July, 2026
This July, we focused on giving clients more control over verification logic, improving account security, and making Dashboard workflows easier to manage.
We introduced Cross Check Rules, a new service for configuring cross-validation. We also added app token creation notifications and expanded Suspected Fraud Duplicate tasks to support face matches in ID documents.
We also refreshed the Dashboard layout, added manual 2FA setup, expanded Self Purchase with AML Screening and Facial Age Estimation, and improved post-purchase setup with Summy AI.
For Transaction Monitoring, Device Emulation is now available for sample transactions in the Dashboard. Travel Rule settings now include Protocol Manager, and the latest Mobile SDK update adds support for the Payment Methods check step and a redesigned Sumsub ID banner.
Stay tuned for more!
June 29 -> July 3
User Verification
Cross Check Rules release
We have released a new service — Cross Check Rules.
This update transforms cross-validation into a flexible rule builder, giving clients more control over how applicant data is checked across different verification steps.
You can now use Basic mode for standard cross-check settings or switch to Advanced mode to configure custom rules in more detail. In Advanced mode, you can:
- Create rules.
- Add and reorder conditions.
- Test rule logic directly in the Dashboard.
The Dashboard has also been redesigned to make working with presets, testing custom rules, and reviewing cross-validation results easier and more intuitive. Detailed cross-validation results are now available directly in the applicant profile, helping you understand which checks were triggered and why.
App token creation notifications
We now send email notifications when an app token is created. This gives you better visibility into account activity and helps you react faster if suspicious access is detected.
The notification includes key security details, such as the token name, creation time in UTC, IP address, and location. It also includes quick links to app tokens and active sessions, so users can review activity and revoke a token if needed.
Notifications are sent to members who can access the key or client group where the app token was created and have the Manage application tokens permission.
Explore Sumsub app tokens ->Suspected Fraud Duplicate tasks for ID documents
Suspected Fraud Duplicate tasks can now be created based on face matches in ID documents.
Previously, face-matching search worked only with selfies. With this update, Sumsub can match faces across ID documents. If two applicants have the same face but different names or dates of birth, Sumsub creates a Fraud Duplicate task.
Dashboard
Editable SSO users and Owner assignment
SSO users can now be edited in the Dashboard, and the Owner role can be assigned to them.
Previously, SSO users were fully managed through the identity provider, meaning their permissions were overwritten on every login. Because of this, clients using SSO could not assign the Owner role to an SSO account.
With this update, SSO users can now be edited directly in the Dashboard. Users with the required permissions can assign the Owner role to an SSO user when needed. SSO users with the Owner role are no longer affected by identity provider group and permission mapping during login, so their permissions stay unchanged. Their identity details, such as first and last name, continue to sync from the identity provider.
Regular SSO users remain fully managed through the identity provider. SSO sync cannot automatically promote a user to Owner, and the last-owner protection still applies.
Learn more about the Owner account functionality->Sumsub Support Portal
The new Sumsub Support Portal is now available.
The portal gives clients a dedicated space to manage support requests and access problem-centric resources directly from the Dashboard. They can submit new support requests, track active and historical tickets, filter tickets by status, and search by keywords or specific Applicant IDs.
The portal also includes an FAQ library with answers to common support scenarios, such as Dashboard troubleshooting, AML review guidance, and applicant rejection reasons. The FAQ will continue to be updated and expanded.
The Support Portal is integrated with the Dashboard and is available only to logged-in users.
Dashboard visual refresh
Content is now organized into clearer visual blocks, making pages easier to scan and helping users focus on the main workspace:
- Navigation, main content, and Summy AI are now visually separated into dedicated areas.
- Summy AI opens in a dedicated side panel across Dashboard pages.
- The Sandbox mode indicator is now more prominent.
Manual 2FA setup
You can now set up 2FA manually using a text key.
Previously, 2FA setup required scanning a QR code. With this update, you can either scan the QR code or copy the setup key as text, making 2FA setup easier when QR scanning is not available.
Self Purchase: AML Screening
One more service is now available for Self Purchase — AML Screening. Go to the Solutions page of the Dashboard to get a new solution for your verification.
Self Purchase: Facial Age Estimation
Facial Age Estimation is now available for Self Purchase. Go to the Solutions page of the Dashboard to get a new solution for your verification.
To complete the setup, go to the Advanced Settings in the Dashboard and tick the Enable Facial Age Estimation checkbox.
Discover the full list of available solutions for self-purchase ->Automation
Summy AI Level Builder update
Summy AI Level Builder can now help you enable services after purchase.
You can ask Summy AI for help with product setup, and the requested products can now be configured directly through the self-purchase flow.
This makes post-purchase setup faster and easier, helping you start using purchased services with less manual configuration.
Transaction Monitoring
Device Emulation for sample transactions
Device Emulation is now available for sample transactions in the Dashboard.
You can create sample Fiat, Crypto, Sign up, and Log in transactions with a generated virtual device and a custom set of device risk labels. The full testing flow can be completed directly in the Dashboard.
Learn how Device Emulation works ->Travel Rule
Protocol Manager
Protocol Manager is now available in Travel Rule settings.
You can use Protocol Manager to view available protocols and request the ones you need as part of your Travel Rule setup.
SDK
MobileSDK update
MobileSDK version 1.45 has been released. Changelog:
Main updates include the following:
- Support for the Payment Methods check step — Bank card verification.
- The Sumsub ID banner has been redesigned and the toggle is now enabled by default.
July 6 -> July 10
User Verification
Duplicate search by TIN
We have introduced a new feature that searches for duplicate applicants using their Tax Identification Number (TIN), along with a setting to disable this check if needed.
How it works:
If a new applicant provides the same TIN as an existing one, the system can reject the new applicant as a duplicate. To prevent false rejections from randomly typed numbers (e.g., 1234567890), the current applicant will only be rejected when both of the following conditions are met:
- The TIN matches exactly between the two applicants, and
- The duplicate's TIN was verified against a database, rather than just manually typed.
In all other scenarios, the TIN will not be used for duplicate detection.
New configuration setting:
To complement these changes, a new option, Don't use TIN for duplicates search, has been added to the Applicant account duplicates block within the source key settings.
This checkbox is off by default, meaning the TIN duplicate search is active for all keys that restrict duplicates. If you want to disable TIN-based duplicate searches, check this box for the specific source key.
Back-side template search
The high-confidence document back-side template search has been enabled to detect fraud and prevent the reuse of identical back-side images across different identities.
What's new:
- Identical back-side image detection — The system now flags when two different applicants under the same key submit similar back-side images.
- Automatic rejection — If the back-side images match perfectly but the documents contain different data, the current applicant is automatically rejected.
- Key-level isolation — Duplicate searches are strictly performed within the scope of the same key.
Applicants rejected by this logic will display the following note in the dashboard:
Auto-rejected by high confident document back side template match. Duplicate ids: <duplicate_applicant_id>.
Transaction Monitoring
AI transaction overview agent launch
We have released the final version of the transaction overview agent, delivering full, production-ready functionality.
What's new:
- Instant access — The agent is live for everyone with no beta toggles or manual setup required.
- Summy AI Copilot — A new block is available directly on the transaction page. One click generates a quick summary of the transaction.
- Deep dive chat — You can continue the conversation inside Summy AI Copilot to generate detailed reports or follow smart suggestions to investigate further.
The agent helps with troubleshooting, transaction reviews, and understanding Transaction Monitoring logic by allowing you to:
- Get a detailed transaction overview covering key facts, triggered rules, and anomalies.
- Analyze rule logic to see exactly why a rule triggered (or didn't) and which conditions fired.
- Review relevant AML hits and surface historical transactions matching similar patterns.
- Check if a rule is currently muted or see active tags on the transaction.
- Ask free-form questions about the transaction data beyond the automated suggestions.
AML Screening
Large-volume CSV export for AML cases
The AML cases export functionality has been delivered, making it possible to download an entire filtered dataset to a CSV file in a single request.
What's new:
- Full dataset download — The export from the Checks page now covers all rows matching your filters (including datasets with over 10,000 rows), rather than just the visible page.
- Role-based data masking — Exported fields are classified as either sensitive (e.g., applicant name, date of birth, country) or non-sensitive (e.g., case ID, screening type, match status). The columns included in the download automatically adjust based on account permissions to prevent unauthorized access to personal data.
Availability:
This feature is enabled for all clients in the EU region. To generate these reports, a user must have the Owner access along with the permissions for AML case access, personal data access, and Custom CSV Export.
Export AML case data ->Fraud Prevention
Bulk exporting Fraud Networks data as CSV
The Fraud Networks table now supports bulk CSV export. You can apply any filters—such as Patterns, Network size, Date range, Country, Review status, or Risk labels—and export the matching data into a single file.
The exported file is flat with one row per applicant, repeating network-level fields so you can easily analyze multiple networks at once without nested data.
The export fields have been expanded to match the dashboard view and include additional data for downstream analysis:
- Network context — Connection reasons that triggered the link (exactSameDevice, similarDevice, ip, fingerprint, etc.), last-modified timestamp, and publication status.
- Applicant journey — Sumsub applicant ID, verification level, review status, rejection reasons, and applicant creation timestamp.
- Applicant risk signals (Requires the View check results permission) — Risk labels, risk score, and risk level.
- Applicant country (Requires the View check results permission) — ISO country code.
Note: Fields for which you do not have viewing permissions will be automatically omitted from the CSV file. You can find a detailed description of the export file fields in the documentation.
Export Fraud Networks as CSV ->Dashboard
Korean language support
The Dashboard has been fully translated into Korean to provide a more localized and seamless experience for our clients.
Start your verification journey with Sumsub Dashboard ->Automation
Okta integration
We have launched the Sumsub × Okta integration, allowing Sumsub verification to run directly inside your own Okta policies.
With this integration, you can add Sumsub checks directly into existing workflows to confirm the real person behind an action, requiring no custom development. This closes the gap where a password or MFA token is stolen, ensuring a compromised credential alone is not enough to gain access.
You can decide exactly where the verification runs, who it applies to, and how deep the check needs to be—ranging from a quick liveness scan to full document verification and AML checks.
How to activate:
This is an opt-in feature, so nothing changes automatically. To enable this integration for your account, please contact your Customer Success Manager (CSM).
HubSpot integration
You can now verify counterparties and see real-time KYC results directly within HubSpot contact records, without switching tools.
How it works:
By adding a native Sumsub card to the Contact view in HubSpot, you can start identity checks and view results without leaving your CRM. The setup requires no custom development.
You can use the integration flexibly across your workflows, for example, to verify a counterparty before a deal moves forward, run KYC straight from your pipeline, or simply keep verification statuses visible to your team on the contact record.
Enhance your verification with Sumsub's automation solutions ->