Adverse Media Screening: What It Should Find, What It Cannot, and How to Manage the Gaps
Building an adverse media programme that produces decisions a regulator will accept: search design, hit classification, materiality and ongoing monitoring.
Adverse media screening is one of the most widely implemented controls in AML/CFT programmes and one of the most poorly governed, producing volumes of results that overwhelm the analysts reviewing them without reliably identifying the risks that matter most.
Understanding what adverse media screening genuinely can and cannot find is the foundation for designing a programme that delivers real risk intelligence rather than a false sense of security grounded in process completion.
AML Expert
Get tailored guidance on your compliance obligations, SAR filing, or AML program review.
- What adverse media screening should find
- Financial crime involvement
- Corruption and political exposure
- Sanctions and regulatory exposure
- Reputational risk beyond financial crime
- What adverse media screening cannot find: the coverage gaps
Jurisdictions: UAE, UK, Singapore, Australia, Global
Sectors / audience: MLROs, compliance analysts, screening and onboarding teams
Published: 5th July 2026 | Last reviewed: 6th July 2026 | Reviewed by: Jyoti Maheshwari, CAMS
Editorial note: This article offers general practitioner guidance. Adverse media screening, record retention, sanctions screening and data protection obligations vary by jurisdiction; verify the specific requirements of each relevant regulator against primary sources before relying on any point in this article.
What Adverse Media Screening Should Find
A well-configured adverse media screening programme, drawing on a high-quality, broad-coverage data source, should be capable of identifying several categories of negative information directly relevant to the AML/CFT risk assessment of a customer or their associated parties.
Adverse media screening supports the broader customer due diligence obligations set out in FATF Recommendation 10 and the enhanced due diligence expectations for politically exposed persons in FATF Recommendation 12. However, FATF does not prescribe a specific methodology for adverse media screening.
Financial Crime Involvement
The most directly relevant category of adverse media for AML/CFT purposes is information indicating that the customer, their beneficial owners, or their close associates have been involved in financial crime, whether as suspects, accused persons, convicted individuals, or as subjects of civil proceedings related to financial crime.
This includes allegations and convictions related to money laundering, fraud, bribery, corruption, tax evasion, embezzlement, and related offences. It also includes regulatory findings and enforcement actions indicating conduct that falls short of a criminal standard but is material to the assessment of financial crime risk.
The quality of the intelligence in this category varies enormously depending on the jurisdiction and the nature of the coverage. In jurisdictions where court records and regulatory decisions are published and indexed, the screening tool will typically capture formal findings and proceedings with reasonable reliability. In jurisdictions where court proceedings are less transparent or where regulatory decisions are not routinely published, the tool may rely on media reporting of proceedings rather than on the primary source, introducing both coverage gaps and accuracy risks.
Corruption and Political Exposure
Adverse media is one of the primary sources of intelligence about corruption-related risk, particularly for individuals and entities in jurisdictions where formal corruption indices and PEP databases may not capture the full extent of politically exposed relationships. A customer who is not on a commercial PEP list but who is extensively reported in local media as having close business relationships with government officials, or as benefiting from government contracts awarded without competitive tender, presents a risk profile that adverse media screening is specifically designed to surface.
The challenge in this category is the subjectivity of the assessment. Adverse media reporting on political and business relationships is frequently contested, politically motivated, or based on incomplete information. The compliance officer reviewing a hit in this category must assess the credibility of the source, the specificity of the allegation, and the extent to which independent sources corroborate the information before concluding on the customer's risk profile.
Sanctions and Regulatory Exposure
Adverse media screening can surface information about sanctions designations, regulatory investigations, and supervisory actions that may not yet have been captured in structured data feeds. The lag between a regulatory or sanctions authority making a decision and its appearance in structured data products can be material, and adverse media screening provides a supplementary check that may identify such developments earlier. The compliance officer should understand, however, that adverse media is not a substitute for dedicated sanctions screening against structured, regularly updated lists; it is a supplementary intelligence source that may provide earlier warning of developing situations.
Reputational Risk Beyond Financial Crime
Adverse media screening also captures information that is reputational in character without being directly related to financial crime: involvement in significant litigation, environmental violations, labour disputes, and governance failures that may not constitute financial crime indicators in themselves but that are material to the overall assessment of the customer's risk profile. The compliance officer must make a judgement about the weight to give to this category of information, which should generally be lighter than the weight given to direct financial crime indicators but should not be ignored entirely, particularly where the reputational issue is in a sector or jurisdiction that the firm's risk appetite treats as elevated.
The most important conversation I have with compliance teams about adverse media is about what a clean result means. It does not mean the customer is clean. It means that nothing negative about them has been published in the sources and languages that the tool covers. That is a very different thing, and the distinction matters enormously for how the control is positioned within the overall CDD framework.
Jyoti Maheshwari | AML/CFT Practitioner, Published in ACAMS Today and AMLverse
Adverse Media Is Not Adverse Information
It is worth drawing a distinction that is often blurred in practice. Adverse media screening, also known as negative news screening or adverse news screening, searches published media: news reports, online articles and other openly available editorial content that a screening tool has indexed. Adverse information is a broader category. It includes everything adverse media covers, as well as sources that never reach a media feed.
A complete picture of a customer's risk usually draws on several of the following, only the first of which a media screening tool reliably reaches:
- Media reports: news coverage, investigative journalism and editorial content captured by adverse media tools.
- Court records: judgments, filings and litigation history held in court registries rather than reported in the press.
- Regulator notices: enforcement actions, public warnings and disciplinary findings published by supervisory authorities.
- Internal intelligence: the firm's own records of prior alerts, exits, suspicious activity reports and relationship history.
- Whistleblower and third-party reports: information raised internally or by counterparties that has not been published anywhere.
Treating adverse media as if it were the whole of adverse information is a common weakness in programme design. A clean media screening result tells the firm only that nothing negative has been published in the sources and languages the tool covers. It says nothing about court records that were never reported, regulatory action in a jurisdiction the tool does not index, or intelligence the firm already holds. A robust programme treats media screening as one input into a wider adverse-information assessment, rather than as the assessment itself.
How much weight a hit carries also depends on where it comes from. As a general hierarchy, official regulator notices, court judgments, sanctions-authority listings and company-registry records carry the greatest weight; reputable news outlets and established specialist industry publications come next; single-outlet or local media lower still; and blogs, social-media posts, anonymous claims and other uncorroborated material carry the least, useful mainly as a prompt for further enquiry. An item should be recorded as an allegation unless an official finding confirms it, and the source tier should be noted in the disposition record so that the basis for the weighting can be audited.
What Adverse Media Screening Cannot Find: The Coverage Gaps
Understanding the limitations of adverse media screening is as important as understanding its capabilities, and those limitations are more significant than most compliance programmes explicitly acknowledge.
Language and Geography Coverage
The single most significant structural limitation of most commercial adverse media screening tools is their language and geographic coverage. Many commercial data providers index a large volume of content in English and in the major European languages, and their coverage of content in Arabic, Mandarin, Hindi, Bahasa, Thai, Tagalog, and the many other languages in which significant volumes of relevant financial crime reporting exist is often materially weaker. The extent of this gap varies by provider and should be assessed for the specific tool in use rather than assumed. For regulated businesses operating across the GCC, Asia-Pacific, and South Asia, including the UAE, Saudi Arabia, Kuwait, Bahrain, Qatar, Oman, Singapore, Hong Kong, India, and Australia, the language coverage gap is a material programme risk that must be explicitly managed.
The practical implication is that a customer whose adverse media footprint exists primarily in Arabic, Mandarin, or Hindi language sources may return a clean result from a commercially standard screening tool, not because no adverse information exists, but because the tool does not cover the sources where it is published. The compliance officer working in a jurisdiction where the client population generates a significant volume of content in non-English languages should assess the language coverage of their screening tool explicitly, supplement it with manual searches in relevant languages for higher-risk customers, and document the limitations of the screening coverage as part of the programme's governance record.
Non-Indexed and Paywalled Content
Commercial adverse media tools index content that is publicly accessible and that the data provider has chosen to include in their coverage. They do not index content that is behind paywalls, hosted on platforms with restricted access, or removed from public access through legal action or platform policy. In jurisdictions where significant financial crime reporting appears in subscription media outlets, or where subjects of adverse media have successfully pursued removal of content through legal or regulatory channels, the tool's coverage will be systematically incomplete in ways that are difficult to detect from the screening output alone.
Pre-Publication Intelligence
Adverse media screening captures only what has been published. It does not capture regulatory or law enforcement intelligence that has not yet resulted in public action, internal corporate intelligence about a customer's conduct that has not been disclosed, or market intelligence about a customer's business relationships that exists within the compliance community but has not been formally published. The absence of adverse media results, therefore, does not assure the customer's position regarding active regulatory or law enforcement investigations that have not been made public.
Common Name Ambiguity
In jurisdictions where a small number of family names are extremely common, adverse media screening generates a fundamental problem of identity ambiguity. A screening query on a common name in a high-risk jurisdiction may return hundreds of results, many of which relate to different individuals with the same name. The compliance team must then invest significant time in determining which results relate to the specific customer being screened, with the risk that a genuinely material hit is dismissed as a name coincidence rather than correctly attributed.
In markets such as India, China, the Arab world, and parts of Africa and Southeast Asia, where name ambiguity is a pervasive challenge, the accuracy of adverse media screening is significantly lower than in markets where naming conventions make individual identification more reliable. The same names also appear across multiple scripts and transliteration systems, so a programme screening customers with Arabic, Chinese, Cyrillic, Hindi or other non-Latin names should test whether the tool covers the relevant script and its common transliteration variants, and should supplement it with manual checks where that coverage is weak.
Coverage Gaps That Every Compliance Officer Should Document
- Language coverage: identify specifically which languages the screening tool covers with high reliability and which it covers inadequately, and document the supplementary process for high-risk customers whose adverse media footprint may sit in underserved languages.
- Geographic coverage: assess the depth of the tool's coverage in each jurisdiction where the firm has significant client exposure, and identify markets where local-language supplementary searches should be conducted routinely.
- Source recency: understand how often the data provider updates its coverage and the typical lag between publication and indexing, as this affects the tool's ability to identify recent developments before they appear in structured data products.
- Content types: identify which content types are covered, including news media, regulatory publications, court records, and business registries, and which are not, so that the compliance team understands what the screening is and is not looking at.
- Removal and suppression: acknowledge that content that has been successfully removed from public access, whether through legal action, platform policy, or regulatory direction, will not appear in screening results, and that the absence of results provides no assurance about the existence of suppressed content.
- Structured versus unstructured coverage: understand the difference between the tool's structured data coverage (e.g., sanctions lists and PEP databases) and its unstructured adverse media coverage, and ensure that both dimensions are assessed and documented separately.
The Hit Disposition Process: Where the Value and the Risk Actually Sit
The hit disposition process, which determines how the compliance team responds to the results of adverse media screening, is the element of the programme that most directly determines whether the control delivers genuine risk intelligence or merely documents process completion. It is also the element most frequently left without adequate governance, relying instead on the individual judgement of the analyst reviewing each result.
A well-designed hit disposition process begins with a clear categorisation framework that allows the analyst to classify each hit consistently and to determine the appropriate response based on that classification. The following framework, adapted for use across different sectors and jurisdictions, provides a starting point for that design.
| Hit category | Examples | Materiality assessment | Recommended response |
|---|---|---|---|
| True positive: financial crime | Conviction or formal charge for money laundering, fraud, bribery, corruption or related offence | High: assess recency, severity, and whether the conviction relates to the customer directly or to an associated party | Immediate escalation to MLRO; assess impact on risk rating; consider whether STR/SAR filing or relationship exit is warranted |
| True positive: regulatory action | FCA enforcement notice, MAS reprimand, CBUAE supervisory action, AUSTRAC penalty | Medium to high: assess whether the action relates to conduct directly relevant to the firm's relationship with the customer | Escalate to MLRO; update risk rating; document the action and the firm's assessment of its relevance in the customer file |
| True positive: corruption or PEP adjacency | Reporting of business relationships with government officials, government contract awards, political donations | Medium: assess the specificity and credibility of the reporting, and whether the customer is already identified as a PEP or PEP-adjacent | Escalate if the customer is not already rated high risk; consider whether EDD is warranted; document the assessment |
| True positive: reputational | Significant litigation, environmental violations, governance failures, labour disputes | Low to medium: assess relevance to financial crime risk and to the firm's specific risk appetite | Document the hit and the materiality assessment; update the customer file; consider whether a risk rating review is warranted |
| False positive: name coincidence | Hit relates to a different individual or entity with the same or similar name | None: confirm identity mismatch through a specific identifying detail such as date of birth, nationality or registered address | Document the reason for dismissal with the specific identifying information that confirms the mismatch; retain the record in the customer file |
| False positive: stale information | Hit relates to an event fully resolved, acquitted or otherwise addressed that does not reflect the customer's current risk profile | Low to none: assess recency and whether the resolution is credible and verifiable | Document the stale-information assessment with reference to the resolution; retain the record; consider periodic refresh to assess whether the situation has changed |
The documentation of the disposition decision is as important as the decision itself. The analyst reviewing an adverse media hit must record, in the customer file, not only the conclusion reached but the specific reasoning that supports it. A disposition record that states only "reviewed and dismissed as false positive" provides no evidence that a genuine assessment was made, and no basis for a supervisor to evaluate the quality of the decision. A disposition record that states "hit relates to a conviction in 2019 for an individual named [X] born in [country] who is confirmed to be a different person from our customer based on the date of birth discrepancy" demonstrates the quality of the analytical work and provides the examiner with a credible basis for assessing the decision.
Escalation Matrix: Quick Reference
The framework above sets out the full disposition logic. The table below condenses it into a quick escalation reference for analysts. Where the matrix points towards a suspicious transaction report, the decision to file and its timing turn on the suspicion or knowledge threshold set by the relevant jurisdiction and on the MLRO's documented assessment, not on the adverse media hit alone. Analysts should also respect the tipping-off and confidentiality restrictions that apply once a report or internal escalation is under consideration, and should not disclose that a report may be made.
| Finding | Recommended action |
|---|---|
| Unverified single allegation | Record and monitor; refresh at the next review |
| Multiple credible reports | Escalate to the MLRO for assessment |
| Regulatory action | Escalate to the MLRO; update the risk rating |
| Criminal charge | Apply EDD and refer for MLRO review |
| Conviction | Immediate escalation; consider STR/SAR and relationship exit |
Ongoing Monitoring Versus Point-in-Time Screening
The distinction between point-in-time adverse media screening, conducted at onboarding or during scheduled periodic reviews, and ongoing adverse media monitoring, conducted continuously throughout the customer relationship, is one that many compliance programmes handle inadequately.
Point-in-time screening captures the customer's adverse media profile at a specific point in time. It does not assure developments that occur between screening dates. A customer who is clean at onboarding may become the subject of significant adverse media coverage within weeks of joining, and if the programme relies solely on periodic screening at fixed intervals, that development may not be captured until the next scheduled review, which could be twelve or twenty-four months later.
Ongoing monitoring, also called ongoing screening, negative news monitoring or adverse news monitoring, addresses this gap by generating alerts when new adverse media relating to a customer appears in the indexed sources. Most commercial screening platforms offer this capability, and for higher-risk relationships, its activation is increasingly treated as a supervisory expectation for a credible adverse media programme. Maintaining ongoing awareness of material adverse developments affecting higher-risk customers, rather than relying solely on periodic screening exercises, is consistent with the ongoing customer due diligence expectations that supervisors such as the CBUAE, MAS, the FCA and AUSTRAC apply under their AML/CFT regimes.
The governance of the ongoing monitoring alert stream requires the same discipline as the governance of the initial screening results. Each alert should be reviewed by an analyst with sufficient knowledge of the customer to assess the materiality of the new information, and the disposition of each alert should be documented with the same specificity required for initial screening results. A common failure in ongoing monitoring programmes is treating the monitoring alert as a lower-priority task than the initial screening review, resulting in a backlog of unreviewed alerts that creates both a governance gap and regulatory exposure.
The frequency and intensity of ongoing monitoring should be calibrated to the customer's risk rating. High-risk customers, including PEPs, customers in higher-risk sectors, and customers whose initial screening generated material hits that were assessed as manageable, should receive the most frequent and most granular monitoring. Low-risk customers in lower-risk sectors and jurisdictions may be monitored less frequently, provided that the programme documents the rationale for that calibration and that a trigger mechanism exists to escalate monitoring intensity if the risk profile changes.
Ongoing monitoring is where the gap between a technically compliant adverse media programme and a genuinely effective one is most visible. Running a search at onboarding and again at the annual review is the minimum. What the regulator actually wants to know is whether you would have found out if something significant happened to this customer in the eleven months between those two dates. For most programmes, the honest answer is no.
Pathik Shah | Founder, NIYEAHMA Consultants LLP
The Quality Audit: What Regulators Are Actually Examining
The quality audit of an adverse media screening programme is the assessment of whether the programme delivers genuine risk intelligence, rather than whether the process of conducting screens has been completed. The distinction between these two things is the lens through which regulators across the major supervisory jurisdictions are increasingly examining adverse media controls, and it represents a materially higher standard than the documentary compliance check that many programmes are designed to satisfy.
In a quality audit of adverse media screening, the examiner will not merely verify that screens were conducted and that results were recorded. They will assess a sample of hit disposition decisions to determine whether the analytical quality of those decisions was adequate. They will look for evidence that true positives were escalated appropriately and that the escalation decision was documented with sufficient specificity. They will assess whether false-positive dismissals were supported by specific identifying information rather than a bare conclusion. And they will assess whether the ongoing monitoring programme was active and whether alert dispositions were timely and well-reasoned.
The examiner will also look for evidence of systematic weaknesses in the disposition process. A pattern of dismissals in which the same analyst has applied a consistently lower standard of analysis than their colleagues, or a pattern of dismissals that consistently favours clients in a particular business line or sector, is the kind of systemic issue that a quality audit is specifically designed to surface. The compliance officer should conduct periodic internal quality audits of the adverse media programme through the same lens to identify and address systemic weaknesses before an external examiner does.
The documentation standard that a quality audit expects is specific and demanding. For each adverse media hit, whether at onboarding, during periodic review, or from ongoing monitoring, the record in the customer file should include the date of the screen, the sources searched, the results generated, and the disposition decision for each result, along with the specific reasoning that supports it. Where a hit has been escalated to the MLRO, the escalation record should document what was escalated, when, and what decision the MLRO reached. Where a hit has triggered a change in risk rating, the new rating and the basis for the change should be recorded.
A quality audit also covers the screening tool itself, and the firm should be able to demonstrate that it governs both the vendor and the output. That means conducting due diligence on the provider, maintaining an inventory of the sources and lists the tool draws on, testing language and jurisdiction coverage against the firm's client base, confirming how frequently the underlying data is refreshed, sampling dispositions for quality, controlling and documenting changes to rules or matching logic, testing for false negatives as well as false positives, and revalidating the configuration on a defined cycle rather than leaving it untouched after implementation.
Not sure your programme would survive an examination? Have an AML Guild specialist pressure-test it before your regulator does, and fix the gaps while there is still time. Book a session at amlguild.com.
Configuring the Screening Tool: Practical Governance Decisions
The configuration decisions made when implementing an adverse media screening tool, sometimes called AML screening software or media screening software, have a significant impact on the quality and volume of results the tool generates, and on the resources required to review them. These decisions are frequently made at implementation and then forgotten, even as the business evolves and the client population changes.
Search Term Design
The search terms used in adverse media screening should be designed to capture the full range of identifiers associated with the customer and their connected parties, including formal name variations, trading names, former names, and, where available, unique identifiers such as registration numbers or national identification numbers. A search that uses only the customer's primary name will miss results associated with aliases, maiden names, or corporate name changes. The search term design should be reviewed periodically to ensure that it reflects any changes in the customer's identity or corporate structure.
Category and Keyword Configuration
Most commercial adverse media tools allow the compliance officer to configure the categories of adverse media that the search prioritises. The configuration should reflect the firm's specific risk profile and risk appetite: a bank with significant exposure to trade finance should configure the tool to place greater weight on trade-based financial crime categories, while a private bank with a high-net-worth client base should place greater weight on corruption, PEP adjacency, and wealth-origin categories. A default configuration that has not been adapted to the firm's specific risk profile is likely to generate either excessive noise or material coverage gaps, depending on how the default categories align with the firm's actual risk exposure.
Sensitivity Thresholds
The sensitivity threshold determines the minimum relevance score at which a result is presented to the analyst for review. A high sensitivity threshold reduces the volume of results but increases the risk of missing genuinely material hits. A low sensitivity threshold ensures comprehensive coverage but generates a volume of noise that may overwhelm the review process and, paradoxically, increase the risk that material hits are overlooked in a backlog of low-relevance results. The appropriate threshold is a function of the firm's client risk profile, the review team's capacity, and the consequences of missing a material hit in the specific regulatory environment. It should be documented, justified, and reviewed as part of the periodic model governance cycle.
Sector and Jurisdiction Dimensions
The specific application of adverse media screening differs materially across sectors and jurisdictions, and the compliance officer's programme design should reflect those differences.
Banks and Financial Institutions
In banks, adverse media screening is typically integrated into the broader CDD and transaction monitoring framework, and governance expectations are well established. The principal challenge in this sector is managing the volume of results across a large and diverse client population, particularly in multi-jurisdictional banks operating across the UAE, Singapore, Hong Kong, the UK, Australia, India, and the GCC. Quality assurance of the disposition process is the most significant governance challenge, and it requires a structured sampling methodology, clear quality standards, and regular feedback to analysts on the quality of their assessments.
Fintechs and VASPs
In fintechs and VASPs, adverse media screening is particularly important given the higher proportion of non-face-to-face onboarding, the global character of the customer base, and the elevated financial crime risk associated with digital asset products. The language coverage gap is especially material in this sector, given the global distribution of the customer population and the significant volume of relevant content in non-English languages. VASPs operating in Singapore, Hong Kong, and the UAE should ensure that their screening tool covers the languages most prevalent among their customer populations and supplement automated screening with manual searches in relevant languages for higher-risk customers.
DNFBPs
In DNFBPs, adverse media screening is one of the controls most frequently absent or inadequately implemented. Law firms, accountancy practices, real estate businesses, and trust and company service providers across the GCC, the UK, Australia, and India may conduct limited internet searches at onboarding without a systematic approach to source coverage, hit classification, or ongoing monitoring. Supervisors examining DNFBP compliance across these jurisdictions are increasingly finding that the adverse media screening programme consists of a Google search whose results are not recorded in the customer file, and whose disposition has not been assessed against any documented standard. The gap between this approach and the quality of adverse media programme that regulators expect is substantial, and the compliance officer or designated officer in a DNFBP should regard closing this gap as a priority remediation item.
When I work with DNFBPs on their adverse media programmes, the first question I ask is: show me the disposition record for the last ten clients you onboarded. In most cases, there is no disposition record. There may be a note saying "Google search conducted, no results," but there is no record of what was searched, what sources were checked, or why a result that appeared in the search was determined not to be material. That is not an adverse media programme. That is a process that has been substituted for one.
Dipali Vora | AML/CFT Practitioner, Associate Member, ICSI
Managing the Gaps: Supplementary Measures That Strengthen the Programme
Given the structural limitations of automated adverse media screening, a robust adverse media programme requires supplementary measures to address the coverage gaps identified in its governance documentation.
Manual searches in local languages are the most practical supplementary measure for the language coverage gap. For higher-risk customers, particularly those based in jurisdictions where the screening tool's language coverage is demonstrably weak, a manual search conducted by an analyst with native or near-native language capability adds a layer of coverage that automated tools cannot replicate. The results of manual searches should be documented in the customer file with the same specificity as automated screening results.
Open-source intelligence techniques, when applied by analysts with appropriate training, extend the coverage of adverse media beyond what commercial tools index. Court record databases, company registry filings, regulatory publication archives, and sector-specific information repositories can all provide relevant intelligence that does not appear in commercial adverse media products. The use of these sources should be governed by a documented procedure that specifies when they are used, how results are assessed, and how they are recorded.
Information sharing within the compliance community, where permitted by applicable data protection and confidentiality frameworks, can provide intelligence about customers and associated parties that is not available from any public source. Where the law permits, firms may also take part in approved public-private or financial-institution-to-financial-institution information-sharing frameworks. In Singapore, for example, COSMIC allows participating financial institutions to share customer information for AML/CFT purposes. Financial intelligence units, such as the STRO in Singapore and the JFIU in Hong Kong, primarily receive, analyse and disseminate suspicious transaction reports and financial intelligence through prescribed channels, and should not be treated as general industry intelligence-sharing forums. The compliance officer should understand which mechanisms are available in each jurisdiction and, where appropriate, how they may be accessed.
The governance of these supplementary measures should be documented in the programme design, specifying when each measure is applied, who is responsible for its application, and how the results are recorded. A supplementary measure that is applied inconsistently, or whose application is not documented, does not strengthen the programme. It creates an additional gap in the governance record.
Adverse Media and Data Protection
Adverse media screening processes personal data, often personal data relating to alleged criminal conduct, enforcement actions or other adverse information, and it does so about people who are not the firm's customers as well as those who are. That brings the programme within the scope of data protection law, and examiners increasingly ask how the firm reconciles its AML obligations with its privacy obligations.
The applicable regime depends on where the firm operates and whose data it processes. Firms in the European Union fall under the GDPR; firms handling data of individuals in the United Kingdom fall under the UK GDPR; firms in Singapore fall under the Personal Data Protection Act (PDPA); and firms in the United Arab Emirates fall under the Personal Data Protection Law. The detail differs, but a common set of principles runs through all of them.
Several principles are particularly relevant to an adverse media programme:
- Proportionality: the screening carried out, and the data retained, should be proportionate to the money laundering and terrorist financing risk the firm is managing, rather than a blanket capture of everything available.
- Purpose limitation: adverse media data collected for AML/CFT purposes should be used for those purposes, and not repurposed for unrelated commercial decisions about the customer.
- Retention: disposition records and the underlying data should be kept for as long as the AML framework requires and the firm's risk assessment justifies, and then disposed of, rather than retained indefinitely by default.
- Lawful basis and sensitive data: the firm should identify and record the lawful basis on which it processes adverse media data, and recognise that information about alleged or proven criminal conduct, enforcement action or sanctions exposure may attract special handling requirements depending on the applicable data-protection regime.
- Accuracy and rectification: because adverse media often report allegations rather than findings, the firm should record the status of each item, keep it current, and maintain a route to correct or annotate a record where the underlying position changes or the customer challenges it.
- Security and cross-border transfer: access to adverse media records should be limited to those who need it for AML/CFT purposes, and any cross-border transfer of that data should be checked against the applicable regime's transfer rules.
- Impact assessment and records: where the programme involves large-scale or systematic processing of this data, a data protection impact assessment may be required, and the processing should be recorded in the firm's record of processing activities.
These obligations sit alongside, rather than override, the firm's AML/CFT duties. Where a genuine tension arises, for example, between a request to erase data and a legal duty to retain records, the firm should resolve it by reference to the specific legal bases available under both regimes and, where the position is unclear, with legal advice. The programme documentation should record how the firm has reconciled the two.
Signs That the Adverse Media Programme Is Not Delivering Genuine Risk Intelligence
- Hit disposition records consist of bare conclusions without specific reasoning, making it impossible to assess the quality of the analytical work or to defend the decision in a regulatory examination.
- The proportion of hits dismissed as false positives consistently exceeds ninety per cent, suggesting either that the tool is misconfigured and generating excessive noise or that analysts are applying an insufficiently demanding standard in their materiality assessments.
- Ongoing monitoring alerts are reviewed with a significant backlog, meaning that material developments in a customer's risk profile may not be acted upon in a timely way.
- The programme applies the same screening intensity to all customers, regardless of their risk rating, and fails to allocate review resources to the relationships where the risk of a material adverse media hit is highest.
- The screening tool has not been reconfigured since implementation, despite material changes in the firm's client population, geographic footprint, or risk profile.
- Manual searches in locally relevant languages are not conducted for higher-risk customers in jurisdictions where the automated tool's language coverage is demonstrably weak.
- The programme's coverage limitations are not documented, meaning that the compliance officer cannot demonstrate awareness of what the screening does not cover and has no supplementary process to address those gaps.
Practitioner Checklist: Building a Robust Adverse Media Screening Programme
- Document the screening tool's coverage limitations explicitly, including language gaps, geographic coverage weaknesses, source exclusions, and content-type restrictions.
- Design the search-term configuration to capture the full range of identifiers for each customer and their connected parties, including name variations, aliases, and corporate structure changes.
- Configure the tool's category and keyword settings to reflect the firm's specific risk profile rather than relying on a default configuration.
- Establish a hit classification framework that allows analysts to categorise results consistently and to determine the appropriate response based on the category and materiality of each hit.
- Document every hit disposition decision with specific reasoning, not only a conclusion: the record must demonstrate the quality of the analytical work, not merely its completion.
- Apply ongoing monitoring in accordance with the firm's risk-based approach, with a particular focus on higher-risk customers, and govern the alert review process with the same rigour as the initial screening review.
- Establish a maximum turnaround time for reviewing ongoing monitoring alerts, and monitor compliance with that standard through periodic management information reporting.
- Implement a supplementary manual search process in relevant local languages for higher-risk customers in jurisdictions where the automated tool's language coverage is weak.
- Conduct a periodic quality audit of hit disposition decisions, using a structured sampling methodology, and provide feedback to analysts on the quality of their assessments.
- Review and reconfigure the screening tool periodically to ensure it remains appropriate to the current client population, geographic footprint, and the business's risk profile.
- Report adverse media programme performance metrics to the compliance committee and the board, including disposition volumes, the proportion of true and false positives, alert backlogs, and the findings of the most recent quality audit.
- Document the rationale for sensitivity threshold settings and review them as part of the periodic governance cycle, ensuring that the chosen threshold balances coverage with the review team's capacity.
Frequently Asked Questions
Everything you need to know about adverse media screening and how AML Guild supports your business.
Adverse media on individuals connected to the customer, whether family members, business partners, or close associates, is relevant to the customer's risk assessment because it may indicate the customer's own exposure to financial crime risk through those relationships. The materiality of the hit depends on the nature of the relationship between the customer and the subject of the adverse media, the severity of the information itself, and the extent to which the customer's business relationship with the firm may expose the firm to that risk indirectly. The assessment should be documented with specific reference to the relationship between the customer and the connected party, and the compliance officer should consider whether the hit warrants a review of the customer's EDD requirements, a risk rating adjustment, or escalation to the MLRO.
The regulatory expectations differ across jurisdictions, but common practice in most active AML/CFT supervisory environments is that many regulated firms conduct adverse media screening across their customer base, with the intensity and frequency of screening calibrated to the customer's risk rating. The precise requirement should be assessed against the firm's regulatory obligations and risk-based approach, since not every jurisdiction explicitly mandates adverse media screening for each customer. The compliance officer should assess the specific expectations of each relevant regulator and ensure that the programme meets the applicable standard.
Hit disposition records should be retained for at least the duration of the customer relationship and for the post-relationship retention period prescribed by the relevant regulatory framework. In most jurisdictions, this means a minimum of five years after the end of the relationship, consistent with the FATF Recommendation 11 standard that records be retained for at least five years, though some jurisdictions require longer retention periods. The retention policy should apply equally to records of true positive hits, false positive dismissals, and ongoing monitoring alert dispositions, as all of these may be relevant to a regulatory examination or enforcement investigation that occurs after the relationship has ended.
A customer who challenges a compliance decision that was informed by adverse media should be handled carefully. The tipping-off prohibition may limit what can be disclosed about the specific information that informed the decision. In cases where a decision to exit or restrict a relationship was based on adverse media, the firm should seek legal advice before disclosing the basis of the decision where AML/CFT obligations, confidentiality obligations or tipping-off restrictions may apply. The customer's challenge should be reviewed by the MLRO and, where appropriate, by legal counsel, and the firm's response should be documented carefully regardless of the outcome.
Adverse media information that appears to be inaccurate or outdated should not simply be dismissed. The compliance officer should assess the credibility and recency of the source, seek corroboration from independent sources where possible, and consider whether the information, even if outdated, is relevant to the current risk assessment. Where the information relates to a resolved matter, the nature of the resolution, whether through acquittal, withdrawal of charges, or settlement, should be assessed as part of the overall risk picture. A resolution does not necessarily eliminate the relevance of the underlying information to the firm's risk assessment, particularly where the nature of the original allegation is material.
Work With Pathik Shah Through AML Guild
Pathik Shah and the AML Guild network provide on-demand, CAMS-certified AML/CFT support for regulated businesses, from building and remediating compliance programmes to preparing for regulatory examination and selecting the right technology.