Regulatory Compliance
SIM swap signals for FCA affordability and lending checks
Before entering a regulated credit agreement, CONC 5.2A requires a UK lender to carry out a reasonable assessment of the customer's creditworthiness, including affordability. That assessment only holds if the application is genuinely coming from the person it names. A SIM swap around the application or disbursement window can put the authentication channel in an attacker's hands, which means the assessment itself may be running on a compromised identity rather than simply risking a later loss. Telebase is launching a real-time SIM swap detection signal for this window. Early access is available now.
This page summarises publicly available regulatory material in general terms. It is not legal advice. Confirm your firm's specific obligations with your own compliance and legal teams and against the FCA's published rules.
Why lending has two separate risk moments, not one
Most account takeover content treats SIM swap as an authentication problem: an attacker intercepts an OTP and gets into an account that already exists. Lending has a second, earlier moment that does not apply to a standing account. The creditworthiness assessment under CONC 5.2A is built on data tied to the applicant: income evidence, credit reference agency output, the answers given on the application. If the phone number used to confirm identity during that application has recently changed hands, the assessment is not simply at risk of a later loss, it may already be an assessment of the wrong person.
The second moment sits after approval, at disbursement. A loan can be approved against a genuine applicant and still be redirected if the attacker times the swap to the point funds are released rather than the point the application was submitted. Both moments need a check, and they are not the same check applied twice: one protects the integrity of the assessment, the other protects the payment.
CONC 5.2A and where a phone signal actually fits
CONC 5.2A, part of the FCA's Consumer Credit sourcebook, requires a firm to undertake a reasonable assessment of a customer's creditworthiness before entering into a regulated credit agreement or before a significant increase in a credit limit, including the risk that the customer will be unable to make repayments. Checked August 2026. It does not name a specific data source, a phone signal or any other vendor input; it sets a standard for the assessment to be reasonable and evidenced.
A phone signal does not replace the credit reference agency data or income evidence CONC 5.2A is built around. What it protects is the channel those inputs are confirmed through. If a lender can show it checked the applicant's number was not recently swapped at the point identity was confirmed, that is a documented, proportionate addition to the assessment record, the same kind of evidenced control a firm building out a broader lending fraud control set would already be looking to add.
Consumer Duty and the disbursement moment
Consumer Duty, in force since 31 July 2023, requires firms to act to deliver good outcomes for retail customers, including protecting them from foreseeable harm. Checked August 2026. Account takeover at the point a loan is disbursed is foreseeable and technically preventable, and it is a materially worse outcome for the customer than a declined application: a completed loan taken out in their name leaves them associated with a debt they did not choose, on top of the funds being gone.
CONC 5.2A governs the assessment itself; Consumer Duty governs the outcome for the customer either side of it. A control that closes the disbursement-moment gap speaks to both at once: it protects the assessment's data integrity and it prevents a foreseeable harm to the customer whose name is on the agreement.
A worked example: SIM swap timed to disbursement
A genuine applicant submits a loan application. Identity and affordability checks pass, credit reference agency data supports the application, and the loan is approved. Nothing about the application itself was fraudulent.
An attacker who has gathered enough personal detail on the applicant, often from a data breach or social engineering, convinces the applicant's mobile carrier to port the number to a new SIM. The original SIM goes dead. The applicant may not notice for hours.
The lender sends an OTP to confirm release of funds or a change of payout account. The OTP reaches the attacker's SIM, not the applicant's. Funds are released to an account the attacker controls. The applicant is left with a completed loan in their name and no funds to show for it.
A SIM swap check placed immediately before the disbursement OTP, not only at initial application, is what closes this specific gap. Checking once at the start of the application does not catch a swap that happens after approval.
Live signals available now
While SIM swap detection is launching, the following signals are live today and can be checked at both the application and disbursement moments:
- Active status: confirms the number is currently reachable, relevant at the disbursement OTP step specifically
- Carrier: the current network operator; a carrier change since the application was submitted is worth flagging on its own
- Country: confirms the number is registered where the applicant claims to be
- Number type: mobile, landline or VoIP; a VoIP number applying for credit is worth additional scrutiny before the assessment proceeds
SIM swap detection: launching
Telebase is registering SIM swap data feeds with mobile network operators carrier by carrier. Once live, a query will return a timestamp for the most recent swap on a given number, so a lender can check recency at both the application and disbursement steps. The current API response returns simSwap: UNKNOWN for GB numbers while carrier registration completes. Early access is open now for lending and affordability teams who want to integrate ahead of general availability.