Card Not Present Fraud Detection at Checkout
What your risk engine looks at before an order is authorized, and what you can set yourself.
A customer types a card number into your checkout. You cannot see the card, the buyer, or the signature. Card not present fraud detection is the set of checks and models that decide whether that payment should go through. A sale made with a stolen card can come back to you later as a chargeback. Here is what detection actually looks at, and what you control.
What card not present fraud detection means
Card not present fraud is fraud on a payment where the physical card is never shown to the seller. Online orders are the main case. Detection means spotting a bad payment before it goes through. It uses the data your checkout collects. It also uses the risk tools your processor runs. For a plain-language breakdown of the term, see the card not present fraud definition.
The data you collect at checkout
Detection starts with what you ask for. Collect the CVC, postal code, and billing address for every payment. The CVC is the three- or four-digit code printed on the card itself. Those three fields give your checks something to compare against, and they feed the risk models described below.
What CVC and AVS checks can and cannot tell you
When the CVC or postal code check comes back failed, the payment might be a fraudulent one. Can, not does. An AVS check can also come back failed on a payment from an honest buyer. The same unit number can be written in several formats by different shoppers.
The checks also have blind spots. Checking the CVC will not stop a stolen physical card. A thief who has the card has the code as well. Most cards issued in the United States, Canada, and the United Kingdom support street address verification. Treat these checks as signals, not verdicts.
How machine learning scores transactions in real time
A machine learning system can read each payment as it happens. It flags card payments that may be fraud in real time. The models assign risk scores to transactions based on factors like location and past behavior. Radar's AI models evaluate hundreds of risk factors when scoring a charge.
Adyen's premium features include machine learning powered fraud detection using global transaction data. Models can be retrained on new data so they stay up to date and better detect emerging fraud patterns. Some systems build a unique fingerprint for each user. They use device details like model, operating system, and IP address. They can also use graph analysis. That means looking at how buyers connect to each other, to find fraud rings. For a wider look at the field, see AI fraud detection.
Risk levels and thresholds: block, allow, or review
A risk score is only useful if it drives a decision. In Adyen Protect, each payment goes through a risk evaluation that decides to block, allow, or review the transaction. Each transaction gets a risk level before it is sent to authorization. The levels range from Very Low to Very High.
In Adyen, you set the threshold. A transaction is blocked before it is sent to authorization when it is riskier than the threshold you define. Pick it to match your margin and your appetite for manual work.
How risk engines like Adyen Protect and Stripe Radar work
Protect is Adyen's risk engine and is enabled by default. Protect is Adyen's risk management system. You can use it to detect fraud, watch for it, and cut it down. The default block threshold for the fraud risk rule is set to high risk and above. That rule currently runs on transactions that can be disputed. Credit and debit card payments are one example.
Radar's AI models also score each charge. Radar allows you to block payments that fail the card issuer verification by enabling a rule through the Dashboard. Check each provider's current pricing page, since plan levels decide which features you get.
Strengthening detection
Send high quality data. It helps Protect's machine learning models tell fraud apart from honest payments.
You can add more protection with optional risk features. Two examples are case management and dynamic 3-D Secure.
What detection cannot catch
No tool catches everything. Not all fraud cases can be detected by the machine learning fraud risk rule. Models can spot patterns tied to friendly fraud. This is the pattern where a shopper places an order, then later claims someone else made the purchase. Still, a first purchase on a real card can look clean.
That is where card not present fraud prevention comes in. Detection screens the payment. Prevention covers everything around the payment. Your return policy. Your shipping rules. And what you do with orders that pass every check but still feel wrong.