Handout
Sumsub
User
Verification
Course
Module 4
Case
Management
Sumsub User Verification Course 2
Module 4 Session 1:
Understanding
case creation
Case Management is where you’ll handle most investigations,
whether it’s a failed ID check, a flagged transaction, or
something that doesn’t quite add up in a user’s behavior.
It’s all centralized here. 
↘ With Sumsub, a case is created when something triggers
What a the need for further investigation
case is
↘ That trigger could be a rule you’ve configured (like a large
transaction, a document mismatch, or multiple alerts across
different systems)
↘ It could also be a scheduled event, like periodic re-KYC 
In some setups, you might also create cases manually.
But in most workflows, it’s all automated
How automatic ↘ Imagine a situation where an applicant fails a check and the
case creation looks system automatically takes you from the profile view straight
in practice into the Cases tab 
↘ A case has already been created based on the workflow
you’ve set up 
↘ It appears in the queue as unassigned, waiting for the right
reviewer to pick it up 
↘ This automatic creation ensures that potential issues never
fall through the cracks and that the investigation process
begins with complete context 
Sumsub User Verification Course 3
What’s inside ↘ Once a case is created, it pulls everything you need into one
a case view: the user’s identity documents, their verification history,
transactions, device fingerprints, sanctions results, payment
methods, everything
↘ You’re not toggling between modules or requesting exports;
the full picture is already there
Built-in tools that 1 Checklists: they define the steps an officer needs to
structure the complete before resolving the case
investigation 
2 Deadlines: some jurisdictions require incidents to be
reported quickly, sometimes within 72 hours 
3 Summy, Sumsub’s AI assistant: summarizes the case
context based on existing data and suggests what to
look at next (optional feature) 
4 Blueprints: determine what data shows up in the interface,
what checklist applies, and where the case can be
routed next 
What Blueprints ↘ A Blueprint for onboarding checks might show document
change (examples) images and selfie results
↘ A fraud team’s Blueprint might emphasize transaction
data, IP addresses, and device info
↘ Sumsub offers pre-configured Blueprints for KYC, AML,
and suspicious activity cases, but you can customize
or build your own 
Sumsub User Verification Course 4
How it comes ↘ A user triggers three separate events: an AML screening
together (real-life match, a flagged device, and a suspicious payment. Sumsub
scenarios) rolls them into a single case
↘ A periodic review kicks in, a case is created, and the
assigned team gets a focused checklist with the right context
↘ If a user suddenly starts transferring large amounts from
a new device, that could trigger a case
↘ All actions and decisions are recorded automatically
as you work
Takeaway Case Management gives investigators one place to review
signals, understand what happened, and move through the
investigation with structure and clarity.
See more about Case Management in Sumsub here
Sumsub User Verification Course 5
Module 4 Session 2:
Internal escalation &
team collaboration
This session focuses on how cases move across teams
and how collaboration works when investigations get
more complex. 
Escalation is built ↘ Blueprints determine how a case can move through
into the workflow the workflow
↘ If a case starts in your KYC queue but requires deeper
investigation, the Blueprint might allow it to escalate to
your AML or fraud team
↘ Officers don’t need to guess where a case should go or rely
on Slack messages to transfer ownership. It’s structured and
traceable
↘ When a case moves to another team, they can see e
verything that has already been done: notes, checklist
progress, data, and previous actions
Collaboration ↘ Officers can leave comments, complete tasks, and track
happens inside what’s been done, all in one place
the case
↘ The checklist acts as a shared roadmap, and progress is
visible to anyone who looks at the case later
↘ Every action an investigator takes is automatically attributed
to their name, ensuring the entire workflow is fully traceable
and audit-ready
Sumsub User Verification Course 6
Workload visibility ↘ Each team member has a personal dashboard showing the
for investigators cases they’ve resolved, what’s in progress, and what they’ve
been involved in
↘ Sumsub offers a unified working board called the Majestic
Overview, where officers can see their full workload at a
glance
↘ It shows all Blueprints with open cases, highlights any cases
that already have STRs generated, and displays daily stats
for resolved cases
↘ The board appears automatically once an officer has taken
their first case, and it’s available in both Basic and Growth
versions with no extra setup needed
From internal ↘ If a case involves suspicious activity that meets the threshold
escalation to for a Suspicious Transaction Report (STR), you can generate
regulatory reporting that report directly from inside the case
↘ Sumsub supports the goAML reporting format, which is
used in over 50 jurisdictions
↘ The system auto-fills the relevant data and logs the report
in the case history
Takeaway Whether a case moves between two people or two
departments, or all the way to a regulator, it stays within
a single system, with a shared record and no loss
of information.
Sumsub User Verification Course 7
Module 4 Session 3:
Case audit
& reporting
Resolving a case isn’t the end. You still need to track
what happened, prove it when asked, and in many cases,
report on it. 
Regulatory ↘ If a case leads to the creation of a Suspicious Transaction
reporting Report, the report is linked directly to the case and stored
in the system
↘ You’ll always know who submitted it, when it was sent,
and what jurisdiction it was for
↘ You can create these reports manually, or configure
workflows that guide officers toward reporting when certain
conditions are met
↘ All of these reports, along with the full audit trail, stay in
the case history
Internal tracking ↘ Sumsub provides a dashboard that shows your current case
(real-time visibility) volume, how those cases are distributed across Blueprints,
and how many reports have been filed 
↘ You can filter this by team, assignee, status, or time period to
get a real-time view of what’s going on 
Performance ↘ You can export SLA reports filtered by who worked the case,
monitoring how long it took, or what actions were involved 
↘ This helps leadership spot bottlenecks, assign resources,
and adjust workload distribution 
Sumsub User Verification Course 8
Audit ↘ Every action taken in a case (reviewed documents, added
readiness comments, status changes, even who clicked what) is stored
in the audit log
↘ This isn’t something you have to build manually. It’s already
there, ready to pull for internal compliance or external review
How cases are 1 The officer chooses the appropriate resolution
closed 
2 Adds any necessary notes for context 
3 Resolves the case: the status updates instantly, and the
checklist reflects that all required steps have been completed

4 The resolution becomes part of the permanent case history
and shows up in exports, dashboards, and audits 
Connecting Case ↘ Sumsub supports webhooks and APIs to keep
Management to things connected 
external systems
↘ Webhooks notify your systems when a case is created,
escalated, or resolved 
↘ APIs let you extract full case histories or performance
data on demand 
↘ AML cases and audit logs can be exported in bulk and
integrated into whatever reporting framework your
team uses 
Takeaway Once a case has moved through the system, you’re not left
scrambling to reconstruct what happened. It’s already
tracked, already organized, and available when you need it.
Sumsub User Verification Course 9
Sumsub
is looking
forward to
seeing
you soon!
Sumsub User Verification Course 10
© Sum and Substance Ltd. (UK), 2026.
All rights reserved. Company number 09688671.