Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · July 28, 2026

Adverse Media Screening: Process, Tuning, and Risks

An operational guide to adverse media screening: regulatory context, source quality, matching, triage, false positives, tuning, ongoing monitoring, testing, and governance.

By DiditUpdated
adverse-media-screening-process-tuning-guide.png

Adverse media screening is the process of finding and assessing public reporting that may reveal financial-crime, integrity, or reputational risk connected to a customer, beneficial owner, counterparty, or related party. It is also called negative news screening, adverse news screening, or negative media screening.

The useful output is not a list of alarming headlines. It is a documented assessment that connects the correct subject to a relevant event, preserves the source and event stage, weighs credibility and recency, and explains what the information changes in customer due diligence. An allegation, investigation, charge, conviction, acquittal, and corrected article are different evidence states.

For the wider lifecycle, see the AML compliance guide; this article stays with media retrieval, adjudication, tuning, and governance.

Key takeaways

  • Adverse media is risk evidence, not a verdict. A result can change due diligence or monitoring without proving that the subject committed an offence.
  • FATF supports a risk-based use of external information. Its standards do not create a universal requirement to buy a database or screen every person in the same way.
  • Entity and event resolution come before judgment. Establish the subject, then weigh source quality, corroboration, date, allegation maturity, and later outcomes.
  • False-positive management is a control, not a cleanup task. Better input data, matching, deduplication, suppression, and feedback reduce noise without hiding material risk.
  • Tuning needs measurable recall and workload. Alert volume alone cannot show whether the program finds relevant events or merely generates review.

What is adverse media screening?

Adverse media screening searches public information for events relevant to a defined risk policy. Common categories include money laundering, fraud, bribery and corruption, sanctions evasion, terrorist financing, organized crime, trafficking, tax crime, cybercrime, environmental crime, and other predicate offences.

The scope should come from the organization’s products, customers, geographies, legal duties, and risk assessment. “Negative” is too broad to be an operating rule. A poor product review, labor dispute, political criticism, civil claim, arrest, regulatory fine, and money-laundering conviction do not carry the same financial-crime relevance.

The Wolfsberg Group Negative News Screening FAQs define negative news broadly as public-domain information that a financial institution considers relevant to managing financial-crime risk. They also emphasize proportionality: screening may add little value for some lower-risk populations, while targeted or continuing searches may be justified for higher-risk relationships.

Adverse media, sanctions, PEP, and transaction screening compared

ControlWhat it comparesTypical resultImportant limitation
Adverse media screeningA subject against public reporting about risk eventsCandidate article or eventReporting may be incomplete, false, duplicated, outdated, or about another person
Sanctions screeningA subject or transaction against applicable designation dataPotential list or ownership matchName similarity alone does not establish a match or the legal consequence
PEP screeningA person and related parties against public-function dataPotential PEP relationshipPEP status is preventive risk context, not evidence of crime
Transaction screeningPayment parties and fields against lists or rulesPayment alertIt observes transaction data, not the full customer relationship
Transaction monitoringActivity against expected behavior, scenarios, or modelsBehavioral alertAn anomaly is not automatically suspicious

These controls can inform each other but should not collapse into one score. Adverse reporting about a beneficial owner may justify enhanced due diligence. It does not automatically resolve a sanctions match, prove suspicion, or establish that every linked transaction is illicit.

What does FATF expect?

The FATF Recommendations require countries to implement risk-based anti-money-laundering and counter-terrorist-financing measures. Recommendation 10 covers customer due diligence and ongoing scrutiny; Recommendation 12 adds measures for politically exposed persons; Recommendation 20 addresses suspicious-transaction reporting.

FATF does not state that every organization must purchase an adverse-media database or run identical searches on every customer. Its guidance on politically exposed persons explains that internet, media, commercial databases, and other external sources can assist. The guidance is equally clear that commercial databases are neither required by the Recommendations nor sufficient for compliance. They supplement customer due diligence; they do not replace it.

This distinction matters. The control objective is to understand and manage relevant risk, not to prove that a search button was pressed. A proportionate program defines:

  • which subjects and related parties are in scope;
  • which offence categories and event stages matter;
  • when screening occurs and what triggers rescreening;
  • which sources, languages, and markets require coverage;
  • how results change due diligence, approval, monitoring, or review;
  • who can close, escalate, or override a result;
  • what evidence and rationale must be preserved.

In the European Union, Directive (EU) 2015/849 requires risk-based customer due diligence, higher-risk measures, ongoing monitoring, records, and internal controls. It does not convert every media allegation into a legal finding. EU rules and local implementations should be read with sector guidance and the applicable national law.

Where adverse media fits in the customer lifecycle

Onboarding

Screening can identify relevant events before a relationship begins. The result should feed the customer-risk assessment and determine whether more information, source-of-funds work, senior approval, narrower product access, or another measure is justified.

Enhanced due diligence

Higher-risk relationships may require deeper, locally informed searches. A reviewer may need original-language sources, court or regulatory records, company ownership data, and corroboration rather than a translated headline.

Periodic review

An updated search can reveal events since the previous review. Delta screening should distinguish new reporting from old events that were already assessed, preventing the same article cluster from becoming a fresh alert every cycle.

Event-driven review

Changes in ownership, geography, occupation, transaction behavior, PEP status, sanctions exposure, or other customer data can justify targeted rescreening. The trigger and resulting scope should be recorded.

Ongoing monitoring

Continuous or frequent source updates can surface new events between scheduled reviews. The operational requirement is not merely speed: the system must connect the event to the correct customer, preserve what changed, and route it to a decision owner.

A defensible screening workflow

1. Define the risk taxonomy

Create a controlled list of offence categories, event stages, and policy consequences. Separate allegation, investigation, arrest, charge, trial, conviction, dismissal, acquittal, settlement, and regulatory action. Record whether civil, administrative, and criminal events have different treatment.

Broad keywords such as “crime,” “scandal,” or “investigation” create noise without a taxonomy. A category should explain why the event is relevant to the organization’s financial-crime exposure.

2. Select the screened population

Decide whether the control covers customers, beneficial owners, directors, controllers, representatives, counterparties, vendors, or other parties. Apply the same ownership and relationship logic used elsewhere in due diligence.

Screening everyone at maximum depth may consume review capacity without improving risk detection. Screening only the named customer may miss the person who actually owns or controls the relationship.

3. Prepare identity data

Match quality begins with input quality. Useful fields include:

  • complete current and former names;
  • aliases, local scripts, and transliterations;
  • date or year of birth;
  • nationality and residence;
  • company registration identifiers;
  • locations and occupations;
  • ownership or related-party relationships.

Do not collect extra personal data merely because a vendor accepts it. Use fields that improve a defined matching or review decision and have an appropriate legal basis.

4. Retrieve relevant sources

Coverage should reflect where customers operate and where relevant events are reported. International news agencies offer reach; national and local publications can provide events absent from global sources; official court, regulator, enforcement, and company records can add primary evidence.

Search and aggregation systems should preserve the original URL, publisher, author where available, publication and event dates, language, retrieval date, article text or lawful archive reference, and any translation provenance.

5. Resolve the subject

Before judging the article, decide whether it concerns the screened person or entity. Compare identifiers, relationships, location, occupation, age, company, and timeline. Classify the result as confirmed, probable, possible, false match, or insufficient data under a documented rule.

A common name and a relevant keyword are not enough. Conversely, a minor spelling difference should not hide an otherwise strong identity match.

6. Assess the event

Evaluate:

  • relevance: does the event fit an in-scope risk category?
  • stage: allegation, inquiry, charge, conviction, or later resolution?
  • source quality: is there editorial oversight, independence, attribution, and original reporting?
  • corroboration: do independent reliable sources or official records support it?
  • recency and persistence: when did the event occur, and what happened later?
  • severity and proximity: what conduct is alleged, and what is the subject’s role?
  • customer connection: how does the event affect the product, ownership, expected activity, or jurisdiction?

The reviewer should distinguish facts reported by the source from the source’s characterization and from the reviewer’s inference.

7. Apply a policy outcome

Possible outcomes include no change, request more information, increase customer risk, apply enhanced due diligence, require approval, intensify monitoring, restrict a feature, investigate activity, or decline under a documented policy. The applicable law and circumstances determine whether reporting must be considered.

The screening result should never file a regulatory conclusion automatically. Authorized staff own suspicion and reporting decisions.

8. Preserve the record

Store the subject-resolution evidence, source snapshot or lawful reference, risk category, event stage, material facts, reviewer rationale, policy version, decision, approver, and timestamps. Record later corrections, acquittals, article removals, and customer-provided evidence rather than overwriting history.

How to assess source credibility

Source credibility is not binary. A practical hierarchy can include:

  1. official judgments, regulatory notices, enforcement releases, and public records;
  2. original reporting from established outlets with editorial controls;
  3. reputable secondary reporting that identifies its sources;
  4. local or specialist reporting requiring contextual review;
  5. opinion, user-edited content, anonymous posts, and social media requiring corroboration.

The Wolfsberg FAQs recommend considering completeness, accuracy, geographic coverage, editorial oversight, independence, corroboration, original sourcing, and geopolitical context. A widely repeated claim can still originate from one weak source, so count independent reporting rather than duplicate syndication.

Deletion or correction is also evidence. A robust system can show whether an article changed and why a prior decision remains reasonable.

False positives: where they come from

A false positive is a candidate that should not become a material adverse-media finding. Common causes include:

  • common names or incomplete customer data;
  • transliteration and token-order differences;
  • article subjects mentioned only incidentally;
  • broad keywords used in unrelated contexts;
  • duplicated or syndicated articles;
  • an event outside the policy taxonomy;
  • allegations later dismissed or reporting corrected;
  • a company confused with a similarly named entity;
  • stale events repeatedly surfaced as new.

Not every irrelevant alert is a matching failure. Some are entity-resolution failures, some taxonomy failures, and some are duplicate-management failures. Label the cause so tuning addresses the right layer.

How to reduce false positives without creating blind spots

Improve identity features

Use additional identifiers when available and lawful. A date of birth, location, company, or occupation can distinguish two people with the same name. Missing data should lower confidence, not silently become a no-match.

Tune by risk category and event stage

Separate high-relevance offence terms from generic negativity. Use stage vocabulary to distinguish “investigated” from “convicted,” while preserving the possibility that an early-stage event can still be relevant.

Deduplicate by event, not only URL

Cluster articles that describe the same underlying event. Preserve distinct sources for corroboration, but route one review unit rather than twenty near-identical alerts.

Use controlled suppression

A false-match decision can be reused only when the identity facts and event remain equivalent. Suppression needs an expiry or invalidation rule for new identifiers, new events, changed ownership, or stronger sources.

Keep uncertainty visible

Auto-discount only where a rule has strong exclusion evidence. A missing birth date is not proof of a mismatch. Route ambiguous high-risk cases to review instead of forcing a binary answer.

Feed reviewer outcomes back into tuning

Capture whether alerts were wrong subject, irrelevant event, duplicate, weak source, stale event, or true material finding. Aggregate these reasons by population, language, source, rule, and threshold.

Tuning and performance measurement

No single metric describes screening quality. Track a balanced set:

MeasureWhat it revealsFailure if used alone
Candidate rateWork generated per screened subjectLower can mean cleaner results or missed risk
False-positive rateShare of candidates closed as irrelevantDepends on review policy and test population
Relevant-event recallKnown relevant events foundRequires a maintained, representative test set
PrecisionShare of candidates that are relevantCan improve by narrowing scope too far
Duplicate rateRepeated articles or eventsDoes not measure missed coverage
Time to triageOperational responsivenessFast review can still be poor review
Escalation and override ratePolicy and reviewer behaviorNeeds reason and quality sampling
Source and language coverageReach across expected marketsA source count does not show useful coverage

Build a labeled evaluation set with confirmed matches, false matches, aliases, common names, multiple scripts, historical events, corrections, weak sources, duplicate clusters, and known relevant events. Segment results by customer type, geography, language, and risk category. Re-run it before and after material changes.

Production outcomes also need quality assurance. Sample closed alerts, escalations, auto-discounts, and overrides. Compare reviewers for consistency and track whether later events expose an earlier miss.

Common adverse media screening mistakes

Treating an allegation as proof

Preserve the event stage and source wording. Risk decisions can respond to uncertainty without declaring guilt.

Assuming “no result” means “no risk”

Media coverage varies by country, language, wealth, profession, and press freedom. Absence of reporting is not positive evidence.

Buying a database and outsourcing the policy

Data and software can retrieve and classify candidates. The organization still defines scope, thresholds, review, customer treatment, and accountability.

Tuning only to reduce alert volume

Noise reduction is useful only if relevant-event recall remains acceptable. Every material rule change needs regression testing.

Screening only at onboarding

Events and customer relationships change. Use periodic or event-driven rescreening according to risk, source updates, and applicable requirements.

Hiding the original source

Summaries accelerate triage but can omit caveats, dates, attribution, and later outcomes. Reviewers need traceable source evidence.

Auto-declining adverse-media matches

The result may concern another person or a non-material allegation. Apply a governed decision process and provide appropriate review or redress.

An operating checklist

Before launch or material change, confirm that:

  • the screened population, risk categories, event stages, and lookback are documented;
  • source inclusion considers authority, editorial controls, geography, language, and corrections;
  • customer identity data is normalized without erasing original scripts;
  • matching, event clustering, translation, and suppression rules are versioned;
  • reviewers can distinguish subject match, source credibility, event relevance, and policy outcome;
  • every alert preserves source, date, category, stage, rationale, and decision;
  • false positives are labeled by cause and feed a controlled tuning process;
  • representative recall and precision tests run before releases;
  • ongoing screening distinguishes new events from previously resolved reporting;
  • privacy, retention, access, redress, quality assurance, and change governance have owners.

Using Didit for adverse media screening

Didit’s AML Screening can be combined with conditional paths in the Workflow Orchestrator and customer activity controls through Transaction Monitoring. The published AML Screening price is $0.20, and Ongoing AML Monitoring is $0.07 per user per year.

Current module rates are listed on the pricing page. Screening evidence should feed the organization’s customer-risk, review, and monitoring policy; it does not replace source assessment, match resolution, investigation, or regulatory judgment.

Frequently asked questions

Is adverse media screening required by FATF?

FATF requires risk-based customer due diligence and ongoing controls, and its guidance recognizes internet, media, and other external sources as useful. It does not impose a universal requirement to purchase a database or run identical media searches on every customer.

Is adverse media the same as a criminal record?

No. Media can report allegations, investigations, charges, litigation, enforcement, convictions, acquittals, or corrections. Reviewers must preserve the event stage and assess source quality.

Does an adverse-media match mean a customer should be declined?

No. First establish the subject match, then assess relevance, credibility, severity, recency, and customer context under applicable policy and law.

Who should be screened?

The risk-based scope can include customers, beneficial owners, controllers, directors, representatives, counterparties, or other related parties. The organization should document why each population is included.

How often should screening run?

There is no universal frequency. Screening may occur at onboarding, periodic review, source update, or a material customer event, with greater depth or frequency where risk justifies it.

How can teams reduce false positives?

Improve identity data, narrow risk categories, distinguish event stages, cluster duplicate reporting, apply evidence-based suppression, and use reviewer outcomes to tune rules against a labeled test set.

Can artificial intelligence make the final decision?

It can help retrieve, translate, cluster, summarize, and prioritize content. A governed process should still preserve sources, expose uncertainty, and assign customer and regulatory decisions to accountable people.

Primary references

Adverse media screening works when it turns uncertain public information into traceable, proportionate risk evidence. Define the events that matter, resolve the right subject, preserve the source and stage, measure both missed events and review burden, and keep the final decision inside a governed customer-risk process.

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page