Skip to content
Payment Processing

CNP (Card Not Present)

Transaction where physical card is not used (online, phone, mail order). Higher fraud risk than card-present; requires different security measures.

Overview

What is CNP?

Card Not Present (CNP) transactions occur when the physical card isn't presented during the transaction - including all online purchases, phone orders, mail orders, recurring subscriptions, and mobile app purchases. CNP carries significantly higher fraud risk than card-present (CP) transactions because merchants cannot verify physical card possession, cardholder identity, or card authenticity through chip reading or signature. This elevated risk results in higher interchange fees (2.5-3.5% vs. 1.8-2.3% for CP), stricter fraud screening requirements, elevated chargeback rates (1.5-2.5% vs. 0.3-0.6% for CP), and merchant liability for fraudulent transactions.

All high-risk online merchants process CNP transactions exclusively, making CNP fraud prevention existential. Unlike card-present transactions where EMV chip technology provides strong authentication, CNP security relies on digital verification methods: AVS (Address Verification System), CVV codes, 3D Secure authentication, device fingerprinting, IP address geolocation, fraud scoring algorithms, velocity checking, and behavioral analysis. These tools significantly reduce fraud but cannot eliminate it - sophisticated merchants balance fraud prevention (keeping fraud rates at 0.3-0.8%) against false declines (which can reach 5-10% with overly aggressive screening).

CNP liability rules differ fundamentally from card-present. For CP transactions, EMV liability shift transfers chargeback responsibility to issuing banks when merchants properly process chip cards. For CNP, merchants bear full liability regardless of fraud prevention measures implemented - if a cardholder disputes as fraud, you lose funds AND pay chargeback fees ($15-100). The only CNP liability shift available is 3D Secure 2.0: when customers complete authentication, liability for fraud chargebacks transfers to issuing banks (though liability shift doesn't apply to non-fraud dispute types like "product not as described").

Fraud patterns in CNP differ from card-present fraud. Common CNP fraud includes: card testing (fraudsters making small purchases to verify stolen cards work before larger fraud), account takeover (criminals accessing legitimate customer accounts to make fraudulent purchases), friendly fraud (customers making legitimate purchases then falsely claiming fraud), BIN attacks (using stolen BIN ranges to generate valid card numbers), and refund fraud (criminals requesting refunds to different accounts after making purchases with stolen cards). Each pattern requires specific detection and prevention strategies.

In depth

Everything you need to know.

CNP transactions process similarly to card-present but with additional verification steps. Customer enters card details manually (online form, phone order, mail order). Merchant's payment gateway captures card number, expiration, CVV, and billing address. Gateway performs preliminary validation: Luhn algorithm check (verifying card number is mathematically valid), expiration date check (rejecting expired cards), and format validation (ensuring CVV is 3-4 digits).

The gateway then submits authorization request to PSP including AVS data (billing address and ZIP code) and CVV code. PSP routes to appropriate acquirer and card network, which forwards to issuing bank. Issuer performs verification: checks if card is active and not reported stolen, verifies CVV matches (though not all issuers check this), compares billing address against cardholder's address on file, applies fraud scoring based on transaction characteristics, and either approves or declines based on available credit and fraud assessment.

For approved transactions, issuer returns authorization code plus AVS response (indicating whether address matched) and CVV response (whether CVV was correct). Merchant's fraud system evaluates these responses: full AVS match with CVV match indicates low fraud risk, AVS mismatch or CVV failure suggests potential fraud requiring additional verification or decline, international transactions with no AVS support assessed through alternative fraud signals.

3D Secure adds authentication layer when configured: after initial authorization, transaction redirects to issuer's authentication page for customer identity verification via SMS code, biometric, or app approval. Successful authentication shifts liability to issuer; failed authentication returns liability to merchant who decides whether to proceed or decline.

CNP fraud prevention determines business viability for online merchants. Uncontrolled fraud rates of 3-5% create existential chargeback problems - exceeding network monitoring thresholds leads to TMF listing and payment processing termination. A merchant processing $5M annually with 3% fraud rate faces $150K in fraud losses, $75K-150K in chargeback fees, and likely enters Visa VDMP with $25K-100K monthly fines. Proper CNP fraud controls reduce fraud to 0.5-0.8%, saving $125K-142K annually while avoiding monitoring programs.

Interchange fees penalize CNP transactions. Card-present transactions with EMV chip qualify for lowest interchange rates (1.5-2.0%). CNP transactions pay premium interchange (2.5-3.5%) due to elevated fraud risk. For a merchant processing $10M annually, this 1% interchange premium costs $100K annually vs. card-present equivalent - unavoidable cost of online business model but emphasizes importance of fraud control to prevent compounding with fraud losses.

False declines from aggressive CNP fraud screening cost massive revenue. Declining legitimate customers (false positives) creates hidden losses: industry research shows 40% of falsely declined customers never retry, 25% try once more, only 35% persist until success. A merchant processing $5M annually declining 8% as suspected fraud (when only 0.8% is actual fraud) loses $280K-350K in legitimate revenue annually from false positives - 7X larger than fraud losses prevented. Optimizing CNP fraud tools to balance prevention and approval is critical.

3D Secure liability shift for CNP is game-changing. Without 3DS, merchants bear 100% liability for fraud chargebacks - $150K fraud on $5M volume means $150K losses plus $15K-30K chargeback fees. With 3DS authentication, liability shifts to issuers for authenticated transactions, reducing merchant fraud exposure by 60-80% to $30K-60K annual losses. The $5K-8K annual cost of 3DS implementation delivers 5-10X ROI purely from reduced fraud liability.

Illustrative example — not a specific client engagement.

  • A $8M annual nutra merchant processing CNP exclusively faced 2.4% fraud rate, costing $192K in fraud plus $96K in chargeback fees annually. Implementing 3D Secure on international and first-time customer orders (40% of volume) reduced fraud to 1.1%, saving $104K annually. Adding velocity limits and device fingerprinting further reduced fraud to 0.7%, total savings $136K annually.
  • An online course platform declined all AVS mismatches, creating 8% false decline rate and $240K lost revenue annually on $3M volume. Segmented approach - declining AVS failures only on new customers over $500, accepting mismatches for repeat customers - reduced false declines to 3% while maintaining 0.6% fraud rate, recovering $150K revenue.
  • A supplement merchant ignored CVV verification to improve approval rates. Fraud spiked to 3.8% ($190K losses on $5M volume) from fraudsters using stolen card numbers without CVV codes. Implementing CVV requirement reduced fraud to 1.2% and slightly decreased approval rates 2%, but net financial impact was $135K annual savings ($190K fraud prevention minus $55K lost revenue from lower approvals).
  • Require CVV for all CNP transactions - non-matching CVV should auto-decline or trigger manual review
  • Implement risk-based AVS rules: decline AVS failures on high-value international orders, allow mismatches for repeat customers with clean history
  • Use 3D Secure selectively: authenticate all international transactions, first-time customers, and orders over $500; skip for repeat domestic customers under $200
  • Layer multiple fraud signals: device fingerprinting + IP geolocation + velocity checking + behavioral analysis provides better accuracy than any single method
  • Set velocity limits: maximum 3 cards from same IP per hour, maximum 2 different cards to same shipping address per day
  • Implement card testing detection: flag and block customers making multiple small authorizations followed by larger purchases
  • Monitor fraud rates by segment: track fraud separately for new vs. repeat customers, domestic vs. international, low-value vs. high-value transactions
  • Balance fraud prevention with approval optimization - target 0.5-0.8% fraud rate with <3% false decline rate
  • Not requiring CVV for CNP transactions - declining CVV failures reduces fraud 30-40%
  • Ignoring AVS mismatches - accepting transactions when billing address doesn't match doubles fraud risk
  • Treating all CNP transactions identically - domestic repeat customer orders shouldn't face same scrutiny as international first-time $1,000 purchases
  • Implementing overly aggressive fraud filters - declining 10% of transactions to prevent 1% fraud loses 9% in legitimate revenue
  • Not using 3D Secure for high-risk transactions - missing liability shift opportunity on international, high-value, or first-time customer orders
  • Failing to implement velocity limits - allowing fraudsters to test 50+ stolen cards before detection
  • Not distinguishing card testing from legitimate fraud - small $1-5 authorizations followed by chargebacks indicate testing requiring different prevention

Keep exploring

Related terms

APPROVED

Put this to work
for your business.

MIDs structures high-risk acquiring across 30+ banks — smart routing, fraud and chargeback control built in. Tell us your category and volume and we'll build the setup around it.