What the card verification process is

Card verification is the set of checks a merchant, payment gateway, and card issuer run to confirm that a payment card is valid and authorized for a specific transaction. Verification happens before any money moves. It combines data checks on the card itself, checks against the cardholder's billing details, and an authorization request sent to the issuing bank. Passing verification does not prove that the person at the keyboard owns the card. It only means the submitted data matches issuer records and the issuer approves the charge.

related article

Checks that run during verification

Card security code check

The three-digit code on the back of Visa, Mastercard, and Discover cards, or the four-digit code on the front of American Express cards, is compared with the issuer's record. PCI DSS rules bar merchants from storing this code after authorization.

card check

Address Verification Service

AVS compares the billing street number and ZIP code the customer enters with what the issuer has on file. The response is a partial match code, not a plain yes or no.

card verification process

3-D Secure challenge

For card-not-present orders, the issuer may send a one-time code or push a prompt to the cardholder's banking app. The merchant receives an authentication result instead of raw card data.

card inspection

Network tokenization

The card number is replaced with a token tied to a specific merchant or device, so the real number is not stored in the merchant's systems.

Step-by-step: what happens when a card is verified

  1. The customer submits the card number, expiration date, security code, and billing address at checkout.
  2. The payment gateway encrypts the data and runs the card number through the Luhn formula to catch typing errors.
  3. The gateway sends the security code and billing address to the issuer for comparison.
  4. The processor routes an authorization request through the card network to the issuing bank.
  5. The issuer checks available credit, account status, and fraud rules, then returns an approval or decline code.
  6. If 3-D Secure applies, the issuer prompts the cardholder for a one-time code or an app approval.
  7. The merchant receives the authorization result and captures the payment or releases the hold.
  8. The processor records the transaction without the security code and includes it in the next settlement batch.

What the result codes mean

  • CVV match: the submitted code matches issuer records.
  • CVV mismatch: the code fails, and most processors decline the order outright.
  • AVS full match: street number and ZIP code both match.
  • AVS partial match: one element matches, so merchants often accept the charge and flag it for manual review.
  • Do not honor: the issuer blocks the charge because of fraud rules, a frozen account, or a credit limit.

What verification does not do

Verification checks data, not identity. Card details exposed in a breach can pass a CVV check and an AVS check when the billing address travels with them. That gap is why card networks push 3-D Secure and why processors layer in velocity limits, device fingerprinting, and manual review for high-value orders. Merchants that skip these layers carry the loss when a chargeback follows. Buying, selling, or using payment card data that belongs to someone else is a federal crime in the United States under 18 U.S.C. 1029, and merchants that handle card data outside PCI DSS rules risk fines and loss of processing privileges.