking that the buyer holds the physical card, not just the 16-digit number. PCI DSS v4.0 forbids storing the code after the authorization response. A merchant that keeps CVV2 data is out of compliance.
What the code does not prove
A correct code does not prove the buyer is the cardholder. Card data taken in a database breach includes the code when the breached merchant stored it. A code check raises the cost of fraud. It does not end fraud.
Credit Card Authentication Check: How It Works
Address Verification Service
AVS compares the billing address at checkout with the address on file at the issuer. In the United States the check reads the street number and the 5-digit ZIP code. The issuer returns a single-letter code. A full match returns Y. A ZIP match with a street mismatch returns Z. Merchants set their own rules for each result. AVS covers the US, Canada, and the UK. Issuers in other markets may not support it.
credit card authentication test
3D Secure and step-up authentication
3D Secure moves the check to the issuer. The merchant sends the transaction to the issuer. The issuer asks the cardholder for a password, a one-time code, or a biometric scan. Visa sells this as Visa Secure. Mastercard sells it as Identity Check. American Express sells it as SafeKey. Version 2 of the protocol sends device data and transaction history to the issuer, so low-risk orders pass with no challenge. The issuer returns a cryptogram that proves the authentication.
Velocity checks and fraud scoring
Fraud tools watch patterns, not single orders. A model may flag 5 orders from one IP address in 10 minutes, or one card used in 2 countries in 1 hour. Controls of this kind are called velocity checks. The output is a score. A high score sends the order to manual review.
Decline codes
Issuers return codes with each response. Common ones: 05 (do not honor), 14 (invalid card number), 51 (insufficient funds), 54 (expired card), N7 (CVV2 mismatch), and U1 (AVS mismatch on the street address). An N7 code points to a data problem or a fraud attempt. A typo is possible but not the common cause, because the customer reads 3 digits off the card.
Legal status of card data
In the United States, 18 U.S.C. § 1029 covers access device fraud. Trafficking in card numbers, CVV codes, or full card data carries prison terms of up to 10 years for some offenses and up to 15 years for others. Buying or selling CVV data is a federal crime. Card networks also fine merchants that store prohibited authentication data.