What is a CVV?
CVV stands for Card Verification Value, which American Express calls the Card Identification Number (CID). It is the security code found on your credit or debit card. Visa and Mastercard use a 3-digit number located on the back of the card, while American Express uses a 4-digit number located on the front of the card. It helps to verify that you have the physical card, and can help reduce fraud during online, phone, or mail orders where the card is not physically presented.
Did you know that a customer can successfully make a purchase, even if they entered their CVV incorrectly?
It might seem like entering an incorrect CVV should always cause a payment to fail. In practice, that's not always true - some payments still succeed even when the CVV was wrong. This isn't a bug or a sign of a fraudulent customer; it's expected behavior built into how card networks and issuers verify payments today.
Why can a card payment sometimes succeed with an incorrect CVV?
The CVV was originally introduced to prove that the person paying physically has the card in their hand - it's a check on the card itself.
Since then, 3D Secure (3DS) has been introduced as part of Strong Customer Authentication (SCA). Unlike the CVV, 3DS is designed to verify the identity of the person making the payment, not the card.
In other words: the CVV checks the card, 3DS checks the person.
A card payment used to rely on a single check - the CVV. Today, issuers evaluate hundreds of data points for each transaction, including the result of 3DS authentication. If most of those data points look correct, some issuers will still approve the payment even if the CVV was entered incorrectly - for example, if a customer accidentally chooses the wrong number while typing it in during a busy checkout period.
How strict this check is depends on who's involved:
- Issuers (the customer’s bank) set their own rules: some always require a correct CVV, some accept an incorrect CVV if 3DS succeeded, and some don't check CVV at all anymore.
- Payment Service Providers (PSPs) and acquirers (like Mollie, who process the payment on the merchant’s behalf): can also choose how strictly to enforce this check - more strictly to reduce fraud risk, or more leniently to reduce friction and improve conversion.
Why is this good to know?
If a customer contacts you confused about why their payment succeeded despite entering the wrong CVV, you can reassure them this is normal. It doesn't mean the payment page is broken or that anything fraudulent has occurred.