Why card-not-present sales carry more risk
In a card-present sale, the chip or tap interaction itself authenticates the card. In a card-not-present sale — a keyed phone order, an emailed invoice, or a website checkout — that physical step is missing, so the business has to lean on other signals to judge whether the person entering the card is the actual cardholder.
Fraud rules and dispute categories generally treat card-not-present transactions differently from card-present ones, which is why the tools below matter more here than at a staffed counter.
Front-line checks: AVS, CVV and authentication
These are the baseline checks available through most gateways and virtual terminals. None of them is foolproof on its own, but together they filter out a meaningful share of low-effort fraud attempts.
Address Verification Service (AVS)
Compares the billing address and ZIP code entered at checkout against the address on file with the issuing bank. A mismatch is a signal to review, not necessarily to decline automatically.
CVV / security code
Confirms the person entering the card can see the physical card or a copy of it. Configure your gateway to require it on every keyed and online transaction.
3-D Secure and other cardholder authentication
Where supported by the processor and the customer's card, an authentication step (such as a one-time passcode) can shift dispute liability and add a layer of verification for higher-risk or higher-ticket online sales. Availability varies by processor and program.
Rules-based and velocity screening
Beyond AVS and CVV, many gateways and processors support configurable fraud rules that flag or hold orders before they settle. These may be available through compatible processors and are typically tuned to the business rather than left on factory defaults.
Velocity limits
Flag multiple transactions in a short window from the same card, device, IP address or shipping address.
Order value thresholds
Route unusually large or unusually round-number orders to manual review before fulfillment.
Geolocation and mismatch checks
Compare the billing country, shipping address and the IP address location for inconsistencies worth a second look.
Negative and allow lists
Maintain a list of cards, emails or devices previously tied to confirmed fraud or, conversely, known trusted repeat customers.
Tokenization and card-on-file
For repeat customers, invoicing clients or subscription billing, storing a card as a token — rather than re-keying the number each time — reduces how often raw card data is handled and lowers the window of opportunity for it to be intercepted or mistyped.
Tokenized card-on-file also supports cleaner recurring billing and account-updater style workflows where available, so expired or reissued cards can be refreshed without asking the customer to re-enter details over email or phone.
Shipping, pickup and delivery verification
For physical goods, the fulfillment step is an additional checkpoint. Confirming that a shipping address matches the billing address, or requiring ID and the physical card at pickup, catches attempts that pass the online checks but fall apart at delivery.
Ship-to vs bill-to mismatch
Not automatically fraudulent, but a reasonable trigger for manual review on a first-time or high-value order.
In-store or curbside pickup
Ask to see the card used online and a matching photo ID before releasing the order.
Signature or delivery confirmation
For higher-ticket shipments, a delivery confirmation record supports any later dispute response.
Staff procedures for suspicious orders
Tools only work if staff know what to do when something looks off. A short, written procedure removes the guesswork during a busy shift.
At minimum, document what was checked, what was found, and the decision made, so the same record can support a dispute response later. Reporting tools can help track flagged and reviewed orders over time.
Hold, don't guess
Any order that fails more than one check is held for manager review before it ships or is fulfilled.
Call back to verify
For phone orders, call the number on file — not one provided by the caller — before processing a large or first-time order.
Log the decision
Note who reviewed the order, what was checked, and why it was approved or declined.
Escalate patterns, not just single orders
Repeated attempts from a related email, device or address are worth reviewing together, not one at a time.
Frequently asked questions
What is card-not-present fraud?
It is fraud that occurs when a stolen or fabricated card number is used without the physical card present, such as on an invoice, phone order or ecommerce checkout, where the merchant cannot inspect the physical card.
Do AVS and CVV checks stop all fraud?
No. They filter out a meaningful share of low-effort attempts but are not a guarantee. They work best combined with velocity rules, authentication where supported, and staff review.
Does 3-D Secure guarantee a dispute will be won?
No outcome is guaranteed. Cardholder authentication is a tool that may shift liability in certain circumstances depending on the card network and program rules, subject to how it was implemented and the specific dispute.
Is tokenizing a card safer than storing the card number ourselves?
Yes, generally. Tokenization replaces the card number with a reference value, so the business is not holding raw card data, which reduces exposure if a system is ever compromised.
Should we manually review every card-not-present order?
Not necessarily. Rules-based screening can route only the orders that carry unusual signals — mismatches, velocity, or high value — to manual review, so staff time is focused where it matters most.
Where can I get these tools set up for my business?
BSV Solution can review your current checkout, invoicing and virtual terminal setup and outline which fraud tools may be available through compatible processors. A free statement analysis is a good starting point.
Want a second opinion on your setup?
Tell us how you take payments today and a BSV Solution specialist will walk through the options with you. Eligibility and processor selection are reviewed individually, subject to underwriting approval.