{"site":"Credicorp Help","count":136,"docs":[{"t":"A colleague left and still has access","u":"/help/access/a-colleague-left-and-still-has-access/","c":"Access","e":"Access","s":"A leaver who still has access is a live risk. Remove them now; if they were your administrator, transfer that role first so you're not locked out.","b":"What's happening It is easy to forget the finance account when someone leaves, especially if they set it up. But retained access means they can still see information, and their credentials are a risk if compromised later. This is one of the most common avoidable account exposures. What to do Open Users and remove them — access ends at once. If they were the only administrator, promote a staying colleague first. Change any shared secret they knew and confirm alerts go to a current address. Build removal into your offboarding checklist so it never slips."},{"t":"A supplier says they've changed their bank details","u":"/help/security/a-supplier-changed-their-bank-details/","c":"Security","e":"Security","s":"Treat any 'we've changed banks' request as unverified until you confirm by phone on a number you already hold. That one call defeats mandate fraud.","b":"What's happening A request to update a supplier's bank details is one of the most common fraud vectors. Criminals — often after compromising the supplier's email — send a convincing notice so your next payment goes to them. The message can look entirely genuine. What to do Do not update details from an email or letter alone. Phone the supplier on a number from a previous invoice or their official website — never the number on the request — and confirm the change. Require a second person to approve supplier bank changes. See invoice and mandate fraud."},{"t":"Accessibility and additional support options","u":"/help/access/accessibility-and-additional-support-options/","c":"Access","e":"Access","s":"We want the account to work for everyone. That includes accessible formats, flexible contact options and additional support for anyone who needs it — just ask.","b":"Accessible formats If a standard statement or letter is hard for you to read, we can provide information in accessible formats — such as large print — on request. Tell us what works for you and we will set it as your preference so you do not have to ask each time. Requesting an accessible format is free and never affects your account. Contact that suits you You can deal with us in the way that suits you best. If a particular channel is difficult, let us know and we will find one that works. If you would like someone to help you manage the account — a colleague, family member or adviser — you c"},{"t":"Account takeover","u":"/help/security/glossary-account-takeover/","c":"Security","e":"Glossary","s":"Account takeover is when a criminal gains control of your account using stolen, guessed or phished credentials, then misuses it.","b":"Definition Account takeover follows a leaked password, a phishing success or credential reuse. Once in, the attacker may change details, add users or attempt to move money. Why it matters for your business Two-factor authentication, unique passwords and alerts stop the vast majority of takeovers and catch the rest early. If you suspect one, act fast — see reporting suspected fraud."},{"t":"Adding a user to your account","u":"/help/access/adding-a-user-to-your-account/","c":"Access","e":"Access","s":"Give a colleague their own login rather than sharing yours. Inviting a user takes a minute, lets you set exactly what they can do, and keeps every action properly attributed.","b":"Before you invite Decide what the person actually needs to do and pick the matching role — Viewer, Finance user or Administrator. Choosing the lowest role that fits keeps the account secure. Have their work email address ready; the invitation goes there. How to add them Sign in and open Users in account settings.Choose Invite user (you need administrator rights to do this).Enter their name and work email, and select the role.Send the invitation. They receive an email with a secure link to set up their own login. What the new user does The invited colleague follows the link, sets their own pass"},{"t":"Administrator role","u":"/help/security/glossary-administrator-role/","c":"Security","e":"Glossary","s":"The administrator role is the account role able to add and remove users, set roles, and change account settings.","b":"Definition An administrator holds the highest level of control over an account's users and settings. Keep at least two, and no more than you need, so the account is neither stranded nor over-exposed. Why it matters for your business Managing the administrator role well prevents lockouts and limits risk. See changing the administrator and setting up a second administrator."},{"t":"Advance-fee and fake loan-offer scams","u":"/help/security/advance-fee-loan-scams-guide/","c":"Security","e":"Security","s":"A fake loan offer promises easy funding, then asks for an upfront 'release', 'insurance' or 'admin' fee before the money arrives. No genuine lender works this way — the fee is the scam.","b":"What an advance-fee scam looks like You are offered a business loan — often unsolicited, often for more than you expected and with barely any checks. To 'release' the funds, you are asked to pay a fee first: an insurance premium, an admin charge, a tax, or a deposit to 'prove you're serious'. Once you pay, the funds never arrive, and the scammer disappears or invents another fee. The whole scheme exists to extract that upfront payment. The red flags An upfront fee demanded before any money reaches you.An offer that seems too easy — large sums with little or no assessment of your company.Pressu"},{"t":"Advance-fee fraud","u":"/help/security/glossary-advance-fee-fraud/","c":"Security","e":"Glossary","s":"Advance-fee fraud is a scam that promises funding — such as a loan — then asks for an upfront fee to 'release' it, after which nothing is delivered.","b":"Definition Advance-fee fraud dangles an attractive offer, usually unsolicited and with few checks, then demands a payment to unlock it. Once paid, the fee is lost and the funds never come. Why it matters for your business A genuine lender never asks you to pay to release your own loan — fees come from the facility, disclosed in the agreement. See advance-fee and fake loan-offer scams."},{"t":"Anti-money laundering (AML)","u":"/help/security/glossary-anti-money-laundering/","c":"Security","e":"Glossary","s":"Anti-money laundering (AML) refers to the legal obligations and checks that prevent the financial system being used to disguise the proceeds of crime.","b":"Definition AML rules require lenders to verify customers, understand the source of funds where relevant, and monitor for suspicious activity. They protect the whole system and are non-negotiable. Why it matters for your business For you, AML mostly means straightforward identity and business checks. See how we verify your business identity and KYC."},{"t":"Authenticator app","u":"/help/security/glossary-authenticator-app/","c":"Security","e":"Glossary","s":"An authenticator app generates a fresh six-digit code every 30 seconds on your phone, used as the second factor when you sign in.","b":"Definition An authenticator app (such as Google or Microsoft Authenticator) implements the TOTP standard, producing time-based codes tied to your account. Unlike SMS, the codes are generated on the device and can't be intercepted by SIM-swap fraud. Why it matters for your business Using an app rather than text messages for 2FA is more secure and works offline. See setting up an authenticator app."},{"t":"Authorised user","u":"/help/security/glossary-authorised-user/","c":"Security","e":"Glossary","s":"An authorised user is someone you've formally added to your account with a defined role, so they can be recognised, verified and dealt with.","b":"Definition An authorised user has their own login and a role that sets what they can do. Because they're recorded on the account, we can verify and deal with them — unlike someone using a shared password. Why it matters for your business Adding users properly keeps access attributable and revocable. See adding a user and roles and permissions."},{"t":"CEO fraud","u":"/help/security/glossary-ceo-fraud/","c":"Security","e":"Glossary","s":"CEO fraud is a scam in which a criminal impersonates a director or senior figure to pressure an employee into making an urgent, unauthorised payment.","b":"Definition CEO fraud uses authority and urgency: a message that looks like it is from the boss instructs a member of staff to pay an invoice or transfer funds immediately and confidentially. Why it matters for your business Defeat it with a payment process that no seniority can bypass: verify unusual requests in person or by phone, and require dual approval for payments. See protecting director details."},{"t":"Changing the main account administrator","u":"/help/access/changing-your-account-administrator/","c":"Access","e":"Access","s":"The administrator controls users and settings. When that person moves on, transfer the role before they go so the account is never left without someone able to manage it.","b":"Why the administrator matters The administrator is the person who can add and remove users, change roles and manage account settings. If the only administrator leaves without transferring the role, no one can manage the account — you would need to contact us and prove your authority as a director to restore control, which is slower than doing it in advance. Plan the handover. How to transfer the role The current administrator signs in and opens Users.They promote a staying colleague to Administrator (add them as a user first if needed — see adding a user).Once the new administrator is confirme"},{"t":"Changing your repayment bank account","u":"/help/access/changing-your-repayment-bank-account/","c":"Access","e":"Access","s":"You can change the account your repayments come from yourself, in your settings. Because it is sensitive, we verify the change and alert you — and we never ask you to do it via a link in a message.","b":"How to change it Sign in and open Payments or Repayment settings.Choose Change repayment account and enter the new business bank details.We verify the account and set up the new mandate.You receive confirmation, and a security alert records that the change was made.Make sure the new account has funds available for the next collection — see keeping funds available. Why we protect this so carefully The repayment account is a prime target for mandate fraud: if a criminal could redirect collections, they could cause real disruption. So we verify the new account and alert you whenever it changes. C"},{"t":"Changing your sign-in email address","u":"/help/access/changing-your-sign-in-email-address/","c":"Access","e":"Access","s":"Your sign-in email is also where resets and alerts go, so keeping it current matters. Changing it is simple, and we verify the new address before it takes over.","b":"Why keep it current Your sign-in email is more than a username — it is where password resets, security alerts and account notices are sent. If it points at a mailbox you no longer check, or one belonging to someone who has left, you could miss a critical alert or be unable to recover access. Update it whenever the right person or address changes. How to change it Sign in and open Account or Profile settings.Choose Change sign-in email and enter the new address.We send a verification link to the new address; open it to confirm you control the mailbox.The change takes effect once verified, and w"},{"t":"Checking a link before you click it","u":"/help/security/checking-a-link-before-you-click-it/","c":"Security","e":"Security","s":"Before you click a link in any message about your finance, check where it really goes. It takes ten seconds and stops most phishing dead.","b":"Steps On a computer: hover your mouse over the link (don't click) and read the real address that appears at the bottom of the window.On a phone: press and hold the link until a preview of the destination appears.Compare: does it really go to credicorp.co.uk, or something close-but-wrong like credicorp-secure.net?When unsure: don't click. Type credicorp.co.uk yourself and sign in. Good to know Attackers rely on you not looking. The visible text of a link can say anything; only the real destination matters. See spotting phishing and recognising official communications."},{"t":"Checking a website address is genuine","u":"/help/security/checking-a-website-address-is-genuine/","c":"Security","e":"Security","s":"Before you type your password, make sure you're on the real credicorp.co.uk — check the exact address, the padlock, and reach the site by typing it yourself.","b":"Get there the safe way The safest way to reach any finance site is to type the address yourself — credicorp.co.uk — or use a bookmark you saved from the real site. Following a link from an email, text or search advert is how people land on convincing fakes. Type it, and you skip that risk entirely. Check the address bar Read the address carefully. Fakes use look-alikes: extra words (credicorp-secure.co.uk), different endings (credicorp.co.uk vs credicorp.net), or subtle misspellings. The genuine domain is credicorp.co.uk. Look at the part just before the first single slash — that's the real do"},{"t":"Choosing a strong passphrase for your business account","u":"/help/security/choosing-a-strong-passphrase-business-account/","c":"Security","e":"Security","s":"A passphrase — three or four unrelated words — is both stronger and easier to remember than the old-style short password with a symbol on the end. Here is how to choose one and keep it safe.","b":"Length beats complexity The old advice — one capital, one number, one symbol — produced passwords that were hard for humans to remember and easy for computers to guess. The modern rule is simpler: make it long. A passphrase of three or four unrelated words, such as copper-lantern-harbour-42, is far harder to crack than P@ss1! and much easier to type. Aim for at least 14 characters.The one word to avoid is anything guessable about your company — the trading name, your postcode, the year you incorporated. Those are the first things an attacker tries. Never reuse it The biggest real-world risk is"},{"t":"Choosing the right role for a colleague","u":"/help/access/choosing-the-right-role-for-a-colleague/","c":"Access","e":"Access","s":"Match the role to the job: Viewer for read-only, Finance user to transact, Administrator to manage the account. When in doubt, choose the lower one.","b":"Overview Getting roles right is the heart of good access control. Give too much and you widen the risk if a login is compromised; give too little and people can't do their job. The fix is to think about what the person actually needs to do day to day, and match the role to that. What to do Bookkeeper / accountant reconciling statements: Viewer.Finance manager making payments and managing the facility: Finance user.Director or account owner: Administrator (keep two).You can always raise access later if a role grows. See roles and permissions and least privilege."},{"t":"Closing your account: what to do first","u":"/help/access/closing-your-credicorp-account-checklist/","c":"Access","e":"Access","s":"Closing your account is straightforward, but do a few things first: settle the balance, download your records, and remove users. Here is the order that leaves everything tidy.","b":"Settle or arrange the balance Before closing, make sure any outstanding balance is repaid or that you have arranged how it will be. You can see the figure in your account, and the Credicorp calculators can help you check a settlement position. If money is tight, talk to us first — closing is not a substitute for arranging repayment, and we handle difficulty with care and no friction. Download everything you'll want Once an account is closed, self-service access ends, so download your records first: statements, your agreement, and any export you want for your books. See downloading statements a"},{"t":"Complaining about data or privacy","u":"/help/security/raising-a-data-or-privacy-complaint/","c":"Security","e":"Security","s":"If you are unhappy with how we have handled your data, tell us first — we aim to put it right quickly. You can also escalate to the Information Commissioner's Office, the UK regulator.","b":"Raise it with us If you think we have got something wrong with your data — an unanswered request, data you believe is inaccurate, or a use you did not expect — the fastest route is usually to tell us. Contact us through credicorp.co.uk or your account, explain the concern, and we will look into it and aim to put it right. Many issues are simple to resolve once we know about them. What we'll do We will acknowledge your complaint, investigate, and come back to you with a clear explanation and any action we are taking. If the issue is really a data error or an unmet data request, we will address "},{"t":"Correcting an error on your account","u":"/help/access/correcting-an-error-on-your-account/","c":"Access","e":"Access","s":"Spotted something wrong — a wrong figure, a mis-recorded payment, an out-of-date detail? Tell us and we will investigate and correct it. You also have a formal right to have inaccurate personal data rectified.","b":"Kinds of error and where to start Errors fall into a few types: a detail is wrong (address, contact, company information); a transaction looks wrong (a payment missing or duplicated); or personal data we hold is inaccurate. For simple details you can often fix them yourself — see updating your company details. For anything financial or disputed, contact us so we can investigate. How to report an error Gather the evidence — the statement line, a bank record, the correct detail — and contact us through your account or credicorp.co.uk. Reference the specific item and what it should say. Having yo"},{"t":"Credential stuffing","u":"/help/security/glossary-credential-stuffing/","c":"Security","e":"Glossary","s":"Credential stuffing is an automated attack that tries username-and-password pairs leaked from one site against many others, exploiting reused passwords.","b":"Definition Credential stuffing takes the huge lists of credentials exposed in breaches and tests them automatically against banking, lending and other accounts, betting that people reuse passwords. Why it matters for your business A unique password per site defeats it on the first try; 2FA blocks it even if the password matches. See choosing a strong passphrase."},{"t":"Credit reference agency","u":"/help/security/glossary-credit-reference-agency/","c":"Security","e":"Glossary","s":"A credit reference agency (CRA) collects and provides credit information about businesses and individuals, which lenders use to assess applications.","b":"Definition A credit reference agency holds data on borrowing and repayment history. Lenders search it when assessing an application, and report accounts back to it, building a credit profile over time. Why it matters for your business For your company, borrowing and repaying well helps build its profile. You can access and correct data held about you. See how your data is used."},{"t":"Data breach","u":"/help/security/glossary-data-breach/","c":"Security","e":"Glossary","s":"A data breach is a security incident in which personal data is lost, stolen, or accessed by someone without authorisation.","b":"Definition A data breach can range from a lost laptop to a system intrusion. Where it's likely to risk people's rights, the organisation must report it to the regulator and, for high risk, tell those affected. Why it matters for your business If your data is ever affected, we'll tell you directly and never via a login link. Watch for scams exploiting breach fears. See if your data may have been affected."},{"t":"Data controller","u":"/help/security/glossary-data-controller/","c":"Security","e":"Glossary","s":"A data controller is the organisation that determines the purposes and means of processing personal data, and carries the primary data-protection responsibilities.","b":"Definition The data controller decides why and how personal data is processed and is accountable for protecting it and honouring your rights. A processor, by contrast, acts on the controller's instructions. Why it matters for your business Knowing who controls your data tells you who to make a request or complaint to. See what data we hold and complaining about data."},{"t":"Data subject access request (DSAR)","u":"/help/security/glossary-data-subject-access-request/","c":"Security","e":"Glossary","s":"A data subject access request (DSAR) is your legal right to receive a copy of the personal data an organisation holds about you, usually free and within one month.","b":"Definition A DSAR lets you see the personal data held about you and how it is used. You do not need to give a reason, and the organisation must respond within a statutory time, normally one month. Why it matters for your business As a director you can make a DSAR for your personal data; your company's transaction data is separately available in-account. See making a data request."},{"t":"Direct debit","u":"/help/security/glossary-direct-debit/","c":"Security","e":"Glossary","s":"A direct debit is an authorised instruction that lets a company collect payments from your bank account on set dates, protected by the Direct Debit Guarantee.","b":"Definition A direct debit is the usual way repayments are collected. You authorise it once, and collections run on the agreed dates. The Direct Debit Guarantee entitles you to a refund of any payment taken in error. Why it matters for your business Keep the account funded ahead of each collection to avoid a returned-payment fee. See keeping funds available and changing your repayment account."},{"t":"Downloading statements and documents","u":"/help/access/downloading-statements-and-documents/","c":"Access","e":"Access","s":"Every statement, agreement and notice is available to download from your account whenever you need it — for your records, your accountant, or a lender or landlord who asks for proof.","b":"Where to find them Sign in and open Documents or Statements. There you will find your periodic statements, your credit agreement, any variation or settlement letters, and notices we have sent. Everything is available to download whenever you need it — you never have to request a copy and wait. How to download Open Statements and choose the period you need.Download it as a PDF to read or print, or where offered as a CSV to import into your bookkeeping.Save it to your records, or send it on to whoever needs it.For a machine-readable dump of activity, see exporting your account history. Sharing w"},{"t":"Encryption","u":"/help/security/glossary-encryption/","c":"Security","e":"Glossary","s":"Encryption converts data into an unreadable form that only someone with the correct key can decode, protecting it in transit and in storage.","b":"Definition Encryption secures data by making it unintelligible without the key. 'In transit' encryption protects data moving over the internet; 'at rest' encryption protects stored data. Why it matters for your business It is the baseline of protecting your finance data, so that intercepted or stolen data is useless without the keys. See how we protect your data."},{"t":"Exporting your account history","u":"/help/access/exporting-your-account-history/","c":"Access","e":"Access","s":"Beyond individual statements, you can export a machine-readable history of your account activity — ideal for reconciling in your accounting software or keeping a full local record.","b":"What the export contains The account-history export gives you a structured file — typically CSV — of transactions and events on your account: drawdowns, repayments, fees and adjustments, each with a date and amount. Because it is machine-readable, you can import it straight into your bookkeeping or reconcile it against your bank feed rather than retyping figures from a PDF. How to export Open Statements or Activity and choose Export.Pick the date range you need.Download the CSV and open it in your spreadsheet or import it into your accounts software.For formatted statements and your agreement,"},{"t":"Giving and revoking open banking permission","u":"/help/security/giving-and-revoking-open-banking-permission/","c":"Security","e":"Security","s":"Open banking is opt-in and read-only — you authorise it through your own bank, it can only view data, and you can withdraw it at any time.","b":"Steps To grant it: during your application or in settings, choose to connect via open banking; you're sent to your bank's secure page to authorise read-only access.What it does: lets us view transaction data to assess affordability — it cannot move money.To withdraw it: revoke the permission in your bank's open banking or third-party access settings at any time. Good to know Open banking often means a faster, better decision because it shows real, current trading. It is regulated and secure. Learn more in how your data is used and the Learn hub."},{"t":"Giving your accountant or bookkeeper access","u":"/help/access/giving-your-accountant-account-access/","c":"Access","e":"Access","s":"Let your accountant help without handing over your login. Add them as their own user with view-only access, or share a statement — never give out your password.","b":"The wrong way and the right way It is tempting to just send your accountant your password so they can 'have a look'. Do not. A shared login cannot be attributed, cannot be limited, and means changing your password every time the relationship ends. The right way is to give them their own Viewer user so they can see what they need and nothing more — and you can remove it in one click when the work is done. Add them as a view-only user Open Users and choose Invite user.Enter your accountant's email and set their role to Viewer.They set up their own login and can then see statements, activity and "},{"t":"How Credicorp protects your business data","u":"/help/security/how-credicorp-protects-your-business-data/","c":"Security","e":"Security","s":"Your data is protected by layered measures: encryption in transit and at rest, strict access control, and continuous monitoring. Here is a plain-English overview of how we keep it safe.","b":"Encryption everywhere Data moving between you and us travels over encrypted connections, so it cannot be read in transit. Data we store is encrypted at rest, so a copy of the underlying storage is useless without the keys. Encryption is the baseline of modern data protection, and we apply it across the board rather than only to the obvious fields. Access on a need-to-know basis Inside Credicorp, staff can only reach the data their role requires — the same least-privilege principle we recommend for your own user roles. Access is logged, so who looked at what is recorded, and sensitive actions r"},{"t":"How Credicorp verifies your business identity","u":"/help/security/how-credicorp-verifies-your-business-identity/","c":"Security","e":"Security","s":"Before we lend, we confirm your company and its directors are genuine — standard identity, KYC and anti-money-laundering checks. Accurate, current details make them quick and painless.","b":"What we check and why As a responsible lender we must confirm we're dealing with a real company and genuinely authorised people. That means Know Your Customer (KYC) and anti-money-laundering (AML) checks: verifying the company against Companies House, confirming directors and persons of significant control, and checking the identity of whoever is acting on the account. These protect you as much as us — they're how we stop someone impersonating your business to borrow in its name. How verification works Much of this happens automatically by comparing what you tell us against trusted sources. Oc"},{"t":"How long Credicorp keeps your data","u":"/help/security/how-long-credicorp-keeps-your-data/","c":"Security","e":"Security","s":"We keep data only as long as we have a lawful reason — while your facility is live, and for a defined retention period after — then delete or anonymise it.","b":"The principle We don't keep data indefinitely 'just in case'. Data is retained only while we have a lawful reason: to run your live facility, to meet legal and regulatory obligations, and to handle possible disputes or fraud claims for a limited period afterwards. Once no reason remains, the data is deleted or anonymised. While your account is open For as long as you have a facility with us, we keep the data needed to run it and meet our obligations. You can access, correct and, where applicable, restrict this data — see making a data request and correcting an error. After your account closes "},{"t":"How to recognise genuine Credicorp communications","u":"/help/security/recognising-credicorp-official-communications/","c":"Security","e":"Security","s":"Knowing what a genuine Credicorp message looks like is your best defence against impersonation. We will never ask for your full password, and we never demand payment to a new account by text.","b":"What we will and will not do Fraudsters impersonate lenders because it works — a message that looks official can push a busy director into acting fast. Knowing our real behaviour makes the fakes obvious:We will never ask for your full password, PIN or a full 2FA setup code.We will never phone or text to demand an urgent payment to a new bank account.We will never pressure you to move money to keep it 'safe'.Our emails come only from addresses ending @credicorp.co.uk. Check before you act When a message asks you to do something — click a link, confirm details, make a payment — stop and verify t"},{"t":"How we verify your identity on the phone","u":"/help/security/how-we-verify-your-identity-on-the-phone/","c":"Security","e":"Security","s":"Before we discuss or change anything sensitive, we verify that it is really you. Here is what that involves, why it protects you, and how to confirm a caller is genuinely from Credicorp.","b":"Why we verify Identity verification is a protection, not an obstacle. It is how we make sure that the person asking to change bank details, add a user or discuss an account is genuinely authorised to do so. Without it, anyone who learned a few public facts about your company could try to interfere with your finance. The brief check at the start of a call is what stops that. What we will ask We ask a small number of questions only the account holder or an authorised user would know — details tied to the account and, where appropriate, a one-time code sent to your registered contact method. Cruc"},{"t":"How your data is used in lending decisions","u":"/help/security/how-your-data-is-used-in-lending-decisions/","c":"Security","e":"Security","s":"A lending decision uses your company figures, credit reference data and, with your permission, open banking to assess affordability fairly. Here is what feeds a decision and what rights you have over it.","b":"What informs a decision We assess your company's ability to afford the facility. That draws on the figures you provide (accounts, the purpose of the funds), credit reference agency data about the business and, where you grant it, open banking access to your business bank data for a current view of cash flow. Combining these lets us lend responsibly and price fairly rather than guessing. Open banking is your choice Open banking is opt-in and read-only: with your permission we see transaction data to assess affordability, and we cannot move money through it. You grant access through your bank's "},{"t":"I can see a login I don't recognise","u":"/help/security/i-see-a-login-i-dont-recognise/","c":"Security","e":"Security","s":"An unfamiliar sign-in in your activity might be innocent or might be an intruder. Sign it out, change your password, and check the details to decide.","b":"What's happening Your account lists the devices and sessions signed in, with a device type, rough location and last-seen time. Locations are only estimates and can look wrong even for your own logins, so weigh the device and timing too — a Windows PC in another city at 3am is a very different signal from a slightly-off town on your own phone. What to do If in any doubt, choose sign out on that session, or sign out of all other devices, then change your password and confirm 2FA. If it looks like a genuine intruder, report it — see reporting suspected fraud. Full detail in managing devices and s"},{"t":"I can't access the email on my account","u":"/help/access/i-cant-access-the-email-on-my-account/","c":"Access","e":"Access","s":"If the account's email is a mailbox you've lost access to — a former colleague's, say — you need to move it to one you control, which we'll verify to keep it safe.","b":"What's happening The sign-in email is where resets and alerts go, so if it points at a mailbox you cannot reach, you risk missing critical messages and being unable to recover access the usual way. This often happens after a staff change where the account was set up under someone else's address. What to do If you can still sign in, change it yourself — see changing your sign-in email. If you cannot sign in because resets go to the lost mailbox, follow account recovery; we'll verify your authority as a director before moving the account, which protects you from anyone trying to hijack it."},{"t":"I can't receive my 2FA codes","u":"/help/access/i-cant-receive-my-2fa-codes/","c":"Access","e":"Access","s":"If your codes won't work, use a recovery code to get in, then re-enrol 2FA. If you have none, follow identity-verified recovery.","b":"What's happening Codes can stop working for a few reasons: a new or reset phone that no longer has the authenticator, an app that lost its accounts, or a phone clock that's drifted so time-based codes don't match. The fix depends on which it is. What to do First, check your phone's date and time are set automatically — that fixes many code failures. If you can't produce a working code, use a saved recovery code to sign in and re-enrol. With no codes, follow account recovery for identity-verified access. See also moving your authenticator."},{"t":"I forgot to sign out on a shared computer","u":"/help/security/i-forgot-to-sign-out-on-a-shared-computer/","c":"Security","e":"Security","s":"Left a session open on a machine you can't get back to? Sign out of all other devices from your own phone or laptop to close it immediately.","b":"What's happening A session left open on a shared office PC, a client's machine or a public computer could let the next person reach your account. The good news is you don't need to go back to that machine to fix it. What to do Sign in on your own device, open Devices and sessions, and choose sign out of all other devices. That ends the forgotten session at once. In future, use a private window and sign out fully on shared machines — see keeping your account safe on shared computers."},{"t":"I got a suspicious call claiming to be Credicorp","u":"/help/security/i-got-a-suspicious-call-claiming-to-be-credicorp/","c":"Security","e":"Security","s":"If a caller claiming to be us pressures you for details, a code or a payment, hang up and call back on a trusted number. Genuine advisers welcome that; scammers don't.","b":"What's happening Vishing — phone-based fraud — relies on authority and urgency. A convincing 'fraud team' may ask you to 'confirm' security details, read back a code we supposedly sent, or move money to a 'safe' account. Caller ID can be faked to look like us. The pressure to stay on the line is itself the warning sign. What to do Do not share your full password, a code, or move any money. Hang up and call the number on your statement or credicorp.co.uk to check. We will never ask for your full password or push you to move money. Report the call via reporting suspected fraud. See how we verify"},{"t":"I got an email asking me to log in to 'verify' my account","u":"/help/security/i-received-a-genuine-looking-email-asking-me-to-log-in/","c":"Security","e":"Security","s":"An email demanding you log in through a link to 'verify' or 'secure' your account is a classic phishing sign. Don't click — sign in yourself by typing the address.","b":"What's happening A hallmark of phishing is a message that manufactures a reason to log in right now — 'verify your account', 'unusual activity', 'confirm your details' — with a convenient link. The link leads to a fake page that captures whatever you type. What to do Genuine Credicorp messages tell you what happened but ask you to sign in yourself by typing credicorp.co.uk — never through a supplied link. Don't click; check the sender and, if unsure, open the account directly. Report it via reporting suspected fraud. See spotting phishing and checking a link."},{"t":"I need someone to manage the account while I'm away","u":"/help/access/i-need-someone-to-manage-the-account-while-im-away/","c":"Access","e":"Access","s":"Don't hand over your login. Give a trusted colleague their own user access at the right level, or nominate them formally — and keep alerts on.","b":"What's happening Whether it's annual leave, travel or parental leave, the account still needs someone able to act. The wrong way is to share your password; the right way is to give the person proper, scoped access that you can see and remove. What to do Add them as a user with a role matched to what they'll do, or set up a formal nominee if they need to contact us. Keep alerts on so you see activity while away, and remove or downgrade the access when you're back."},{"t":"I need to remove a user quickly","u":"/help/access/i-need-to-remove-a-user-quickly/","c":"Access","e":"Access","s":"To cut someone off now: sign in as an administrator, open Users, and remove them — access ends instantly and their session closes.","b":"What's happening Sometimes access needs to end this minute — a sudden departure, a suspected problem, or a mistake in who was added. Removal is immediate, so there's no window in which the person can still act once you've done it. What to do Open Users, find the person, choose Remove. If they were an administrator, make sure another administrator remains first — see changing the administrator. Then change any secret they knew. Full steps in removing a user."},{"t":"I received a 2FA code I didn't request","u":"/help/security/i-received-a-code-i-didnt-request/","c":"Security","e":"Security","s":"An unexpected 2FA code usually means someone has your password and is trying to sign in. Don't share it — change your password instead.","b":"What's happening Two-factor codes are only sent when someone is trying to sign in or authorise something. If one arrives and it wasn't you, the likely explanation is that someone else has entered your password and is being stopped at the second step — which is exactly 2FA doing its job. What to do Never read the code to anyone, and never approve a prompt you didn't start. Change your password to a new, unique one right away, review your sessions, and report it via reporting suspected fraud. This is a good moment to add a passkey too."},{"t":"I share a device with my business partner","u":"/help/access/i-share-a-device-with-my-business-partner/","c":"Access","e":"Access","s":"Even on a shared device, keep separate logins. Each director signs in as themselves, with their own password and 2FA — never a shared account.","b":"What's happening It's common for two directors to use the same office computer. That's fine — but sharing one login isn't. Separate logins mean each person's actions are attributable, and one person's access can be changed or removed without affecting the other. What to do Give each director their own user, ideally both as administrators, each with their own password and 2FA or passkey. On the shared machine, don't save passwords and sign out between people — see shared computers."},{"t":"I think I paid a fraudulent invoice","u":"/help/security/i-think-i-paid-a-fraudulent-invoice/","c":"Security","e":"Security","s":"If you've paid a fraudulent or redirected invoice, speed is everything: contact your bank immediately, then report it and warn the genuine supplier.","b":"What's happening Invoice and mandate fraud diverts a real payment to a criminal account. Money moved this way is hard to recover, and every hour matters — banks can sometimes recall a payment if told quickly enough, but the window is short. What to do Call your bank at once to attempt a recall. Report it to Action Fraud, warn the genuine supplier that their details were spoofed, and tighten your process so bank-detail changes are always verified by phone. If the scam invoked Credicorp, tell us via reporting suspected fraud. Prevention detail is in invoice and mandate fraud."},{"t":"I think there's a mistake on my statement","u":"/help/access/i-think-there-is-a-mistake-on-my-statement/","c":"Access","e":"Access","s":"Spotted a wrong figure or a payment that looks off? Tell us with the detail and we'll investigate and correct any genuine error — you have a right to accurate records.","b":"What's happening Statements can occasionally show something that looks wrong to you — a missing payment, a duplicate, an unexpected fee. Sometimes there's a straightforward explanation; sometimes it's a genuine error. Either way, it's worth checking rather than leaving it. What to do Note the specific line and what you think it should be, with your statement or a bank record to hand, then contact us. We'll trace it and put right any real error. For inaccurate personal data you have a formal right to rectification — see correcting an error."},{"t":"I want a copy of everything you hold on me","u":"/help/security/i-want-a-copy-of-everything-you-hold-on-me/","c":"Security","e":"Security","s":"For your personal data, make a data subject access request. For your account transactions, download statements or export your history — no request needed.","b":"What's happening There are two different things you might want. Your business's transaction data — payments, drawdowns, fees — is already yours to pull from the account. The personal data we hold about you as an individual is obtained through a formal data request. What to do For account records, use downloading statements and exporting your history. For your personal data, make a data subject access request — usually free, answered within a month. You don't need to give a reason."},{"t":"I want to check my account hasn't been tampered with","u":"/help/security/i-want-to-check-my-account-hasnt-been-tampered-with/","c":"Security","e":"Security","s":"Worried but no specific alert? Run a quick self-check: sessions, users, bank details, contact email and 2FA. Five minutes buys peace of mind.","b":"What's happening Sometimes you just want to be sure — after a phishing scare, a lost device, or a staff change. A short review confirms nothing has been altered and, if something has, catches it early. What to do Check five things: your sessions (anything unfamiliar?), your user list (only current colleagues?), your repayment bank details (unchanged?), your contact email (still yours?), and that 2FA is on. If anything looks wrong, change your password and report it. Make it a quarterly habit."},{"t":"I want to report a scam using your name","u":"/help/security/i-want-to-report-a-scam-using-your-name/","c":"Security","e":"Security","s":"If a scam is impersonating Credicorp, report it to us — it helps us get fake sites and numbers taken down and protects other borrowers.","b":"What's happening Fraudsters impersonate lenders because the brand lends credibility. When you report an impersonation — a spoof email, a fake website, a bogus caller — you give us what we need to act, and you help protect every other business that might be targeted next. What to do Report it via reporting suspected fraud, forwarding the original message where you can. Also report to Action Fraud, and forward scam texts to 7726. If you interacted with the scam, secure your account too — change your password and review sessions. See recognising official communications."},{"t":"I want to stop marketing but keep service messages","u":"/help/security/i-want-to-stop-marketing-but-keep-service-messages/","c":"Security","e":"Security","s":"You can switch off marketing entirely — it's an absolute right — while keeping the essential service messages and security alerts your account needs.","b":"What's happening Marketing and service messages are different things. You can opt out of all direct marketing with no reason and no friction. Essential service messages — about your facility, payments and security — aren't marketing and continue so you don't miss anything important. What to do Set your marketing preference in notification settings or tell us directly. Keep security alerts on. More on the underlying right in objecting to processing."},{"t":"I want to tighten security after a scare","u":"/help/security/i-want-to-tighten-security-after-a-scare/","c":"Security","e":"Security","s":"A near-miss is a good prompt. In fifteen minutes you can move from 'probably fine' to genuinely hard to compromise: passkey, 2FA, alerts, session cleanup and a user review.","b":"What's happening Scares happen — a dodgy email you nearly clicked, a colleague who was caught out, news of a breach. Rather than just worry, use it as the nudge to harden the account properly. The steps are quick and cumulative. What to do Add a passkey and confirm 2FA; turn on all security alerts; sign out unfamiliar sessions; review your users; and adopt a password manager. Then schedule a quarterly review so it stays that way."},{"t":"I want two people to approve important changes","u":"/help/access/i-want-two-people-to-approve-changes/","c":"Access","e":"Access","s":"Spread control across two administrators and route alerts to both, so every important change is seen — and, in practice, approved — by more than one person.","b":"What's happening For many companies, a single person controlling the finance account is a governance risk as much as a security one. You can build in oversight so major changes don't happen without a second pair of eyes. What to do Keep two administrators, use roles so most users can't make major changes, and send security alerts to both administrators so each sees what the other does. Combined with a company rule that big changes are agreed between them, this gives you effective dual control."},{"t":"I was offered a loan I didn't apply for","u":"/help/security/i-was-offered-a-loan-i-didnt-apply-for/","c":"Security","e":"Security","s":"An unsolicited, too-easy loan offer that asks for an upfront fee is a classic advance-fee scam. Genuine funding never charges you to release it.","b":"What's happening Fraudsters send unsolicited offers — often for generous sums with almost no checks — then ask for a fee to 'release', 'insure' or 'process' the funds. Once you pay, nothing arrives. The offer exists only to extract that payment. What to do Never pay to unlock a loan. Only apply through credicorp.co.uk, where fees are disclosed in your agreement and taken from the facility, not paid up front. Compare against real figures with the calculators. If our name was used, report it via reporting suspected fraud. See advance-fee scams."},{"t":"I'm being pressured to act urgently about my account","u":"/help/security/i-am-being-pressured-to-act-urgently/","c":"Security","e":"Security","s":"Manufactured urgency is the scammer's main tool. A genuine request survives you slowing down to check; a scam falls apart. So slow down.","b":"What's happening Almost every finance scam relies on pressure: a deadline, a threat to suspend your facility, a warning that you must act 'in the next hour'. The urgency exists to stop you thinking and checking. That pressure is itself the warning sign. What to do Whatever the message, pause. Verify through a channel you trust — type credicorp.co.uk yourself, or call the number on your statement. A genuine matter will still be there; a scam relies on you not looking. Report pressure tactics via reporting suspected fraud. See recognising official communications."},{"t":"I'm changing my business bank","u":"/help/access/i-am-changing-my-business-bank/","c":"Access","e":"Access","s":"Switching banks? Update your repayment details before your next collection, keep the new account funded, and watch for the confirmation alert.","b":"What's happening When your company moves banks, the account we collect repayments from has to change too — otherwise a collection could bounce. It's a simple update, but timing matters: do it before the next collection date. What to do Sign in and change your repayment bank account to the new business account, make sure it's funded for the next collection, and check the confirmation and alert arrive. Remember we never ask you to change this via a link — see mandate fraud. Keep funds ready — see keeping funds available."},{"t":"I'm worried about identity theft as a director","u":"/help/security/i-am-worried-about-identity-theft-as-a-director/","c":"Security","e":"Security","s":"Directors are public on Companies House, which raises the risk. Use a service address, enable Companies House protections, and lock down your finance account.","b":"What's happening Your name, role and correspondence address are public at Companies House by law. That transparency helps trust but also gives fraudsters a starting point to impersonate you — to us, to suppliers, or to the register itself. What to do Reduce the exposure: use a service address rather than your home; enable Companies House email reminders and consider the PROOF scheme against forged filings; be sparing with personal detail online; and secure your finance account with a unique password, 2FA and alerts. Full detail in protecting director details."},{"t":"If your data may have been affected by a breach","u":"/help/security/if-your-data-may-have-been-affected-by-a-breach/","c":"Security","e":"Security","s":"If a breach were ever likely to put your data at risk, we would tell you and the regulator within the required timescales and set out what to do. Here is how that works and how to protect yourself.","b":"Our obligations Under UK data-protection law, an organisation must report a qualifying personal-data breach to the Information Commissioner's Office without undue delay and within 72 hours where feasible, and must tell affected people directly if the breach is likely to result in a high risk to their rights. We take these duties seriously and would communicate honestly and quickly rather than downplay anything. How we would tell you If a breach were likely to affect you, we would contact you directly — not bury it — explaining what happened, what data was involved, what we are doing, and what "},{"t":"Information Commissioner's Office (ICO)","u":"/help/security/glossary-ico/","c":"Security","e":"Glossary","s":"The Information Commissioner's Office (ICO) is the UK's independent authority upholding information rights and data-protection law.","b":"Definition The ICO oversees how organisations handle personal data, provides guidance, and handles complaints. You can escalate a data or privacy complaint to it if an organisation's own response doesn't satisfy you. Why it matters for your business If you're unhappy with how we've handled your data, you can raise it with the ICO after us. See complaining about data or privacy."},{"t":"Invoice and mandate fraud, explained","u":"/help/security/invoice-and-mandate-fraud-explained/","c":"Security","e":"Security","s":"Invoice fraud tricks you into paying a genuine-looking bill to a criminal's account; mandate fraud changes the bank details you already hold on file. One phone call to a trusted number defeats both.","b":"How the scam works In invoice-redirection fraud, a criminal — often after compromising a supplier's email — sends a real-looking invoice or a 'we've changed banks' notice, asking you to pay a new account. In mandate fraud, they pose as an existing supplier or service and ask you to update the bank details you already hold. In both, the money leaves for a criminal account and is hard to recover. This is one of the most costly frauds affecting UK businesses. The one step that stops it Whenever bank details are new or changed, verify by phone on a number you already trust — from a previous invoic"},{"t":"Invoice fraud","u":"/help/security/glossary-invoice-fraud/","c":"Security","e":"Glossary","s":"Invoice fraud (or invoice redirection) uses a genuine-looking invoice with changed bank details to divert your payment to a fraudster.","b":"Definition Invoice fraud often follows a compromised supplier email: you receive a real-looking bill or 'we've changed banks' notice and pay the criminal's account. The loss is hard to recover. Why it matters for your business Always confirm new or changed bank details by phone on a trusted number before paying, and require a second approver for supplier bank changes. See invoice and mandate fraud."},{"t":"Is it safe to connect open banking?","u":"/help/security/i-want-to-know-if-open-banking-is-safe/","c":"Security","e":"Security","s":"Yes — open banking is regulated, read-only, and revocable. You grant view-only access through your own bank, and it can never move your money.","b":"What's happening Open banking worries some directors because it involves connecting the business bank account. In fact it's one of the safer ways to share financial data: it's regulated, you authorise it through your own bank's secure page, and the access is read-only. What to do What you grant is permission to view transaction data to assess affordability — not to move money, and not a copy of your bank login. You can withdraw it at any time from your bank's settings. It often means a faster, fairer decision. See giving and revoking permission and how your data is used."},{"t":"Keeping enough funds available for collection","u":"/help/access/keeping-funds-available-for-collection/","c":"Access","e":"Access","s":"A missed collection can mean a returned-payment fee and, if it recurs, an effect on your record. Keeping the repayment account funded ahead of each date — and using alerts — avoids it entirely.","b":"Know your collection date Repayments are collected on set dates by direct debit or your agreed method. Knowing those dates and making sure the repayment account holds enough the day before is the whole job. You can see upcoming collections in your account, and set a reminder a couple of days ahead so a busy week never catches you out. Use reminders and alerts Turn on payment reminders in your notification settings so you are prompted before each collection. Pair that with security alerts and you have both a nudge to fund the account and a warning if anything about your payments changes. If a c"},{"t":"Keeping the devices you use for the account secure","u":"/help/security/keeping-your-devices-secure/","c":"Security","e":"Security","s":"Your account is only as secure as the device you sign in from. Keep those devices updated, locked, and free of dubious software — the basics do most of the work.","b":"Overview A hardened account can still be undermined by a compromised device — one running out-of-date software, left unlocked, or carrying malware that captures what you type. Because you sign in from your phone and computer, their security is part of your account's security. What to do Install updates promptly — they fix the flaws attackers exploit.Use a screen lock (PIN, fingerprint or face) on every device.Run reputable security software and don't install software from untrusted sources.Enable find-my-device so a lost device can be located or wiped.Pair this with a passkey and 2FA. If a dev"},{"t":"Keeping your account safe on public Wi-Fi","u":"/help/security/keeping-your-account-safe-on-public-wifi/","c":"Security","e":"Security","s":"Public Wi-Fi is lower-risk than it used to be thanks to encrypted connections, but a few precautions — your own device, a private network where possible, and 2FA — remove what remains.","b":"The real risk today Accessing your account over public Wi-Fi — a café, a station, a hotel — used to be genuinely risky. Today, because connections to sites like ours are encrypted end to end, the data you send can't simply be read off the network. The main residual risks are fake hotspots and shoulder-surfing rather than interception. Sensible precautions Use your own device, not a shared or public computer.Prefer your mobile data or a trusted network for anything sensitive; if using public Wi-Fi, a reputable VPN adds a layer.Check you're on the real network, not a look-alike hotspot with a si"},{"t":"Keeping your account safe on shared or public computers","u":"/help/security/keeping-your-account-safe-on-shared-computers/","c":"Security","e":"Security","s":"On a machine you do not fully control, treat every session as temporary: use a private window, never save the password, and sign out fully when you finish.","b":"The risk of shared machines A shared office computer, a client's PC or a public machine may keep your login details, browsing history or an open session after you walk away. Anyone using it next could then reach your finance account. The fix is to treat any device that is not solely yours as untrusted and leave no trace behind. Do this every time Open a private or incognito window — it stores no history and forgets logins when closed.Type credicorp.co.uk yourself rather than following a saved bookmark or a link.When prompted to save the password or 'remember this device', decline.Do the task, "},{"t":"Keeping your contact email up to date","u":"/help/access/keeping-your-contact-email-up-to-date/","c":"Access","e":"Access","s":"Your contact email receives alerts and resets, so an out-of-date one is a real risk. Keep it current and monitored, especially after a staff change.","b":"Overview The address on your account is where security alerts, payment reminders and password resets land. If it points at a mailbox no one watches — or a former colleague's — you could miss a critical alert or lose the ability to recover access. This is one of the most overlooked security details. What to do Check the contact and sign-in addresses whenever someone leaves or roles change. Update the sign-in address via changing your sign-in email, confirm alerts go somewhere monitored, and consider copying alerts to a second director. See updating your details."},{"t":"Keeping your recovery codes safe","u":"/help/security/keeping-your-recovery-codes-safe/","c":"Security","e":"Security","s":"Recovery codes are your backup way in if you lose your phone. Store them somewhere safe and separate from your phone — a password manager or with your key company documents.","b":"Overview When you set up two-factor authentication you're given single-use recovery codes. They exist for one job: to let you back in if the device holding your authenticator is lost or replaced. Without them, a lost phone can mean a slower, identity-verified recovery. With them, you're back in seconds. What to do Best: save them in your password manager, which is encrypted and separate from your phone.Also good: print them and keep them with your important company documents.Avoid: storing them only on the same phone as your authenticator, or in an unprotected note.See recovery codes and accou"},{"t":"Know Your Customer (KYC)","u":"/help/security/glossary-know-your-customer/","c":"Security","e":"Glossary","s":"Know Your Customer (KYC) is the set of identity and business-verification checks a regulated lender must carry out before and during a relationship.","b":"Definition KYC checks confirm the identity of the company and its directors and controllers, helping prevent fraud and financial crime. They're a legal requirement for regulated finance. Why it matters for your business Keeping your details current makes these checks pass smoothly. See how we verify your business identity."},{"t":"Least privilege","u":"/help/security/glossary-least-privilege/","c":"Security","e":"Glossary","s":"Least privilege is the principle of granting each person the minimum access required for their role — no standing rights they do not need.","b":"Definition Least privilege keeps access tightly matched to need. A user who only reads statements gets a view-only role; only those who must manage the account are administrators. Why it matters for your business Applied to your user list, least privilege shrinks the damage any single compromised login can do. See managing user roles."},{"t":"Legitimate interest","u":"/help/security/glossary-legitimate-interest/","c":"Security","e":"Glossary","s":"Legitimate interest is a lawful basis for using personal data where an organisation has a genuine need that isn't overridden by the individual's rights.","b":"Definition Legitimate interest lets an organisation process data for real purposes — such as preventing fraud — provided that need is balanced against, and doesn't override, your interests and rights. Why it matters for your business You can object to processing based on legitimate interest, and we'll stop unless we have compelling grounds or a legal need. See objecting to processing."},{"t":"Making a data subject access request","u":"/help/security/making-a-data-subject-access-request/","c":"Security","e":"Security","s":"You have the right to a copy of the personal data we hold about you — a data subject access request, or DSAR. It is free in most cases and we respond within the statutory timescale.","b":"What a DSAR gives you A data subject access request (DSAR) is your right to obtain a copy of the personal data an organisation holds about you, along with information about how and why it is used. It covers your personal data — for example your details as a director or authorised user — rather than the company's business data, which you can already retrieve through your account history. How to make one You can make a DSAR in writing through the contact details on credicorp.co.uk, or via the account. You do not need to explain why you want the data. We may ask you to verify your identity first "},{"t":"Managing multiple facilities in one account","u":"/help/access/managing-multiple-facilities-in-one-place/","c":"Access","e":"Access","s":"If your company runs more than one facility, you can see and manage them together in one account — with a clear view of each balance, collection and document, and roles that control who sees what.","b":"A single view of everything Where your company holds more than one facility with us, you do not need separate logins for each. They appear together in one account, so you can see every balance, upcoming collection and document from a single place. This makes reconciliation and cash-flow planning far easier than juggling separate portals. Keep collections aligned With several facilities, collection dates can stack up. Review them together and, where helpful, ask us to align dates so payments fall at points that suit your cash flow. Turn on payment reminders for each, and keep the repayment acco"},{"t":"Managing trusted devices and active sessions","u":"/help/security/device-and-session-management-guide/","c":"Security","e":"Security","s":"Your account keeps a list of the devices and browsers currently signed in. Reviewing it — and removing anything unfamiliar — is one of the fastest ways to catch and stop unauthorised access.","b":"Why review your sessions Every time you sign in on a new browser or phone, your account records that device — its type, rough location and when it was last active. This list is a mirror of who currently has your account open. If you ever see a device or location you do not recognise, that is a warning sign you can act on immediately, before any damage is done. How to review and remove Open Security settings and go to Devices and sessions.Read down the list. Each entry shows the device, the approximate location and when it was last used.For anything you do not recognise, choose Sign out — that "},{"t":"Managing user roles and permissions","u":"/help/access/managing-user-roles-and-permissions/","c":"Access","e":"Access","s":"Roles let you give each colleague the right level of access: some can only view, some can transact, one is the administrator. Least privilege — the least access needed to do the job — keeps the account safe.","b":"How roles work Rather than everyone sharing one login (never do that), each person who needs access gets their own user account with a role. The role decides what they can see and do. Typical roles are: Administrator, who can manage users and all settings; Finance user, who can view balances, make payments and manage the facility; and Viewer, who can see statements and activity but change nothing. Separate logins mean actions are attributable and access can be removed for one person without disrupting anyone else. Apply least privilege Give each colleague the least access they need to do their"},{"t":"Managing your account notification settings","u":"/help/access/managing-account-notification-settings/","c":"Access","e":"Access","s":"Tune your notifications so you get the reminders that matter — payment prompts, security alerts, statement notices — and mute the rest. Security alerts are one group we recommend always leaving on.","b":"What you can control Notifications fall into groups: payment reminders ahead of collections, security alerts for sign-ins and sensitive changes, statement and document notices, and general account updates. You choose which groups you receive and to which address, so your inbox carries the prompts you rely on without unnecessary noise. How to change them Open Notification settings from your account menu.Turn each group on or off to taste.Confirm the address each group goes to — you can direct security alerts to more than one person. Leave security alerts on You can quieten most notifications, b"},{"t":"Mandate fraud","u":"/help/security/glossary-mandate-fraud/","c":"Security","e":"Glossary","s":"Mandate fraud is when a criminal persuades you to change the bank details you hold for a supplier or service, so payments go to their account instead.","b":"Definition Mandate fraud targets the bank details on file. A fraudster, often posing as a genuine supplier, asks you to update account details; future payments then go to them. Why it matters for your business The defence is simple: verify any change of bank details by phone on a number you already trust. We never ask you to change your repayment account via a link. See invoice and mandate fraud."},{"t":"Moving your authenticator to a new phone","u":"/help/security/moving-your-authenticator-to-a-new-phone/","c":"Security","e":"Security","s":"Getting a new phone? Move your authenticator across before you wipe the old one — or use a recovery code to re-enrol. Here is the safe order.","b":"Steps Best case: before wiping the old phone, use your authenticator app's export or account-sync to move codes to the new phone.If the app doesn't sync: sign in to Credicorp on the new phone, open Security settings, remove the old 2FA and add it again — scanning the fresh QR code into the new phone's authenticator.If you've already lost the old phone: use a saved recovery code to sign in, then re-enrol 2FA. Good to know The one thing that turns this from easy to painful is not having your recovery codes. Save fresh ones whenever you re-enrol, and keep them separate from your phone. If you are"},{"t":"Multi-factor authentication (MFA)","u":"/help/security/glossary-multi-factor-authentication/","c":"Security","e":"Glossary","s":"Multi-factor authentication (MFA) requires two or more independent factors — something you know, have or are — to sign in, of which 2FA is the common two-factor form.","b":"Definition MFA combines factors from different categories: knowledge (password), possession (a code or passkey on your device) and inherence (biometrics). Requiring more than one makes a single stolen credential useless. Why it matters for your business For business accounts, enabling MFA is the strongest routine defence. On a Credicorp account this means a password plus an authenticator code or a passkey — see setting up 2FA."},{"t":"My accountant needs to see my account","u":"/help/access/my-accountant-needs-to-see-my-account/","c":"Access","e":"Access","s":"Give your accountant a view-only login of their own, or just send the statements they need — never your password.","b":"What's happening Accountants routinely need your figures, but sharing your password is the wrong way to provide them: it can't be limited, can't be attributed, and forces a password change when the work ends. There are two clean alternatives. What to do Either add them as a Viewer user so they can see statements and activity but change nothing — see giving your accountant access — or simply download the statements they need and send those. Remove their access when the engagement ends."},{"t":"My business email was hacked — is my finance account at risk?","u":"/help/security/my-business-email-was-hacked/","c":"Security","e":"Security","s":"A hacked business email is serious because password resets and alerts often flow through it. Secure the email, then lock down your finance account.","b":"What's happening Email is the master key to many accounts: whoever controls it can trigger password resets and read your alerts. If your business email is compromised, an attacker could try to reset your finance login or quietly watch for opportunities. Treat it as urgent. What to do First, regain control of the email and secure it with its own strong password and 2FA. Then, on your Credicorp account, change your password, confirm 2FA (ideally an authenticator app, not email codes), review sessions, and check no reset was triggered. Report concerns via reporting suspected fraud."},{"t":"Nominating someone to help manage your account","u":"/help/access/nominating-someone-to-help-manage-the-account/","c":"Access","e":"Access","s":"You can nominate a trusted person to help with your account — for a busy period, an absence, or a health reason. Doing it properly means they can help while you stay in control.","b":"When a nominee helps There are times when a director needs someone else to help run the finance side — a period of illness, extended travel, parental leave, or simply delegating day-to-day admin to a trusted colleague. Rather than an informal 'just use my login' arrangement, a proper nomination records that person on the account so they can be verified and dealt with, while you keep ultimate control and can end it whenever you wish. How to set it up For routine help, add the person as a user with a role matched to what they need to do. For someone who needs to speak to us on your behalf, recor"},{"t":"Objecting to or restricting how your data is used","u":"/help/security/objecting-to-or-restricting-data-processing/","c":"Security","e":"Security","s":"You can object to some uses of your data — marketing is an absolute right to opt out — and ask us to restrict processing while a concern is resolved. Here is how each works.","b":"Objecting to marketing You have an absolute right to object to your data being used for direct marketing. Say so, and we stop — no reason needed, no friction. You can set this in your notification settings or tell us directly. Opting out of marketing does not affect the essential service messages we must send to run your account. Objecting to other processing For processing based on our legitimate interests, you can object and we will stop unless we have compelling legitimate grounds that override your interests, or need to continue for legal claims. In practice, much of what we do is necessar"},{"t":"Offboarding an employee from your account","u":"/help/access/offboarding-an-employee-from-your-account/","c":"Access","e":"Access","s":"When someone leaves, remove their access as part of offboarding. This checklist takes a minute and closes a common security gap.","b":"Steps Remove their user from the account — see removing a user. Access ends immediately.If they were an administrator, transfer that role first.Change any shared secret they knew (a shared mailbox that gets alerts, for instance).Confirm alerts now go to a current, monitored address.Review the whole user list while you're there. Good to know Doing this on the leaving day, every time, prevents former staff retaining access they no longer should have — one of the most common and avoidable account risks. Turn on user-change alerts so additions and removals are always visible."},{"t":"Open banking","u":"/help/security/glossary-open-banking/","c":"Security","e":"Glossary","s":"Open banking lets you securely share read-only access to your business bank data with a lender, so affordability can be assessed from real, current transactions.","b":"Definition Open banking is a regulated, permission-based way to share bank transaction data. It is read-only — a lender can see the data you approve but cannot move money — and you authorise it through your own bank. Why it matters for your business For borrowers it often means a faster, better-informed decision because it shows live trading rather than dated accounts, and you can withdraw permission at any time. See how your data is used."},{"t":"Passkey","u":"/help/security/glossary-passkey/","c":"Security","e":"Glossary","s":"A passkey signs you in using your device's own unlock (fingerprint, face or PIN) instead of a typed password, and cannot be phished.","b":"Definition A passkey is a cryptographic credential stored on your device and unlocked with your biometrics or PIN. When you sign in, the device proves it holds the key without sending any password, and the key only works on the genuine website. Why it matters for your business Because there is no secret to type, a passkey cannot be captured by a fake login page or reused after a breach elsewhere. It is the strongest and simplest way to protect a business account — see adding a passkey."},{"t":"Passphrase","u":"/help/security/glossary-passphrase/","c":"Security","e":"Glossary","s":"A passphrase is a password made of several unrelated words — long, memorable, and much harder to guess than a short complex string.","b":"Definition A passphrase such as copper-lantern-harbour-42 gains its strength from length. It's easier for a person to remember and far harder for a computer to crack than a short password with symbols. Why it matters for your business Combined with never reusing it, a passphrase is the foundation of account security. See choosing a strong passphrase."},{"t":"Personal data","u":"/help/security/glossary-personal-data/","c":"Security","e":"Glossary","s":"Personal data is any information relating to an identifiable living individual — for a business account, typically the details of directors and authorised users.","b":"Definition Personal data covers information that can identify a living person, directly or indirectly. Much company data is not personal data, but a director's or user's details are, and carry data-protection rights. Why it matters for your business Your data rights — access, correction, objection, erasure — apply to personal data. See what data we hold and making a data request."},{"t":"Persons of significant control (PSC)","u":"/help/security/glossary-persons-of-significant-control/","c":"Security","e":"Glossary","s":"A person of significant control (PSC) is someone who ultimately owns or controls a company — for example holding over 25% of shares or voting rights — and must be listed at Companies House.","b":"Definition The PSC register records who really controls a company, improving transparency. Like directors, PSCs appear on the public register, which lenders and others can check. Why it matters for your business Keeping PSC information accurate matters for verification and for your own protection. See updating your company details and how we verify identity."},{"t":"Phishing","u":"/help/security/glossary-phishing/","c":"Security","e":"Glossary","s":"Phishing is a fraudulent email, text or call designed to trick you into revealing login details or moving money, usually by impersonating a trusted organisation.","b":"Definition Phishing messages imitate a genuine sender and create urgency — 'verify now or your account is suspended' — to make you click a fake link or hand over details. Variants include smishing (by text) and vishing (by phone). Why it matters for your business Business borrowers are targeted because a compromised finance account is valuable. Learning the tell-tale signs — wrong sender, urgency, mismatched links — defeats almost all of them. See spotting phishing."},{"t":"Protecting director details from impersonation","u":"/help/security/protecting-director-details-from-impersonation/","c":"Security","e":"Security","s":"A director's name, role and correspondence address are public record. That transparency is the law — but a few sensible steps reduce the risk of that information being used to impersonate you.","b":"Why directors are targeted Company directors and persons of significant control are listed publicly at Companies House — name, role, month and year of birth, and a correspondence address. This openness is a legal requirement and a good thing for trust, but it also hands fraudsters a starting kit for impersonation: enough to craft a convincing scam aimed at you or at people who deal with your company. Practical protections Use a service address, not your home address, for your Companies House correspondence — your home address can be suppressed from the public register.Enable Companies House pr"},{"t":"Recovering access if you're locked out","u":"/help/access/account-access-recovery-if-locked-out/","c":"Access","e":"Access","s":"Being locked out is almost always recoverable. Work through it in order: reset your password, use a recovery code, then verify your identity if the automated routes are exhausted.","b":"Try the quick fixes first Most lockouts are simple. Start here:Forgotten password? Use reset your password — you will get a secure link to your registered email.Locked after too many attempts? Accounts briefly lock after several wrong tries as a protection. Wait a short while and try again with the correct details, or reset the password. Lost your second factor If you have your password but cannot produce your 2FA code — a lost or replaced phone — use one of the recovery codes you saved when you set up two-factor authentication. Each code works once and lets you sign in and re-establish 2FA on"},{"t":"Recovery codes","u":"/help/security/glossary-recovery-codes/","c":"Security","e":"Glossary","s":"Recovery codes are one-time backup codes generated when you set up two-factor authentication, used to sign in if you lose your authenticator device.","b":"Definition Recovery codes are your safety net for 2FA. Each works once. Saved somewhere safe and separate from your phone, they let you back in if the device holding your codes is lost. Why it matters for your business Storing them at setup is the difference between a quick self-service recovery and a slower identity-verified one. See setting up 2FA and account recovery."},{"t":"Removing a user from your account","u":"/help/access/removing-a-user-from-your-business-account/","c":"Access","e":"Access","s":"When a colleague leaves or no longer needs access, remove them straight away. Removal is immediate, ends any open session, and is one of the most important routine security tasks a director can do.","b":"Why prompt removal matters A former colleague who still has access is a live risk — even if you trust them, their credentials could be compromised after they leave, and they may retain visibility of information they should no longer see. The safest habit is to remove access on the day someone leaves, as part of your normal offboarding. It takes under a minute. How to remove someone Sign in with administrator rights and open Users.Find the person in the list.Choose Remove (or Downgrade if you only want to reduce their access).Confirm. Their access ends immediately and any session they have open"},{"t":"Reporting a lost or stolen device","u":"/help/security/reporting-a-lost-or-stolen-device/","c":"Security","e":"Security","s":"If a device with access to your account goes missing, act in this order: sign out the device remotely, change your password, and confirm your second factor — all from another device, in minutes.","b":"Do these three things first Sign out the device remotely. From another device, open Devices and sessions and remove the missing one. This ends its access to your account immediately.Change your password. A new password invalidates anything saved on the lost device.Confirm your second factor. Check that 2FA is active. If the lost device held your authenticator or a passkey, set up a fresh one on a device you still have. Then tidy up Once access is locked, use your phone or laptop's own find my device and remote-wipe features to protect everything else on it. Let your colleagues know if the devi"},{"t":"Reporting suspected fraud to Credicorp","u":"/help/security/reporting-suspected-fraud-to-credicorp/","c":"Security","e":"Security","s":"If you spot something wrong — a scam pretending to be us, a strange login, an unexpected change — report it fast. Quick reporting lets us secure your account and warn other borrowers.","b":"When to report Report to us if you receive a message impersonating Credicorp, notice a sign-in or change you did not make, believe your login details may have leaked, or have been targeted by a scam that references your borrowing. You do not need to be certain — a suspicion reported early is far more useful than a confirmed loss reported late. How to report Sign in and use the Report a problem or Security option in your account, or contact our support team through the details on your statement or on credicorp.co.uk. If it is a phishing email or text, forward it to us with the original sender v"},{"t":"Requesting erasure of your data","u":"/help/security/requesting-erasure-of-your-data/","c":"Security","e":"Security","s":"You can ask us to erase your personal data, but the right is not absolute: while you have a live facility, and for a period after, we must keep certain records by law.","b":"The right and its limits The right to erasure (sometimes called the right to be forgotten) lets you ask us to delete personal data we hold about you. It is a real and important right — but it is not unlimited. Where we have a legal or regulatory obligation to retain records, or an ongoing lawful reason such as a live credit agreement, we must keep the relevant data even if you ask us to delete it. This is normal for regulated finance and protects both sides. While your facility is live If you have an active facility, we cannot erase the data needed to run it and meet our obligations. What we c"},{"t":"Resetting a forgotten password","u":"/help/access/resetting-a-forgotten-password/","c":"Access","e":"Access","s":"Forgotten your password? A reset takes a minute. We send a secure, time-limited link to your registered email — never ask for your old password, and never send the new one by email.","b":"How to reset it On the sign-in screen, choose Forgotten password.Enter your registered email address.We email you a secure, time-limited link. Open it.Choose a new, strong passphrase you have not used elsewhere.Sign in with the new password and confirm your 2FA still works. Why we do it this way Sending the link to your registered email proves you control that mailbox, which is a check an impostor cannot easily pass. We never ask for your old password to set a new one, and we never email you a password — anyone who does is not us. The link expires quickly so it cannot be used later if the emai"},{"t":"Right to erasure","u":"/help/security/glossary-right-to-erasure/","c":"Security","e":"Glossary","s":"The right to erasure (the 'right to be forgotten') lets you ask an organisation to delete your personal data — but it is limited by legal retention duties.","b":"Definition The right to erasure lets you request deletion of your personal data. It is not absolute: where the organisation has a legal obligation or ongoing lawful reason to keep records, it must retain the relevant data. Why it matters for your business For a live finance facility we must keep records to run it and meet regulation; we erase what we can and delete the rest once retention ends. See requesting erasure."},{"t":"Running a quarterly account security review","u":"/help/security/reviewing-your-account-security-quarterly/","c":"Security","e":"Security","s":"Security drifts if left alone. A five-minute review every quarter keeps it tight: check users, access, 2FA and recent sign-ins.","b":"Steps Users: remove anyone who has left; downgrade anyone with more access than they need — see roles and permissions.Administrators: confirm there are still two.2FA: check it's active on your login and your recovery codes are safe.Sessions: scan your devices and remove anything unfamiliar.Alerts: confirm they go to a monitored address. Good to know Put a recurring reminder in your calendar. Directors carry responsibility for how the business is run, and a compromised finance account is expensive — five minutes a quarter is cheap insurance. See the full security guide."},{"t":"SIM-swap fraud","u":"/help/security/glossary-sim-swap-fraud/","c":"Security","e":"Glossary","s":"SIM-swap fraud is when a criminal transfers your mobile number to their SIM, so they receive your SMS security codes and calls.","b":"Definition In a SIM swap, the fraudster persuades your mobile provider to move your number to a SIM they control, then intercepts any codes or resets sent by text. It's a key reason SMS is the weakest form of 2FA. Why it matters for your business Using an authenticator app or a passkey instead of SMS codes defeats it, because those don't depend on your phone number. Watch for a sudden loss of mobile signal as a warning sign."},{"t":"Securing your Credicorp business account: the full guide","u":"/help/security/securing-your-credicorp-account-full-guide/","c":"Security","e":"Security","s":"The single place to lock down your Credicorp business account — covering the password, two-factor authentication, passkeys, session controls and the user reviews every company director should run quarterly.","b":"Start with the six layers that matter Account security is not one switch — it is a stack of independent controls, each of which closes a different attack. If one layer fails, the others still stand. For a Credicorp business account the layers are: a strong, unique password; two-factor authentication (2FA) or a passkey; a short list of trusted devices; a reviewed list of account users and their roles; alerts that tell you when something changes; and your own vigilance against phishing. Turn on all six and the account is genuinely hard to compromise even if one credential leaks.None of these fea"},{"t":"Securing your account before you go on holiday","u":"/help/access/what-to-do-before-you-go-on-holiday/","c":"Access","e":"Access","s":"Before you're away: make sure a second administrator can act, alerts reach someone, and collections are covered. Five minutes now saves a scramble later.","b":"Overview Time away is exactly when a small oversight becomes a problem — a collection that fails, an alert no one sees, a change only you could make. A quick pre-holiday pass keeps the account running and secure while you're off. What to do Confirm there's a second administrator who can act.Make sure alerts reach someone who's around.Check the repayment account is funded for upcoming collections.If someone will help, give them proper access — not your password."},{"t":"Service address","u":"/help/security/glossary-service-address/","c":"Security","e":"Glossary","s":"A service address is the official correspondence address a company director can register at Companies House instead of their home address.","b":"Definition A service address keeps a director's home address off the public register, reducing exposure to fraud and unwanted contact. It's where official mail is sent. Why it matters for your business Using one is a simple step against director identity theft. See protecting director details."},{"t":"Session (sign-in session)","u":"/help/security/glossary-session/","c":"Security","e":"Glossary","s":"A session is a period during which a particular device or browser stays signed in to your account without re-entering your password.","b":"Definition A session begins when you sign in and lasts until you sign out or it expires. Your account lists active sessions so you can see, and end, where you're logged in. Why it matters for your business Reviewing and ending sessions is a fast way to cut off unrecognised access. See managing devices and sessions."},{"t":"Setting up a passkey for your Credicorp account","u":"/help/security/setting-up-a-passkey-for-your-account/","c":"Security","e":"Security","s":"A passkey replaces your password with your device's own unlock — fingerprint, face or PIN. It is phishing-proof by design, because there is no secret to type into a fake site.","b":"What a passkey is A passkey is a modern replacement for the password. Instead of a secret you type, your device holds a cryptographic key and unlocks it with your fingerprint, face or device PIN. When you sign in, your device proves it holds the key without ever sending a password anywhere. There is nothing for a criminal to phish, guess or reuse.Passkeys are built into modern iPhones, Android phones, Macs and Windows machines, and they sync securely across your own devices through your Apple, Google or Microsoft account. Why it beats a password Cannot be phished. A fake login page has nothing"},{"t":"Setting up a second administrator","u":"/help/access/setting-up-a-second-administrator/","c":"Access","e":"Access","s":"One administrator is a single point of failure. Adding a second administrator means the account is never stranded if one person is away or leaves.","b":"Steps Sign in as an administrator and open Users.Add the second person as a user if they aren't already — see adding a user.Set their role to Administrator.Have them secure their login with a password and 2FA. Good to know Two directors, or a director and a trusted finance lead, is the usual pairing. Keep the number of administrators small — they can change everything — but never leave it at one. See roles and permissions."},{"t":"Setting up an authenticator app for two-factor authentication","u":"/help/security/setting-up-authenticator-app-2fa/","c":"Security","e":"Security","s":"Two-factor authentication adds a second step to sign-in: after your password you enter a six-digit code from an app on your phone. It is the single most effective account-security upgrade you can make.","b":"Why 2FA matters most Passwords leak — through phishing, reuse and data breaches. Two-factor authentication (2FA) means that even if a criminal has your password, they still cannot sign in without the second factor: a code that lives only on your phone and changes every thirty seconds. Industry data consistently shows that app-based 2FA blocks the overwhelming majority of automated account-takeover attempts. If you do one thing on this page, do this. What you need A free authenticator app on your phone. Any app that follows the TOTP standard works — Google Authenticator, Microsoft Authenticator"},{"t":"Sign-in problems: a quick checklist","u":"/help/access/signing-in-problems-checklist/","c":"Access","e":"Access","s":"Most sign-in trouble is one of a handful of things. Run this quick checklist before resetting your password or contacting us.","b":"Steps Right email? Sign in with the exact address registered to the account.Caps lock / autofill? Check your password isn't being mistyped or auto-filled with an old value.2FA code current? Codes change every 30 seconds — use the one showing now, and check your phone's clock is set automatically.Browser up to date? An old browser or a strict extension can block sign-in; try a private window.Still stuck? Reset your password. Good to know If none of this works, you may be locked out after several attempts — wait a short while, or go straight to account recovery. If a message about your account l"},{"t":"Smishing","u":"/help/security/glossary-smishing/","c":"Security","e":"Glossary","s":"Smishing is phishing by text message: a scam SMS that pushes you to click a link or call a number to 'confirm' or 'secure' your account.","b":"Definition Smishing is phishing delivered as a text. Because links are hard to inspect on a phone and sender names are easy to spoof, texts can be more convincing than email. Why it matters for your business Treat any text demanding urgent action with a link as suspect. We never text you a login link and ask you to sign in through it. See spotting phishing and smishing, and forward scam texts to 7726."},{"t":"Social engineering","u":"/help/security/glossary-social-engineering/","c":"Security","e":"Glossary","s":"Social engineering is the manipulation of people — through urgency, authority or trust — to make them reveal information, grant access or make payments.","b":"Definition Social engineering is the human side of fraud. Rather than hacking systems, the attacker persuades a person to act against their interest — 'I'm from the fraud team, act now'. Phishing, vishing and CEO fraud are all forms of it. Why it matters for your business Awareness is the defence: slow down, verify through a trusted channel, and never let urgency override your normal checks. Train everyone who can move money or grant access. See spotting scams."},{"t":"Someone may know my account password","u":"/help/security/someone-may-know-my-account-password/","c":"Security","e":"Security","s":"If you think anyone knows your password — a former colleague, or after a phishing scare — change it now and enable 2FA. Assume the worst and close the gap.","b":"What's happening Passwords get known in ordinary ways: they were once shared with a colleague who has since left, written somewhere visible, reused on a site that was breached, or handed over in a phishing scam. Any of these means the password can no longer be trusted, even if nothing has gone wrong yet. What to do Change your password to a new, unique passphrase, turn on two-factor authentication so the old one is useless anyway, and review your sessions. If it was shared in a scam, report it via reporting suspected fraud."},{"t":"Spotting a fake invoice or payment request","u":"/help/security/spotting-a-fake-invoice-or-payment-request/","c":"Security","e":"Security","s":"Before paying any invoice with new or changed bank details, run a few checks — the key one being verify by phone on a trusted number. It stops invoice fraud cold.","b":"Overview Fake and altered invoices are among the costliest frauds hitting UK businesses. The invoice often looks genuine — right logo, right layout — but the bank details have been changed to a criminal's account. Paying it sends your money straight to the fraudster. What to do New or changed bank details? Verify by phone on a number you already hold — never the one on the invoice.Unexpected urgency or a chased 'overdue' balance? Slow down and check.Slightly-off sender or reference? Treat as suspect.Require a second approver for supplier bank changes.See invoice and mandate fraud."},{"t":"Spotting fake Credicorp social media and adverts","u":"/help/security/spotting-fake-credicorp-social-media-and-ads/","c":"Security","e":"Security","s":"Scammers clone brands on social media and in adverts. Verify any 'Credicorp' account or ad by going to credicorp.co.uk yourself rather than trusting the post.","b":"How the scam works Fraudsters set up fake social-media profiles and paid adverts using a real lender's name and logo, promising easy funding to lure businesses. Victims are steered into messaging the fake account, applying on a fake site, or paying an upfront 'fee'. The branding can look convincing because logos are easy to copy. The tell-tale signs Promises of guaranteed approval or 'no checks' — no genuine lender offers that.Requests to continue in direct messages or via a messaging app.An upfront fee to release funds — a hallmark of a scam.A profile with few followers, a recent creation dat"},{"t":"Spotting phishing emails and smishing texts","u":"/help/security/spotting-phishing-and-smishing-scams/","c":"Security","e":"Security","s":"Phishing (fake emails) and smishing (fake texts) try to trick you into handing over login details or moving money. A handful of quick checks catches almost all of them.","b":"The four-check habit Almost every phishing message fails at least one of four checks. Run them before you act on any message about your finance:Sender. Does the address really end @credicorp.co.uk, or is it close-but-wrong like credicorp-secure.com?Urgency. Is it pushing you to act immediately — a threat to suspend the facility, a countdown? Manufactured urgency is the scammer's main tool.Links. Hover over any link (on a phone, long-press) to see where it really goes. If the visible text and the real address differ, do not click.The ask. Is it asking for your password, a code, or a payment to "},{"t":"Telling us someone should no longer have access","u":"/help/access/how-to-tell-us-someone-should-no-longer-have-access/","c":"Access","e":"Access","s":"If someone previously authorised should no longer act on your account, remove their user access and tell us to drop them as a contact — so no one can act in the company's name who shouldn't.","b":"Overview Access has two sides: the login they hold, and any record we have of them as an authorised contact or nominee. When someone's authority ends — they've left, or their role has changed — you'll usually want to close both, so they can neither sign in nor deal with us about the account. What to do Remove their user access yourself, and tell us to remove them as an authorised contact or nominee. We may verify your authority as a director first. Build both into your offboarding routine."},{"t":"Trusted device","u":"/help/security/glossary-trusted-device/","c":"Security","e":"Glossary","s":"A trusted device is one you designate as yours, so it may skip the two-factor prompt for a set period — appropriate only for devices only you use.","b":"Definition Marking a device as trusted reduces how often it asks for a 2FA code, trading a little friction for convenience. It should only ever be a private device you control. Why it matters for your business Never trust a shared or public machine. Review your trusted devices periodically and remove any you no longer use. See managing devices and sessions."},{"t":"Turning on alerts for bank-detail changes","u":"/help/security/turning-on-alerts-for-bank-detail-changes/","c":"Security","e":"Security","s":"A bank-detail change is exactly the event you want to hear about instantly. Turn on the bank-change alert so mandate fraud can't happen quietly.","b":"Steps Open Notification settings.In the Security alerts group, enable bank-detail change alerts.Confirm they go to an address you monitor — and add a second recipient if you want a co-director to see them too. Good to know If a bank-change alert ever arrives that you didn't make, treat it as urgent: sign in, reverse it if you can, and report it via reporting suspected fraud. Remember we never ask you to change your repayment account through a link — see invoice and mandate fraud."},{"t":"Turning on security alerts for your account","u":"/help/security/turning-on-security-alerts-for-your-account/","c":"Security","e":"Security","s":"Security alerts email you the moment something sensitive changes — a new sign-in, a password reset, a change to your repayment bank details — so an unauthorised change never goes unnoticed.","b":"What alerts cover Alerts turn your account into something that watches itself. You can be notified whenever a security-sensitive event happens, including: a sign-in from a new device or location, a password or 2FA change, a change to the bank account repayments are collected from, a new user added, or a request to close the account. Because these arrive by email in real time, an unauthorised change is something you find out about in seconds, not at your next login. How to switch them on Open Notification settings from your account menu.Find the Security alerts group.Turn on the events you want"},{"t":"Two-factor authentication (2FA)","u":"/help/security/glossary-two-factor-authentication/","c":"Security","e":"Glossary","s":"Two-factor authentication (2FA) is a second proof of identity — usually a code from an app — required in addition to your password when you sign in.","b":"Definition Two-factor authentication combines something you know (your password) with something you have (a code on your phone, or a passkey). Even if your password is stolen, an attacker cannot sign in without the second factor. Why it matters for your business For a finance account, 2FA is the highest-value single security step. It blocks the overwhelming majority of automated account-takeover attempts that rely on leaked passwords. See how to set it up."},{"t":"Understanding single sign-on across Credicorp","u":"/help/access/understanding-single-sign-on-across-credicorp/","c":"Access","e":"Access","s":"Single sign-on lets you access Credicorp services with one secure login rather than many. It's convenient and secure — provided that one login is well protected.","b":"Overview Single sign-on (SSO) means you authenticate once and can move between Credicorp services without signing in again each time. It reduces password fatigue and the temptation to reuse weak passwords, and it centralises security so one strong login protects everything. What to do The trade-off is that your single login matters even more. Protect it with a unique passphrase, two-factor authentication or a passkey, and keep an eye on your sessions. Sign out fully on shared machines."},{"t":"Updating your company details","u":"/help/access/updating-your-company-details/","c":"Access","e":"Access","s":"Keep your company details current so notices reach the right place and identity checks pass smoothly. Most details you can update yourself in settings; some we verify.","b":"What you can update From Account or Company settings you can keep your details current: trading and contact information, phone numbers, correspondence preferences and, where relevant, your registered office. Keeping these accurate means our notices reach you and that identity and verification checks — which compare what you tell us against trusted sources — go through smoothly rather than flagging a mismatch. How to update them Sign in and open Company details.Edit the fields that have changed.Save. For sensitive changes we may verify — see how we verify your identity. Changes that also go to "},{"t":"Using a password manager for your business","u":"/help/security/using-a-password-manager-for-your-business/","c":"Security","e":"Security","s":"A password manager generates and stores a unique, strong password for every site, so you only remember one. It is the highest-value security habit a small business can adopt.","b":"Steps Choose one: your browser or phone has one built in, or use a dedicated app — several are free.Set a strong master passphrase and protect it with your device unlock.Let it generate a unique password for each site, including your Credicorp account.Turn on its breach alerts so it warns you if a stored password is exposed. Good to know A password manager kills two of the biggest risks at once: weak passwords and reused ones. Pair it with 2FA or a passkey and your accounts are genuinely hard to compromise. See choosing a strong passphrase."},{"t":"Vishing","u":"/help/security/glossary-vishing/","c":"Security","e":"Glossary","s":"Vishing is phishing by phone: a fraudster calls pretending to be your bank or lender to extract details or push you into moving money.","b":"Definition Vishing uses a phone call and social pressure — a convincing 'fraud team' asking you to 'confirm' security details or move funds to a 'safe' account. Caller IDs can be spoofed to look genuine. Why it matters for your business You can always hang up and call back on a number from your statement. We will never ask for your full password or a code we just sent you, and a genuine adviser welcomes a call-back. See how we verify your identity."},{"t":"What data Credicorp holds about your business and why","u":"/help/security/what-data-credicorp-holds-and-why/","c":"Security","e":"Security","s":"We hold only the data we need to lend responsibly and run your account: company and director details, financial information, and account activity — each for a clear, lawful reason.","b":"The main categories The data we hold falls into a few clear categories: company information (registered details, structure, trading history); director and authorised-user information needed to verify identity and authority; financial information (accounts, bank data used to assess affordability, the facility itself); and account activity (statements, payments, contact history). We hold what we need to lend responsibly and service your account — not more. Where it comes from Some data you give us directly when you apply and use the account. Some comes from trusted sources with a lawful basis: C"},{"t":"What happens when you sign out everywhere","u":"/help/security/what-happens-when-you-sign-out-everywhere/","c":"Security","e":"Security","s":"Sign out of all other devices ends every session except the one you're using — a fast way to cut off anything you don't control, without touching your colleagues' logins.","b":"Overview This option is your emergency brake. It immediately ends every active session on your login except the current one, so any device you've lost, forgotten to sign out of, or don't recognise is cut off at once. It doesn't change your password or your settings — it just closes the open doors. What to do Use it after a lost device, a forgotten shared-computer session, or an unfamiliar login. It affects only your login, not other users on the account, who have their own separate sessions. Pair it with a password change if you suspect compromise. See managing devices and sessions."},{"t":"What information you should never share","u":"/help/security/what-information-to-never-share/","c":"Security","e":"Security","s":"Some details should never leave your head or your device: your full password, one-time codes, passkey secrets and full card or bank credentials. We will never ask for them.","b":"The never-share list Keep these to yourself, always:Your full password.A one-time code (2FA or verification) — even if a caller says they sent it.Your authenticator setup key or a passkey.Full card details or online-banking credentials in response to any unsolicited request.No genuine Credicorp contact will ever ask for these. Anyone who does is impersonating us. Why these in particular Each of these is a master key. A one-time code hands over your second factor; a full password bypasses the first; a passkey or setup key clones your ability to sign in. Fraudsters ask for exactly these because "},{"t":"What to do if you entered details on a fake site","u":"/help/security/what-to-do-if-you-entered-details-on-a-fake-site/","c":"Security","e":"Security","s":"If you typed your login or details into a fake page, act fast: change your password, review sessions, and report it. Speed limits what a scammer can do.","b":"Steps Change your Credicorp password straight away — and anywhere you reused it.Turn on or confirm 2FA.Check your sessions and sign out anything you don't recognise.Watch for follow-up scams — fraudsters often call posing as the 'fraud team' to finish the job.Report it — see reporting suspected fraud. Good to know If you entered bank details, tell your bank too. If the fake site impersonated Credicorp, reporting it helps us get it taken down for everyone. See spotting phishing to recognise the next one."},{"t":"What to do if you shared your password","u":"/help/security/what-to-do-if-you-shared-your-password/","c":"Security","e":"Security","s":"If your password has been shared, phished or reused somewhere breached, change it now and turn on 2FA — in that order. It takes two minutes and closes the risk.","b":"Steps Change your password immediately to a new, unique passphrase.Turn on two-factor authentication so a known password alone can't get in.Review your sessions and sign out anything unfamiliar.Change it everywhere else you reused it. Good to know If you shared it because a message or caller asked you to, that was a scam — genuine Credicorp contact never asks for your full password. Report it via reporting suspected fraud so we can watch the account."},{"t":"Why we ask security questions","u":"/help/security/why-we-ask-security-questions/","c":"Security","e":"Security","s":"Security questions confirm it's really you before we do anything sensitive. They're a protection, not an obstacle — the same check that stops an impostor acting in your name.","b":"Overview It can feel like friction when we ask you to confirm details before discussing or changing something. But that brief check is exactly what stands between your account and anyone who has learned a few public facts about your company. Without it, impersonation would be far too easy. What to do We keep it proportionate: light checks for routine matters, firmer ones for sensitive changes like bank details or adding a user. We'll never ask for your full password or a code to read back. If you're ever unsure a caller is us, call back on a trusted number. See how we verify your identity."},{"t":"Why your account sometimes asks for a code more often","u":"/help/security/why-your-account-asks-for-a-code-more-often/","c":"Security","e":"Security","s":"An extra 2FA prompt is usually a good sign — the account is being cautious about something unusual, like a new device, network or a sensitive change.","b":"Steps You are signing in from a new device or browser the account hasn't seen before.You are on a new network or location, or a VPN that changes your apparent location.You are about to do something sensitive — change bank details, add a user, close the account.A trusted-device period expired, so the account asks again as a matter of routine. Good to know Extra prompts are the account protecting you, not a fault. If you ever get a prompt when you are not signing in — a code arrives out of the blue — that could mean someone has your password and is trying to get in. Do not approve it; instead ch"},{"t":"Your security responsibilities as a director","u":"/help/access/understanding-your-security-responsibilities-as-a-director/","c":"Access","e":"Access","s":"As a director you're responsible for how the company's finances are run — including who has access and how it's protected. Meeting that is simpler than it sounds.","b":"Why this sits with you Directors have legal duties to run the company with reasonable care and to protect its assets — and the finance account is one of those assets. That doesn't mean you need to be a security expert; it means you're responsible for making sure sensible controls are in place and that access is limited to the right people. What good looks like Every user has their own login and an appropriate role — no shared passwords.There are two administrators, so the account is never stranded.Access is removed promptly when people leave.2FA and alerts are on.A quarterly review keeps it cu"}]}