July, 2026

This July, we focused on giving clients more control over verification logic, improving account security, and making Dashboard workflows easier to manage.

We introduced Cross Check Rules, a new service for configuring cross-validation. We also added app token creation notifications and expanded Suspected Fraud Duplicate tasks to support face matches in ID documents.

We also refreshed the Dashboard layout, added manual 2FA setup, expanded Self Purchase with AML Screening and Facial Age Estimation, and improved post-purchase setup with Summy AI.

For Transaction Monitoring, Device Emulation is now available for sample transactions in the Dashboard. Travel Rule settings now include Protocol Manager, and the latest Mobile SDK update adds support for the Payment Methods check step and a redesigned Sumsub ID banner.

Stay tuned for more!

June 29 -> July 3

User Verification

Cross Check Rules release

We have released a new service — Cross Check Rules.

This update transforms cross-validation into a flexible rule builder, giving clients more control over how applicant data is checked across different verification steps.

You can now use Basic mode for standard cross-check settings or switch to Advanced mode to configure custom rules in more detail. In Advanced mode, you can:

  • Create rules.
  • Add and reorder conditions.
  • Test rule logic directly in the Dashboard.

The Dashboard has also been redesigned to make working with presets, testing custom rules, and reviewing cross-validation results easier and more intuitive. Detailed cross-validation results are now available directly in the applicant profile, helping you understand which checks were triggered and why.

App token creation notifications

We now send email notifications when an app token is created. This gives you better visibility into account activity and helps you react faster if suspicious access is detected.

The notification includes key security details, such as the token name, creation time in UTC, IP address, and location. It also includes quick links to app tokens and active sessions, so users can review activity and revoke a token if needed.

Notifications are sent to members who can access the key or client group where the app token was created and have the Manage application tokens permission.

Explore Sumsub app tokens ->

Suspected Fraud Duplicate tasks for ID documents

Suspected Fraud Duplicate tasks can now be created based on face matches in ID documents.

Previously, face-matching search worked only with selfies. With this update, Sumsub can match faces across ID documents. If two applicants have the same face but different names or dates of birth, Sumsub creates a Fraud Duplicate task.

Dashboard

Editable SSO users and Owner assignment

SSO users can now be edited in the Dashboard, and the Owner role can be assigned to them.

Previously, SSO users were fully managed through the identity provider, meaning their permissions were overwritten on every login. Because of this, clients using SSO could not assign the Owner role to an SSO account.

With this update, SSO users can now be edited directly in the Dashboard. Users with the required permissions can assign the Owner role to an SSO user when needed. SSO users with the Owner role are no longer affected by identity provider group and permission mapping during login, so their permissions stay unchanged. Their identity details, such as first and last name, continue to sync from the identity provider.

Regular SSO users remain fully managed through the identity provider. SSO sync cannot automatically promote a user to Owner, and the last-owner protection still applies.

Learn more about the Owner account functionality->

Sumsub Support Portal

The new Sumsub Support Portal is now available.

The portal gives clients a dedicated space to manage support requests and access problem-centric resources directly from the Dashboard. They can submit new support requests, track active and historical tickets, filter tickets by status, and search by keywords or specific Applicant IDs.

The portal also includes an FAQ library with answers to common support scenarios, such as Dashboard troubleshooting, AML review guidance, and applicant rejection reasons. The FAQ will continue to be updated and expanded.

The Support Portal is integrated with the Dashboard and is available only to logged-in users.

Dashboard visual refresh

Content is now organized into clearer visual blocks, making pages easier to scan and helping users focus on the main workspace:

  • Navigation, main content, and Summy AI are now visually separated into dedicated areas.
  • Summy AI opens in a dedicated side panel across Dashboard pages.
  • The Sandbox mode indicator is now more prominent.

Manual 2FA setup

You can now set up 2FA manually using a text key.

Previously, 2FA setup required scanning a QR code. With this update, you can either scan the QR code or copy the setup key as text, making 2FA setup easier when QR scanning is not available.

Self Purchase: AML Screening

One more service is now available for Self Purchase — AML Screening. Go to the Solutions page of the Dashboard to get a new solution for your verification.

Self Purchase: Facial Age Estimation

Facial Age Estimation is now available for Self Purchase. Go to the Solutions page of the Dashboard to get a new solution for your verification.

To complete the setup, go to the Advanced Settings in the Dashboard and tick the Enable Facial Age Estimation checkbox.

Discover the full list of available solutions for self-purchase ->

Automation

Summy AI Level Builder update

Summy AI Level Builder can now help you enable services after purchase.

You can ask Summy AI for help with product setup, and the requested products can now be configured directly through the self-purchase flow.

This makes post-purchase setup faster and easier, helping you start using purchased services with less manual configuration.

Transaction Monitoring

Device Emulation for sample transactions

Device Emulation is now available for sample transactions in the Dashboard.

You can create sample Fiat, Crypto, Sign up, and Log in transactions with a generated virtual device and a custom set of device risk labels. The full testing flow can be completed directly in the Dashboard.

Learn how Device Emulation works ->

Travel Rule

Protocol Manager

Protocol Manager is now available in Travel Rule settings.

You can use Protocol Manager to view available protocols and request the ones you need as part of your Travel Rule setup.

SDK

MobileSDK update

MobileSDK version 1.45 has been released. Changelog:

Main updates include the following:

  • Support for the Payment Methods check step — Bank card verification.
  • The Sumsub ID banner has been redesigned and the toggle is now enabled by default.

July 6 -> July 10

User Verification

Duplicate search by TIN

We have introduced a new feature that searches for duplicate applicants using their Tax Identification Number (TIN), along with a setting to disable this check if needed.

How it works:

If a new applicant provides the same TIN as an existing one, the system can reject the new applicant as a duplicate. To prevent false rejections from randomly typed numbers (e.g., 1234567890), the current applicant will only be rejected when both of the following conditions are met:

  • The TIN matches exactly between the two applicants, and
  • The duplicate's TIN was verified against a database, rather than just manually typed.

In all other scenarios, the TIN will not be used for duplicate detection.

New configuration setting:

To complement these changes, a new option, Don't use TIN for duplicates search, has been added to the Applicant account duplicates block within the source key settings.

This checkbox is off by default, meaning the TIN duplicate search is active for all keys that restrict duplicates. If you want to disable TIN-based duplicate searches, check this box for the specific source key.

Back-side template search

The high-confidence document back-side template search has been enabled to detect fraud and prevent the reuse of identical back-side images across different identities.

What's new:

  • Identical back-side image detection — The system now flags when two different applicants under the same key submit similar back-side images.
  • Automatic rejection — If the back-side images match perfectly but the documents contain different data, the current applicant is automatically rejected.
  • Key-level isolation — Duplicate searches are strictly performed within the scope of the same key.

Applicants rejected by this logic will display the following note in the dashboard:

Auto-rejected by high confident document back side template match. Duplicate ids: <duplicate_applicant_id>.

Customize identity verification settings ->

Transaction Monitoring

AI transaction overview agent launch

We have released the final version of the transaction overview agent, delivering full, production-ready functionality.

What's new:

  • Instant access — The agent is live for everyone with no beta toggles or manual setup required.
  • Summy AI Copilot — A new block is available directly on the transaction page. One click generates a quick summary of the transaction.
  • Deep dive chat — You can continue the conversation inside Summy AI Copilot to generate detailed reports or follow smart suggestions to investigate further.

The agent helps with troubleshooting, transaction reviews, and understanding Transaction Monitoring logic by allowing you to:

  • Get a detailed transaction overview covering key facts, triggered rules, and anomalies.
  • Analyze rule logic to see exactly why a rule triggered (or didn't) and which conditions fired.
  • Review relevant AML hits and surface historical transactions matching similar patterns.
  • Check if a rule is currently muted or see active tags on the transaction.
  • Ask free-form questions about the transaction data beyond the automated suggestions.
Get started with Sumsub Transaction Monitoring ->

AML Screening

Large-volume CSV export for AML cases

The AML cases export functionality has been delivered, making it possible to download an entire filtered dataset to a CSV file in a single request.

What's new:

  • Full dataset download — The export from the Checks page now covers all rows matching your filters (including datasets with over 10,000 rows), rather than just the visible page.
  • Role-based data masking — Exported fields are classified as either sensitive (e.g., applicant name, date of birth, country) or non-sensitive (e.g., case ID, screening type, match status). The columns included in the download automatically adjust based on account permissions to prevent unauthorized access to personal data.

Availability:

This feature is enabled for all clients in the EU region. To generate these reports, a user must have the Owner access along with the permissions for AML case access, personal data access, and Custom CSV Export.

Export AML case data ->

Fraud Prevention

Bulk exporting Fraud Networks data as CSV

The Fraud Networks table now supports bulk CSV export. You can apply any filters—such as Patterns, Network size, Date range, Country, Review status, or Risk labels—and export the matching data into a single file.

The exported file is flat with one row per applicant, repeating network-level fields so you can easily analyze multiple networks at once without nested data.

The export fields have been expanded to match the dashboard view and include additional data for downstream analysis:

  • Network context — Connection reasons that triggered the link (exactSameDevice, similarDevice, ip, fingerprint, etc.), last-modified timestamp, and publication status.
  • Applicant journey — Sumsub applicant ID, verification level, review status, rejection reasons, and applicant creation timestamp.
  • Applicant risk signals (Requires the View check results permission) — Risk labels, risk score, and risk level.
  • Applicant country (Requires the View check results permission) — ISO country code.

Note: Fields for which you do not have viewing permissions will be automatically omitted from the CSV file. You can find a detailed description of the export file fields in the documentation.

Export Fraud Networks as CSV ->

Dashboard

Korean language support

The Dashboard has been fully translated into Korean to provide a more localized and seamless experience for our clients.

Start your verification journey with Sumsub Dashboard ->

Automation

Okta integration

We have launched the Sumsub × Okta integration, allowing Sumsub verification to run directly inside your own Okta policies.

With this integration, you can add Sumsub checks directly into existing workflows to confirm the real person behind an action, requiring no custom development. This closes the gap where a password or MFA token is stolen, ensuring a compromised credential alone is not enough to gain access.

You can decide exactly where the verification runs, who it applies to, and how deep the check needs to be—ranging from a quick liveness scan to full document verification and AML checks.

How to activate:

This is an opt-in feature, so nothing changes automatically. To enable this integration for your account, please contact your Customer Success Manager (CSM).

HubSpot integration

You can now verify counterparties and see real-time KYC results directly within HubSpot contact records, without switching tools.

How it works:

By adding a native Sumsub card to the Contact view in HubSpot, you can start identity checks and view results without leaving your CRM. The setup requires no custom development.

You can use the integration flexibly across your workflows, for example, to verify a counterparty before a deal moves forward, run KYC straight from your pipeline, or simply keep verification statuses visible to your team on the contact record.

Enhance your verification with Sumsub's automation solutions ->

July 27 -> July 31

User Verification

CSV-based Custom ID document settings configuration

You can now upload a CSV file to configure Custom ID document settings. Follow the path to use the new Upload CSV button:

  • Integrations → Global settings → User verification → Supported ID Documents
  • Verification level → Configurations → ID document settings.

Note:

  • The file must be uploaded in the exact format as produced by Download CSV.
  • After confirmation, all Custom ID document settings for that level/key are fully overwritten and take effect immediately for new verifications.
  • Imports are all-or-nothing: if any part of the file is invalid, nothing changes and you get an error message.
Customize supported ID documents ->

Transaction Monitoring

Expressions update: PreScoringContext is now Service

We continuously update expressions in our TM Rule Builder. The following expressions have been updated in the recent release:

  • preScoringContext.amlCaseReviewservice.amlCaseReview
  • preScoringContext.cryptoTxnInfoservice.cryptoTxnInfo

Note: For now, legacy expression versions will continue to work. However, we will soon start throwing errors for the older ones. Visit the dedicated page to get more details.

Rules bulk export to YAML

Dashboard users with the Manage TM rules permission can now export TM rules in bulk to YAML. The YAML format can be easily converted to CSV, PDF, or other formats using external tools like LLMs or online converters.

New SumScript functions

We have introduced new SumScript functions to enhance Transaction Monitoring rule flexibility across client list searches and person name comparisons.

What’s new:

  • Fuzzy search in client lists. Four new functions for matching a value against a client list with varying levels of strictness:
    • fuzzyMatchExactInList
    • fuzzyMatchStrictInList
    • fuzzyMatchDefaultInList
    • fuzzyMatchFuzzyInList
  • Substring search in lists: anyKeyIsSubstringOf — checks whether any key from a list exists as a substring within a specified value.
  • Person name comparison:
    • personNamesIncompatible — performs exact token matching to determine if two names are unlikely to belong to the same individual.
    • personNamesFuzzyIncompatible — performs fuzzy token matching to identify name discrepancies while accounting for typos and transliteration differences.

Important: The fuzzy search in client lists only works if the target client list contains fewer than 2,000 values. If a list exceeds this limit, the rule will fail.

Get started with Sumsub Transaction Monitoring ->

Automation

Impersonation via URL

The ?clientId= parameter in your URL now determines which Dashboard account you're viewing, and stays attached as you navigate the Dashboard.

How it works:

  • Web address as the source of truth: The ?clientId= in your URL dictates which of your accounts or workspaces you are currently viewing. As you navigate around the Dashboard, this parameter stays attached to your address bar automatically.
  • Seamless link sharing: If you copy a link from your address bar and send it to a colleague, they will open the exact account you were looking at.
  • Automatic redirects & cleanups:
    • If you open an old link that contains legacy parameters (like ?permanentClientId=), the system will automatically convert it to the new ?clientId= format and redirect you.
    • If you navigate to the Dashboard without any ?clientId= in the URL, you will be automatically routed to your default account key with the parameter attached.

Automatic update of ongoing workflows

Ongoing workflow runs can automatically move to a newer version of the workflow.

How it works:

While an applicant's run is in progress, the system checks whether the steps coming after their current position have changed in the new workflow version. If they have, the current run is canceled and a new run starts from that same point, now continuing on the new version.

Note:

  • Automatic updates don't affect the workflow steps that have already been passed by the applicant.
  • Automatic run upgrade does not apply to completed runs.

Bank card payment option for Enterprise invoices

Enterprise clients can now pay invoices directly using a bank card.

How to pay with a card:

  • Go to the Invoices page and locate the required invoice.
  • Click Pay next to the invoice and enter your card details in the pop-up window. If needed, save the card data for future transactions.

Important:

  • Saving card details does not enable auto-debiting for future invoices; it simply saves the payment method for future manual payments.
  • Card payments are currently capped at 1,500 USD per invoice.

Sumsub agent skills

We are excited to announce a game-changing feature: Sumsub agent skills. This public package turns AI coding assistants (such as Claude Code, Codex, and Cursor) into expert tools for Sumsub integration and configuration.

What’s new:

  • Ready-made skills: The package cover both technical integration (WebSDK, access tokens, webhooks) and account configuration (levels, questionnaires, proof-of-address presets, workflows, transaction monitoring rules, and transactions)
  • Conversational app integration: Integrate Sumsub into your application via natural language prompts, letting your AI handle the implementation steps automatically.
  • Regulation-to-configuration mapping: Upload a regulatory PDF (such as MiCA, AML directives, or internal compliance policies) to let the agent map requirements directly to a Sumsub setup and take the necessary actions.

How to get started:

  1. Run the command npx skills add sumsub/agent-skills --all in your terminal to install the skills across modern agents.
  2. Generate a sandbox AI-scoped App Token in the Dashboard (Connect Sumsub to your AI agent → Build & configure).
  3. Prompt your AI to integrate Sumsub and configure your verification flows.
Set up your verification journey with Sumsub's automation solutions ->

Dashboard

Self Purchase: Automated corporate registry check

You can now enable Automated corporate registry check on the Solutions page. The check can be turned on by an Owner account and is only available to Enterprise clients.

Learn more about Automated corporate registry check ->