September, 2026
In September, we released updates focused on fraud prevention and clearer verification handling. The new Fraud Prevention Starter Kit gives clients a ready-made way to score applicant risk without building custom rules, and Device Check has been redesigned for clearer visibility into why a device is flagged. We also expanded Business Verification to Venezuela and made rejection and resubmission handling easier for applicants to follow.
September 7 - September 11
Fraud Prevention
Fraud Prevention Starter Kit
We have released the Fraud Prevention Starter Kit — a predefined fraud risk package that turns onboarding signals, including email, phone, IP, device, identity data, and applicant linkages, into one actionable fraud risk level, using a pre-built matrix based on Sumsub's fraud detection experience.
This feature gives clients a practical way to start assessing applicant risk without building custom fraud rules or models from scratch, and targets new account fraud such as mule accounts, multi-accounting, bonus abuse, and synthetic identities.
Strengthen digital trust with Sumsub Fraud PreventionUser Verification
Automatic rejection after repeated failed attempts
Applicants who kept resubmitting after repeated failures used to hit a technical attempt cap after 69 tries, and were then referred to Sumsub support to resolve a limitation on our side.
Applicants are now automatically rejected as spam after 50 failed attempts. The system directs applicants back to the client's own support team, where a custom flow can help them complete verification if appropriate.
Rejection reason in resubmission emails
Resubmission emails now include the moderation comment explaining why an applicant needs to resubmit, helping applicants understand what went wrong and return to onboarding.
The comment appears formatted with line breaks and covers both applicant-level and document-specific rejections. Final rejection emails still send no comment, by design.
This update applies to both KYC and KYB applicants.
Get started with Sumsub User VerificationDashboard
Device Check redesign
Device Check, part of the verification flow when Device Intelligence is enabled, now gives a clearer picture of device risk and why a device is flagged.
What is new:
- Device risk now factors in the number of connections and any links to fraudulent applicants.
- Medium-risk and high-risk labels use separate colors.
- An inline lookup shows linked applicants, with batch actions such as rejecting them all at once.
- A new Device Map View shows IP address geolocation.
- A Definite vs. Potential Match indicator shows confidence in connected applicants found.
- A new Checked Risk Labels section explains why a device is low risk and which checks ran, which varies by platform.
Self-purchasable steps in Level Settings
Clients can now purchase certain features directly from level configuration, without leaving the flow.
Self-purchasable steps appear in the Add step dropdown with a dedicated icon. Clicking one opens the purchase flow inline, and once the feature is enabled, the step is added to the level automatically.
Business Verification
New country in the KYB Local pack: Venezuela
Business verification now covers Venezuela, with data sourced directly from the Venezuela National Contractors Registry.
The integration returns company name, registration number, and legal form, and supports search by both company name and registration number.
Start verifying businesses with SumsubSeptember 14 - September 18
User Verification
Daily transaction creation limit in Sandbox
To ensure environment stability, we have introduced a rate limit of 1,000 transaction creations per API key per 24-hour period in the Sandbox environment. This restriction applies across both the user interface and API requests.
Sumsub x Ashby integration
We have launched an integration with the Ashby recruiting platform to streamline candidate identity verification within existing hiring workflows.
Key details:
- Automated triggers: You can trigger Sumsub identity verification automatically when a candidate reaches a specific hiring stage, such as the offer phase.
- Profile cross-checking: The integration compares the candidate name extracted from their identity document with the name on their Ashby profile, flagging discrepancies for recruiter review.
- No custom code: Integration requires creating an Ashby API key and configuring the Sumsub Marketplace card.
Separate view and manage permissions for applicant notes
Access control for applicant notes has been split into two distinct permissions.
What’s new:
- View applicant notes: A new permission within the View group that grants read-only access to applicant notes across applicant profiles, Case Management, and reports.
- Manage applicant notes: Now exclusively covers write actions, including adding, editing, deleting, pinning notes, and adding attachments.
- Existing roles: To maintain uninterrupted workflows, all roles, users, SSO group mappings, and API tokens previously assigned
manageApplicantNoteshave automatically receivedseeApplicantNotes.
Non-Doc Verification
Australia Non-Doc Identity Verification
We have released a dual-source Non-Doc Identity Verification service for Australia, allowing you to verify users by cross-referencing details across independent databases without document uploads.
What’s new:
- Dual-source validation: Cross-checks user inputs directly against the Document Verification Service (DVS) and national credit bureau records to meet AUSTRAC independent data requirements.
- Document coverage: Supports verification inputs from Australian Driver Licenses, Australian Passports, and foreign passports with valid Australian visas.
- Prerequisites: Access to credit bureau data requires prior approval (typically requiring two to three weeks), and your business must hold a registered physical address in Australia.
Business Verification
EU and Northern Ireland VAT verification via VIES
We have integrated with the European Commission VIES system to provide automated VAT validation across all 27 EU Member States and Northern Ireland.
Key details:
- Input and output: Requires a company VAT number submitted via the Company Data step. The check validates VAT status, in some cases it returns the available company name and address details, and generates a timestamped verification reference ID.
- Workflow setup: Tax checks operate as an add-on to registry checks and do not alter applicant statuses automatically. You can configure a Workflow Builder flow to process VIES results within decision logic.
Dashboard
App tokens page redesign and management options
The App Tokens management page has been redesigned with enhanced filtering and token control capabilities.
Key updates:
- Token status control: You can now temporarily disable active app tokens to block API access and re-enable them later. Disabling a token requires entering a reason of up to 150 characters, which is recorded alongside user details in the audit log.
- Enhanced filtering and search: Search tokens by name, or filter by status, permission, author, and source key. Author and source key filters list all available system values rather than pagination subsets.
- Usage metrics and visibility: The table displays total API request counts over the previous 30 days, device creation metadata, masked token values, and expandable rows detailing assigned permissions, allowed IPs, and source keys.
September 21 - September 25
User Verification
EU Digital Identity Wallet verification: early prototype
We have built a working prototype of EU Digital Identity Wallet (EUDI Wallet) verification, a full identity presentation flow running end to end in our sandbox environment.
The EUDI Wallet is the European Union's government-backed digital identity wallet, giving citizens across member states a single, shared way to prove who they are online.
The prototype offers:
- Government-issued identity data at the highest assurance level under eIDAS.
- Signed, issuer-verified data that is resistant to forged documents, synthetic identities, and deepfakes.
- Selective disclosure, so only the requested information is shared.
- One integration that works across national wallets, with no need to re-integrate per country.
This is an early-access release running in Sandbox, ahead of a full production upgrade. Contact your Customer Success Manager to get started.
Get started with Sumsub User VerificationBusiness Verification
Primary contact for Associated Parties
Clients can now pick one associated party as the company's Primary contact, giving a single, unambiguous account holder for the company. This also determines which profile is prioritized for API syncing.
This is supported in both WebSDK and Dashboard, and appears as a bold label in Company Structure and as its own row in Level Overview.
Dedicated roles for partnerships and funds
Company Structure now includes dedicated, translatable roles for partnership and fund structures, instead of generic roles that clients previously had to rename manually and that still appeared untranslated for Compliance teams.
New roles include:
- Partnerships: Managing Partner, Equity Partner.
- Funds: Fund Investor, Fund Manager, Investment Manager, Investment Adviser, Fund Administrator, Depositary, Custodian, Prime Broker.
- Account User now sits at the top level of the role menu, alongside Representative, Authorized Signatory, Founder, and Legal Advisor, which moved up from Company Roles.
Transaction Monitoring
Use Cases for Rules
Rules used to be organized one way only, by bundle, mixing technical and business logic together. Now there is a second, independent dimension: Use Case.
- Bundle is the technical dimension: the data pattern a rule's logic analyzes, for example amount patterns, device, or velocity. Each rule has exactly one bundle, and this does not affect how the rule runs.
- Use Case is the applied dimension: the compliance program a rule supports, for example Account Takeover, AML Compliance, Travel Rule Kazakhstan, or Pix Brazil. A rule can carry several use cases at once, and this is purely organizational, so it also does not affect how the rule runs.
Use Case is now a field on rules, with its own column and multi-select filter in Rules Library and Installed Rules. The library also groups rules by use case, with an install-by-use-case option.
Crypto monitoring: per-source API keys for blockchain analytics providers
Clients using their own API keys for blockchain analytics providers, including Chainalysis, Elliptic, Crystal, MerkleScience, TRM Labs, and Nominis, can now configure a different API key per source key.
This lets clients apply different risk assessment settings to different groups of users or transactions.
Detect suspicious transactionsDashboard
New permission: View application tokens
We have added a new permission — View application tokens — giving read-only access to the App Tokens page in Dev Space.
With this permission alone, users can view the page but cannot create, edit, or delete tokens. Creating, editing, and deleting tokens still requires the existing Manage application tokens permission.