{"url_path":"/sec/bap/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-04-27","source_url":"https://www.sec.gov/Archives/edgar/data/1001290/0001001290-26-000008-index.html","accession_number":"0001001290-26-000008","cik":"0001001290","ticker":"BAP","issuer_name":"CREDICORP LTD","edgar_url":"https://www.sec.gov/Archives/edgar/data/1001290/0001001290-26-000008-index.html","primary_entity_key":"0001001290","primary_entity_name":"CREDICORP LTD"},"word_count":1280,"has_tables":true,"body_markdown":"ITEM 16K.    CYBERSECURITY\n\nOverview\n\nFor Credicorp and its subsidiaries, technological progress imposes significant challenges in terms of data privacy, security and other information-related risks. With the increasing use of AI, cybersecurity risks to companies are also increasing, including threats such as denial-of-service attacks, malicious use of deepfakes and more advanced social engineering attacks. Cybercriminals can employ machine learning techniques to automate malware campaigns. Sophisticated and financially motivated cyberattacks, including with the use of ransomware, are constant threats across many industries, including financial services; and we expect they will become more common. With the rapid development and dissemination of AI tools, increasingly sophisticated and effective cybersecurity threats continue to emerge, creating a challenging environment for developing new digital solutions for our clients.\n\nCybersecurity Risk Management\n\nThe effective integration of cybersecurity processes into risk management is a strategic imperative for financial institutions in an increasingly digital and threatening environment. For Credicorp, this integration is not just a matter of regulatory compliance but also an essential measure to protect assets, reputation, and customer trust. By proactively addressing cybersecurity challenges, organizations within the group strengthen their resilience and maintain a strong competitive position in the market. Integrating cybersecurity processes into risk management involves identifying, assessing, mitigating and monitoring operational, fraud, and cybersecurity risks. This requires a holistic approach encompassing people, policies, procedures, technologies, and an organizational culture oriented towards risk management, embedded within Credicorp's broader enterprise risk management framework.\n\nOur goal is to support our business strategy by creating a cyber-resilient organization that protects our products and services and honors the trust our customers have placed in us. Our organization operates under a three lines model. The first line is responsible for managing risks daily, including by designing and implementing controls to mitigate risks. The second line is responsible for developing the cybersecurity strategy and governance program, as well as challenging and overseeing the first line. The third line operates independently and evaluates the processes and functions of both the first and second lines.\n\nCybersecurity Governance\n\nIn terms of personnel, our Chief Information Security Officer (the CISO) is the principal leader of the corporate cybersecurity team, and the CISO’s responsibilities include defining a comprehensive cybersecurity strategy aligned with the business and regulatory objectives affecting any of Credicorp’s subsidiaries and the organization’s risk appetite; providing guidance and advice to senior management on cybersecurity, risk, and compliance issues; coordinating responses and decision-making regarding major security crises; and acting as the focal point for communication with internal and external stakeholders, including regulators and government agencies, to ensure compliance with regulations and other relevant standards, such as preparing periodic reports and audits. Our CISO has broad experience in cybersecurity and information risk management, supported by extensive training, and is supported by dedicated cybersecurity and IT security teams across the group.\n\nCredicorp has internal teams of cybersecurity and IT security experts distributed across the group’s companies, which also work with external cybersecurity service providers for specific tasks. These teams are responsible for protecting technological infrastructure, confidential data, and business operations against cyber threats. Among the security capabilities and technologies that Credicorp and its subsidiaries have are vulnerability assessment and scanning tools, intrusion detection and prevention systems, security event and incident monitoring systems, penetration testing, adversary emulation exercises, data management (including classification, encryption at rest and in transit, and access management), multi-factor authentication requirements and other logical, physical and technical controls designed to prevent, deter, mitigate, and respond to cybersecurity threats.\n\nAdditionally, our employees play a role in protecting Credicorp against cybersecurity threats and, therefore, receive mandatory periodic training on cybersecurity-related topics, including phishing exercises.\n\nMonitoring and identifying risks related to external providers are a fundamental part of our cybersecurity strategy. Given the interconnection and dependence on external services, robust mechanisms are implemented to assess and mitigate risks associated with external service providers.\n\n284\n\n[Table of Contents](#ib149d99176634ff8adf88f8fa17ce583_7)\n\nFinally, we have adopted the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) as the basis for our cybersecurity framework and have established our cybersecurity program to address evolving threats, and have dedicated significant resources to implementing and maintaining processes and controls to manage cybersecurity risk within our appetite.\n\nBoard Governance\n\nWe believe that we have implemented robust cybersecurity risk governance with clear roles and responsibilities, committees, policies, and procedures to ensure the proper prevention, detection, and response to incidents, as well as the continuous improvement of the program. Cybersecurity risk is overseen by the Board of Directors’ Risk Committee. Our Appetite Dashboard incorporates a set of cybersecurity risk appetite metrics, which are monitored monthly. Any deviation from our appetite is reported to the Risk Committee, including action plans to resolve such deviation. Additionally, periodic updates on our cybersecurity program and any cybersecurity incidents or threats are also reported to the Risk Committee, the Audit Committee, or the Board of Directors, as necessary. These reports are consolidated by our CISO team, include contributions from the first and second-line teams of individual companies as needed, and are delivered to the Board and relevant committees by our CISO. By adopting a proactive and collaborative approach and staying abreast of industry best practices and regulatory requirements, the Board, the Risk Committee, and the Audit Committee play key roles in governing the protection of the organization’s assets and reputation in an increasingly challenging cybersecurity environment.\n\nProtocols and Materiality Analysis Regarding Cybersecurity Incidents\n\nWe have established a crisis management structure and a multifunctional crisis management team, with defined protocols for different scenarios and periodic simulation exercises to ensure that an up-to-date and adequate response is available for any potential future incident.\n\nGiven the new SEC rules regarding the disclosure of material cybersecurity incidents, our Risk Committee has approved and established criteria for determining the materiality of cybersecurity incidents. These criteria include financial, business continuity, reputational, and legal impacts, as well as a detailed additional review by a committee formed by our Chief Financial Officer (CFO), Chief Risk Officer (CRO), and Corporate Legal Counsel.\n\nCurrently, we are not aware of any cybersecurity incidents that could have a material effect on our business strategy, operating results, or financial condition.\n\nCybersecurity Risk Management Regarding the Use of Artificial Intelligence\n\nAt Credicorp, we see the value of AI both in increasing the productivity of our employees and processes and in improving the customer experience. In terms of risk management, we ensure that each AI initiative undergoes a risk assessment process led by each company in the group. This assessment considers cybersecurity-related aspects such as data-related risks (e.g., sensitive data leakage or data theft), technological risks (e.g., malicious command injection or availability failures), regulatory and compliance risks (e.g., non-compliance with privacy regulations and insufficient audit and traceability of records), among others.\n\nCredicorp has developed and deployed a Responsible AI Use Policy across the group, which has been developed with the participation of various specialized second-line units (Cybersecurity, Operational Risk, Compliance, Ethics, Legal, Fraud, among others). Credicorp has defined organizational and technical policies regarding the use of chats with generative AI interactions to prevent information leakage risks or misuse of data by our employees concerning the information provided to them to perform their operations.\n\nFinally, we complement these actions with a training and awareness program to strengthen risk management skills and promote the use of standardized AI tools at Credicorp. In this way, we ensure that the risks and impact of technology on our business are managed effectively and proportionally to their magnitude. Thus, we ensure adequate risk management corresponding to regulatory and operational risks regarding the correct use of AI to identify and monitor these risks properly to protect our customers and investors, complying with the expectations of the SEC and other local government regulators.\n\n285\n\n[Table of Contents](#ib149d99176634ff8adf88f8fa17ce583_7)\n\nPART III"}