By NHI Mgmt Group Editorial TeamBased on SumSub: “Statement Addressing False Allegations Circulating About Sumsub” (June 8, 2026)

TL;DR: Claims about ownership, Russia ties, data transfer, and disclosure are false, while pointing to its Trust Center, UBO filings, and public corporate records as evidence of transparency and compliance, according to SumSub. For IAM and security teams, the broader issue is not the vendor dispute itself, but how quickly trust, ownership, and data-location assumptions become governance questions.


At a glance

What this is: This is a vendor rebuttal about ownership, data residency, and disclosure claims, with the core finding that due diligence hinges on verifiable governance evidence rather than narrative allegations.

Why it matters: It matters because IAM, procurement, and security teams increasingly have to validate third-party trust, operating jurisdictions, and disclosure posture before allowing sensitive data or regulated workflows.


Context

Vendor transparency disputes are not just reputational events. They become governance problems when security, legal, procurement, and identity teams must decide whether a supplier’s ownership, control structure, data handling, and disclosure posture are sufficiently evidenced for regulated use.

In this case, the primary issue is vendor due diligence rather than incident response. The question for practitioners is how to distinguish verifiable corporate records, security attestations, and data-location statements from unsupported claims that can still influence procurement and access decisions.


Key questions

Q: How should security teams verify vendor transparency before granting access?

A: Security teams should verify ownership records, data residency claims, subprocessors, and independent attestations before granting access to sensitive workflows. The goal is to replace narrative trust with documented evidence that can be reviewed, renewed, and audited. If the supplier cannot substantiate those claims, the access decision should remain constrained.

Q: What breaks when vendor ownership information is incomplete?

A: When ownership information is incomplete, accountability becomes difficult to prove and the buyer cannot reliably assess who controls the supplier. That weakens due diligence, complicates legal review, and makes it harder to justify data-sharing or privileged integrations in regulated environments.

Q: Why do data residency claims matter in third-party risk reviews?

A: Data residency claims determine where personal or regulated data can be stored, processed, and accessed, which affects legal exposure and operational control. If a vendor cannot clearly identify hosting regions, sub-processors, and contractual restrictions, security teams cannot judge whether the service fits the organisation’s compliance boundary.

Q: How do trust centres fit into vendor due diligence?

A: Trust centres are useful evidence repositories, but they are not substitutes for independent validation. Teams should use them to collect certifications, security controls, and disclosure artefacts, then compare those materials with corporate records, contractual terms, and ongoing monitoring requirements.


Technical breakdown

What makes vendor due diligence a governance control rather than a procurement formality?

Vendor due diligence is the control plane that lets organisations decide whether a third party can be trusted with sensitive data, regulated workflows, or privileged integration paths. It is not satisfied by a marketing page or a single security badge. For IAM teams, the meaningful evidence set includes ownership records, data-processing disclosures, subprocessors, certifications, and clear accountability for where credentials and personal data are handled. When that evidence is incomplete, the organisation is making access decisions on assumption rather than verification.

Practical implication: Require a documented evidence pack before onboarding vendors into identity-connected or data-sensitive workflows.

How do ownership, UBO disclosure, and control structure affect identity risk?

Ultimate beneficial ownership is relevant because it reveals who can influence a vendor’s governance, not just who operates the brand. In identity and third-party risk reviews, ownership structure matters when a supplier will process personal data, sit inside privileged integration chains, or support regulated operations. Public filings, trust structures, and shareholder records help establish whether the declared control model is consistent over time. The governance question is not simply who says they own the company, but whether that ownership is auditable, stable, and aligned with the vendor’s disclosed operating model.

Practical implication: Cross-check UBO, PSC, and corporate registry records against the vendor’s security and privacy representations.

Why does data residency evidence matter in third-party IAM decisions?

Data residency is a governance issue because it changes which laws, subprocessors, and operational jurisdictions apply to the vendor relationship. If end-user data is processed in one region but a vendor’s story suggests another, the resulting ambiguity affects risk acceptance, contractual controls, and auditability. For regulated environments, the concern is not only where data is stored, but whether the vendor can prove the claim through current subprocessor listings, hosting disclosures, and contractual commitments. Identity teams should treat residency claims as part of the access decision, not a post-signature footnote.

Practical implication: Verify hosting regions and subprocessors before approving vendors for systems that carry regulated identity data.


NHI Mgmt Group analysis

Vendor transparency is now an identity governance issue, not a brand issue. When a supplier handles sensitive information, the due diligence record becomes part of the control environment that governs access, trust, and data sharing. The practical implication is that procurement evidence, corporate filings, and security attestations need to be evaluated together, not as separate workstreams.

Ownership and control structure are material because they shape accountability. A vendor can publish security claims, but if the buyer cannot verify who ultimately controls the entity, governance remains incomplete. That is why UBO records, shareholder structures, and public corporate filings matter in regulated vendor reviews.

Data-location claims must be verified as operational facts, not accepted as statements of intent. If a vendor says end-user data sits in a specific region and no Russia-based processors are engaged, the buyer still needs evidence that the statement is current and contractually enforced. The control failure is not technical ambiguity alone, but the absence of a repeatable verification process.

Trust Center disclosures only reduce risk when they are treated as decision inputs, not reassurance artifacts. Certifications, selected restricted documents, and public disclosures can support review, but they do not replace contract controls, subprocessor scrutiny, or periodic re-validation. Practitioners should use them to narrow uncertainty, not to end the review.

What this signals

Vendor transparency should be treated as a control requirement. If a supplier cannot show who controls it, where data lives, and what it discloses to customers, the buyer is accepting governance risk rather than reducing it.

Public filings and attestation artefacts only matter when they are operationalised. The practical test is whether those records are reviewed at onboarding, contract renewal, and access recertification, not whether they exist in a folder or portal.


For practitioners

  • Validate corporate ownership records Check UBO, PSC, and shareholder filings against the vendor’s declared control structure before approving access to regulated data or workflows.
  • Review data residency and subprocessors Confirm where end-user data is processed, which regions host it, and which subprocessors are in scope before signature and at renewal.
  • Treat trust centres as evidence sources Use the Trust Center, SOC 2 materials, PCI DSS attestations, and restricted documentation as evidence inputs, then test whether they match contractual commitments.
  • Reassess third-party access after major disclosure disputes If a vendor becomes the subject of ownership or transparency allegations, re-run access approvals for integrations, privileged accounts, and sensitive data sharing.

Key takeaways

  • Vendor due diligence becomes an identity and data-governance problem when a supplier handles sensitive information for regulated workflows.
  • Ownership, residency, and disclosure claims need evidence, not assumption, because those details shape access decisions and accountability.
  • Trust centres help, but practitioners should validate them against corporate records, subprocessors, and contractual commitments before approving third-party access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OV-01 — Oversight of the cybersecurity risk management strategyThis article is about verifying third-party transparency and accountability in supplier oversight.
ID.AM-07 — Inventories of data, hardware, software, systems, facilities, services, and people are maintainedVendor due diligence depends on knowing which supplier, region, and service instances are in scope.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThird-party access should be approved only when evidence supports the trust decision.
Recommendation — Use governance oversight to require evidence-based vendor reviews before approving sensitive access or data sharing. Maintain a current inventory of vendors, subprocessors, and data-bearing services tied to identity workflows. Tie vendor access approvals to documented authorisation evidence and review them on a fixed cadence.
ISO/IEC 27001:2022A.5.19 — Information security in supplier relationshipsThe article centres on supplier disclosure, assurance, and due diligence.
Recommendation — Apply supplier-security requirements to verify transparency claims before onboarding or renewing vendors.
CSA Cloud Controls MatrixIAM — Identity and Access ManagementSupplier transparency directly affects how identity-connected services and access paths are governed in the cloud.
Recommendation — Map third-party access to IAM controls and require evidence for identity, entitlement, and regional data handling.

Key terms

  • Vendor Due Diligence: Vendor due diligence is the structured review performed before onboarding or renewing a supplier relationship. It examines risk posture, control evidence, regulatory alignment, and business criticality to determine whether the organisation can safely share data or depend on the vendor for an important service.
  • Ultimate Beneficial Owner: The person or people who ultimately control or benefit from a company, even if that control is held through layers of legal entities or trusts. In security and compliance reviews, UBO evidence helps determine who can influence operations, contracts, and risk decisions.
  • Data residency: The requirement that data remain in a specific jurisdiction or region for storage, processing, or both. In regulated identity programmes, residency is part of the assurance model because it influences legal exposure, audit scope, and the set of controls needed to prove compliance.
  • Trust Center: A vendor-published collection of security, privacy, and compliance artefacts used to support customer due diligence. It is only useful when the information is current, specific, and consistent with contractual and operational reality, rather than being a marketing summary.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org