Free guide: How to use AI in compliance
Adverse media screening AML guide 2026 — stylized magnifying glass and newspaper icon for negative news screening in compliance programs

Adverse media screening is the process of checking customers against negative news sources, reports of fraud, money laundering, corruption, sanctions breaches or organised crime, to surface risk that standard identity checks miss. Regulators expect it as part of a risk-based AML programme, performed at onboarding and monitored continuously thereafter.

Table of contents
  • Adverse media screening checks a customer or business against public news, regulatory, court and watchlist sources for links to financial crime, fraud, corruption or sanctions exposure.
  • It is forward-looking: it surfaces risk signals before a regulator formally designates a person, where sanctions and politically exposed person screening react to designations already made.
  • No single statute names it verbatim, but FATF Recommendations 10 and 12, the FFIEC examination manual and the incoming EU rulebook all treat negative news checks as part of risk-based due diligence.
  • Facctum's AML false positive report puts screening false positives across AML generally at 85 to 95 percent, and LexisNexis Risk Solutions reports institutions running at 95 percent or more. Neither figure is adverse-media-specific, and the drivers are name-only matching, allegation-level flagging and duplicated events across vendors.
  • TD Bank pleaded guilty on 10 October 2024 and paid roughly 3.09 billion dollars across four regulators after weak monitoring let three networks move more than 670 million dollars.
  • The buyer question incumbents skip is architectural: where does your customers' verified data live, and is it a breach honeypot?

Adverse media screening is the process of checking a customer or business against public news, regulatory and court sources for links to financial crime, fraud, corruption or sanctions exposure. Also called negative news screening, it is a core part of know your customer and anti-money laundering due diligence, run at onboarding and through ongoing monitoring to surface risk early.

Diagram of adverse media screening checking a resolved customer identity against news, regulatory, court and watchlist sources, with a forward-looking risk-signal arrow ahead of the sanctions and PEP designation lists.
A resolved identity screened against open sources surfaces risk early, ahead of the sanctions and PEP lists that only react to a designation already made.

TL;DR

Adverse media screening, also called negative news screening, checks a customer against public news, regulatory, court and watchlist sources for links to financial crime, fraud, corruption or sanctions exposure. It is a forward-looking part of know your customer and anti-money laundering due diligence: it flags risk before a regulator designates it, where sanctions and politically exposed person checks react to lists already published. Every vendor defines the control the same way and competes on source volume, which is precisely what drives the false positive rates that Facctum puts at 85 to 95 percent across AML screening. The harder questions are architectural: how well does the tool resolve an entity, and where does your customers' verified data end up sitting.

What is adverse media screening?

This guide is for compliance and onboarding teams at regulated fintech and crypto firms who already run screening and want to pressure-test how well it resolves entities and where it stores customer data. Adverse media screening is the process of checking a customer or business against public news, regulatory and court sources for links to financial crime, fraud, corruption or sanctions exposure. The synonym you will see in policy documents is negative news screening, and the two terms mean the same thing. It is a core control inside know your customer (KYC) and anti-money laundering (AML) customer due diligence, run both at onboarding and through ongoing monitoring so that a risk signal can be caught and reviewed.

What makes it distinct from a sanctions or watchlist check is timing. An adverse media check is forward-looking: it scans open sources for reporting that a person or company is linked to wrongdoing, often months or years before any official body formally designates them. The Wolfsberg Group, an association of major banks that publishes financial crime guidance, defines negative news as information in the public domain that a financial institution would consider relevant to managing financial crime risk, and stresses that it follows a risk-based approach rather than a zero-tolerance one. The short version: it is a judgement-based early warning, not a binding legal block.

Why does adverse media screening matter in AML?

No single statute names adverse media verbatim, which trips up a lot of compliance teams. The obligation is indirect but real. The Financial Action Task Force (FATF), the global standard-setter for anti-money laundering, requires customer due diligence under Recommendation 10 and enhanced due diligence for politically exposed persons under Recommendation 12, including source-of-wealth checks and enhanced ongoing monitoring. Negative news screening is how firms operationalise those duties in practice; FATF does not use the phrase itself.

United States examiners expect the same. The FFIEC BSA/AML Examination Manual treats negative media search programmes as a risk-based factor in due diligence and ongoing monitoring, reviewed more closely for higher-risk customers, which is an examiner expectation rather than a blanket statutory mandate. In Europe the direction is firmer. The EU Anti-Money Laundering Regulation, Regulation (EU) 2024/1624, was published in the Official Journal on 19 June 2024, entered into force on 9 July 2024 and applies directly across member states from 10 July 2027, creating a single rulebook for due diligence, beneficial ownership and ongoing monitoring enforced alongside the new Anti-Money Laundering Authority.

The cost of missing negative signals is not abstract. On 10 October 2024, TD Bank pleaded guilty to Bank Secrecy Act and money-laundering conspiracy violations and agreed to pay 1.8 billion dollars to the Department of Justice, the largest Bank Secrecy Act penalty in United States history and roughly 3.09 billion dollars in total once the Financial Crimes Enforcement Network, the Office of the Comptroller of the Currency and the Federal Reserve are added. The Department of Justice found that 92 percent of the bank's transaction volume, about 18.3 trillion dollars, went unmonitored from January 2018 to April 2024, and that the failures let three money-laundering networks move more than 670 million dollars through accounts. Worth being precise about what that case does and does not prove: TD Bank was charged over transaction monitoring, not over adverse media screening specifically, and no regulator has framed it as an adverse media failure. It belongs here because it is the clearest recent measure of what a screening programme that runs but does not surface risk costs once it reaches an enforcement file. For the broader programme context, see our AML transaction monitoring guide.

What sources are used in adverse media screening?

The source set is deliberately broad, because financial crime surfaces in different places before it reaches an official list. A practical negative news programme draws on:

  • Traditional and digital news media, from wire services to local outlets.
  • Regulatory and enforcement publications, such as Securities and Exchange Commission (SEC), Financial Conduct Authority (FCA) and Office of Foreign Assets Control (OFAC) press releases.
  • Court filings and litigation records.
  • Sanctions and watchlist data, used as a cross-reference rather than the primary signal.
  • Investigative leaks and datasets, of the kind published by the International Consortium of Investigative Journalists.
  • Vetted social media and corporate-registry information.

Volume is where the tier-one vendors compete. LSEG's World-Check risk-intelligence database publishes coverage of 240 countries and territories, over 4 million records and more than 700 sanction, watch, regulatory and law-enforcement lists, curated by 470-plus research analysts across 65-plus languages. That breadth is useful, but it is also the problem: more sources means more raw matches to disposition, and most of them are noise. The skill is not in collecting sources, it is in resolving which match actually concerns your customer.

What are the categories of adverse media?

Mature programmes do not treat all negative news the same way; they bucket it. The category typology most teams use, drawn from FATF risk topics and research bodies such as RUSI, sorts hits into financial crime (money laundering, fraud, tax evasion), corruption and bribery, organised crime, terrorism financing, sanctions and regulatory breaches, and a residual reputational category covering environmental harm, trafficking and similar conduct. Tagging a hit by category lets a risk-based programme weight a money-laundering allegation differently from an unrelated reputational story.

The second axis is status, sometimes called the allegation gradient. Vendors tag whether a subject is merely accused, under investigation, formally charged or convicted. This matters because screening that treats a single unproven allegation the same as a conviction over-alerts badly. A risk-based approach reads both the category and the status before deciding whether a hit warrants escalation, enhanced due diligence or no action at all. Our know your customer software and anti-money laundering software pages show how those signals feed an onboarding decision.

How does adverse media screening work?

The process is five steps, and the false positive problem lives in step three. First, entity input: the screening engine takes the verified identity from the KYC or know your business (KYB) profile, including name, date of birth, nationality and role. Second, source matching: the engine searches the source set for references to that name and its variants across languages and transliterations. Third, entity resolution: it tests whether a matched article actually concerns your customer rather than a namesake, by comparing date of birth, nationality, role and known associates.

Fourth, classification: natural language processing reads each surviving match, assigns a risk category and status, and scores it. Fifth, adjudication: an analyst reviews the scored hits, records a decision and reasoning, and keeps an audit trail an examiner can later inspect. Entity resolution is where the whole control is won or lost. Match on name alone and a common surname returns hundreds of irrelevant hits; resolve against a full identity and the queue shrinks to what a human can actually review. The negative news screening process is only as good as the identity it screens against.

The adverse media screening workflow: six steps

A defensible adverse media screening workflow has six steps, each producing a record an examiner can inspect. The first sentence of each step is the control; the rest is how to run it.

  1. Define your risk taxonomy. Decide which categories count (financial crime, corruption, sanctions exposure, terrorism financing, organised crime, fraud, regulatory action) and which allegation statuses (accused, under investigation, charged, convicted) trigger a review rather than a note on file.
  2. Select and weight your sources. Mainstream and local news, regulatory and enforcement publications, court and insolvency records and vetted investigative datasets, weighted by reliability, with language and jurisdiction coverage chosen from your customer book rather than from a vendor’s headline count.
  3. Match and score. Resolve the customer as an entity first, name plus date of birth, nationality, role and known associates, then search variants and transliterations and score each hit by category, status, recency and source reliability.
  4. Review and disposition. An analyst reviews the scored hits, discards namesakes with a recorded reason, and decides between no action, enhanced due diligence, escalation to the MLRO, or exit.
  5. Record the decision. Store the hit, the evidence, the reasoning and the reviewer with a timestamp; this file is what FFIEC examiners and the EU rulebook ask to see.
  6. Monitor continuously. Re-screen on new reporting and on customer-data changes rather than on a calendar batch, and tier the cadence by risk: near-continuous for PEPs and high-risk sectors, periodic for the rest.

Zyphe runs steps three to six inside its PEP and adverse media screening software: fuzzy matching against a resolved identity, a 0 to 100 risk score banded Low, Medium, High and Critical, and a count of contributing sources on every match so the reviewer can see why it fired.

How does it differ from sanctions and PEP screening?

These three controls are complementary, not interchangeable, and conflating them is a common audit finding. The cleanest way to see the difference is side by side.

DimensionAdverse media screeningSanctions screeningPEP screening
Data sourcePublic news, court and regulatory reportingOfficial government lists (OFAC, EU and UN)Designated lists of politically exposed persons
Legal obligation on a hitRisk-based judgement; review and decideBinding legal block; freeze and reportMandatory enhanced due diligence
Time orientationForward-looking; surfaces undesignated riskRetrospective; reacts to a designation madeRetrospective; reacts to a status assigned
Decision typeAnalyst adjudication with reasoningRule-based, near zero discretionSenior-management approval, ongoing monitoring
Re-screening triggerNew reporting or customer-data changeList updateList update or change in office held

The plain-English contrast: a sanctions hit is a binding legal obligation to act, while a negative news hit is a judgement call you have to document. Sanctions and politically exposed person checks are retrospective because they react to a list that someone has already published. The negative news check is forward-looking because it tries to catch the signal before it ever reaches that list. You need all three, and you need to keep them straight. For the sanctions side specifically, our anti-money laundering software page covers list management and watchlist screening.

Why does centralised KYC inflate false positives?

Screening false positive rates commonly run at 85 to 95 percent. That band comes from Facctum's AML false positive report, which also finds compliance teams spending up to 90 percent of their time on alerts that lead to no action; LexisNexis Risk Solutions, citing KPMG, describes institutions struggling under rates of 95 percent or more. Two caveats worth stating plainly, because most vendor pages skip them. Both figures describe AML screening as a whole rather than adverse media on its own, and no regulator publishes an authoritative number, so treat the range as a vendor-reported benchmark rather than an official statistic. The order of magnitude is not disputed, and the mechanism is worth understanding, because it is architectural rather than incidental.

Comparison panel contrasting a name-first centralised screening model that re-raises duplicated hits with a resolved reusable identity that screens against context and keeps an audit trail.
A name-first centralised screen re-raises duplicated hits; a resolved, reusable identity screens against context and keeps an audit-ready trail.

A centralised, name-first model over-alerts for structural reasons. There is no shared entity graph, so the same adverse event gets re-discovered and re-flagged across vendors and across re-screens. There is no reusable resolved identity, so every screen starts from a name string instead of a confirmed person, and a name string matches everyone who shares it. Each periodic batch re-screens the whole book from scratch, re-raising hits an analyst already cleared last quarter. The fix is not more sources, which only adds noise; it is a resolved, reusable identity that carries its own context so the engine knows who it is screening before it starts matching. That reframes the buying decision away from source volume, which is where every incumbent competes.

Reducing the adverse media false positive rate

Why false positives happen

Most false positives are structural rather than accidental. The engine matches on a name string, so a common surname returns everyone who shares it. Transliteration produces several spellings of the same person and several people under one spelling. Old allegations resurface on every re-screen. The same event, reported by five outlets, arrives as five hits. And without a status filter, a dismissed investigation is scored like a conviction.

Entity resolution and name matching

The single largest reduction comes from resolving the entity before matching: comparing date of birth, nationality, role and known associates so that an article about a namesake never reaches an analyst. Fuzzy matching should be tuned per script and per name frequency rather than globally, and every surviving match should carry a count of independent sources, because one report repeated is not the same evidence as five reports confirmed.

Relevance and recency filtering

Filter by the categories in your taxonomy so that a customer’s appearance in a sports report is never scored. Apply the allegation gradient so that accused, investigated, charged and convicted carry different weights. Decay recency so that a settled matter from a decade ago is noted rather than escalated, and deduplicate the same underlying event across outlets before it reaches the queue.

Benchmark: what a good false positive rate looks like

No regulator publishes a benchmark, and a vendor quoting one without describing its population is selling. Facctum’s report puts AML screening false positives at 85 to 95 percent industry-wide, but that figure is not adverse-media-specific. The useful measures are your own: hits per screened customer, the share cleared as namesakes, and time to disposition, tracked month by month. A falling rate with stable true-positive capture is the goal; a falling rate achieved by raising thresholds is a finding waiting to happen.

Can you screen without storing PII centrally?

This is the architectural question the standard vendor model never raises, and it is the one that matters most after a breach. The conventional setup pools every customer's verified identity into a central store, then screens against it. That store is a standing target. It is also unnecessary. Screening needs to confirm whether a resolved identity matches a negative news record; it does not require a central honeypot of raw personal data to do so.

Zyphe's model runs screening against a reusable, resolved identity, a KYC passport the customer verifies once and re-presents elsewhere, rather than re-collecting and re-warehousing personal data at every firm. Verified data is sharded across a decentralised network of more than 60,000 nodes under a 29-of-100 threshold scheme, so no single node holds a complete record and there is no central honeypot to breach. The customer holds the key; there is no master key. A firm can confirm a match or non-match against a resolved entity and keep an exportable, audit-ready trail without becoming the place personal data accumulates. Zyphe states this approach delivers materially lower compliance cost, a fraction of the cost of a conventional stack, though that is a Zyphe figure rather than an independently audited one. The same logic that lowers breach exposure also lowers false positives, because screening runs against a resolved entity instead of a bare name. See how Zyphe works for the architecture in full, and our decentralised KYC explainer for the underlying model.

How often should you re-screen for adverse media?

Negative news screening is not a one-time onboarding gate; ongoing monitoring is an explicit AML expectation, not an optional extra. The cadence should follow risk tier. High-risk customers, such as politically exposed persons or those in high-risk sectors, warrant continuous or near-continuous monitoring. Standard-risk customers are typically re-screened periodically, from quarterly to annually, scaled to their risk rating. On top of the calendar, screening should be trigger-based: a new transaction pattern, a watchlist update or a change in customer data should each prompt a fresh check.

How you run that cadence matters as much as the cadence itself. Batch re-screening re-resolves the entire customer book on a fixed schedule, which spikes alert volumes and re-raises hits analysts already cleared. Event-driven monitoring against a resolved, reusable identity only re-evaluates what has actually changed, which keeps the alert queue proportionate to real new risk. The distinction is the same one running through this whole guide: a resolved identity makes ongoing monitoring tractable, where a name-first batch process makes it a treadmill.

How are AI and LLMs changing screening in 2026?

Natural language processing and large language models are improving the hard parts of this control. Better entity disambiguation cuts namesake false positives. Multilingual models extend coverage into languages a smaller analyst team could never staff. Context and sentiment classification can tell a story about a victim of fraud from a story about a perpetrator, which is exactly the distinction a keyword match misses. Used well, these gains attack the false positive problem at its root rather than adding more raw sources on top of it.

The risks are equally concrete and deserve a clear-eyed read. Models hallucinate, so an LLM that summarises or classifies a negative news hit can fabricate a connection that no source supports, which is dangerous in a control that feeds a regulatory decision. And ungoverned model access to personal data is its own exposure: an AI agent that ingests raw customer PII into a central store to do its work has just rebuilt the honeypot. The privacy-first answer is to let agents screen against resolved identities without pulling raw personal data into a central system, keeping a human adjudication step and an audit trail over every automated call. Our AI compliance agents piece goes deeper on governing that model access.

How do you evaluate an adverse media vendor?

Definitions are table stakes; architecture is the difference. The Zyphe adverse-media vendor architecture checklist below is the artefact to put in front of any tool before you sign, and it pressure-tests a vendor past the source-count marketing. Copy it into your request-for-proposal and require a written answer to each line.

  • Entity-resolution quality: does it resolve against a full identity, or match on name alone?
  • Source breadth and de-duplication: does it collapse the same event reported five times into one hit?
  • False-positive rate and tuning: can you tune thresholds by risk category and status?
  • Audit trail and explainability: can an analyst see why a hit was raised and record a reasoned decision?
  • Ongoing-monitoring model: is it event-driven, or a blunt periodic batch?
  • Language coverage: does it match across the languages and scripts your customers use?
  • The question incumbents dodge: where does your customers' verified data live, and is it a breach honeypot?

That last point is the load-bearing one. Moving from a name-first screen to a resolved-identity screen against the KYC passport reduces the share of adverse-media alerts that need manual review, because the engine knows who it is screening before it starts matching rather than chasing every namesake; that is the lever the checklist is built around, and it is a directional effect rather than a single audited number. Centralised identity vendors such as Sumsub, Onfido, Veriff, Jumio, Trulioo and Persona each operate a model that collects and stores customer PII; we name them as the contrast set without endorsing any. The question to ask any of them, and the one no listicle will, is architectural. For head-to-head detail, see our identity verification software comparison and Sumsub alternatives guides.

That resolved identity is the output of automated KYC: a verified document, a live face matched to it, and the extracted data reconciled, before any screening runs.

What mistakes should you avoid?

The failure modes repeat across audits, and most are cheap to fix once named. Screening on name only, which guarantees a flood of namesake hits no team can clear. Treating every allegation as a confirmed hit, which over-escalates and buries the real signals. Failing to de-duplicate repeated reporting of the same event, which inflates the queue without adding information. Ignoring ongoing monitoring and treating screening as a one-time onboarding gate, which leaves risk that emerges later unseen.

Two more are quieter but costlier. Keeping no audit trail for adjudication decisions, which leaves you unable to show an examiner why a hit was cleared, the exact evidence FFIEC and the EU rulebook expect. And storing more personal data than you need, which turns every customer record into breach exposure. The TD Bank resolution shows what the regulatory end of weak monitoring looks like; our data-breach risk analysis covers the storage side.

The bottom line

Every vendor in this market defines adverse media the same way and competes on source volume, which is precisely what produces the 85 to 95 percent false positive rate Facctum reports across AML screening. Definitions are table stakes. The real differentiator is whether your screening runs against a resolved, reusable identity, and whether collecting all that verified data leaves you holding a breach honeypot you did not need. The teams that come out ahead will treat adverse media screening as an entity-resolution and architecture problem first, and a source-count problem a distant second. Resolve the identity, keep the audit trail, and ask where the data lives before you sign.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

Adverse media screening is the process of checking a customer or business against public news, regulatory and court sources for links to financial crime, fraud, corruption or sanctions exposure. Also called negative news screening, it is a core part of know your customer and anti-money laundering customer due diligence, run at onboarding and through ongoing monitoring to surface risk before authorities formally designate it.

They are synonyms, used interchangeably across the industry. Negative news screening is the more literal description of the activity, while adverse media is the term regulators and the AML industry tend to prefer. The underlying process is identical: checking public sources for reporting that links a person or business to financial crime or other risk relevant to a due diligence decision.

It runs in five steps. The engine takes a verified identity from the KYC or KYB profile, matches that name and its variants across news, regulatory and court sources, resolves each match against date of birth, nationality, role and associates, classifies surviving hits by risk category and status, then routes them to an analyst who adjudicates and records an audit trail. Entity resolution is the step that controls how many false positives reach a human.

The source set spans traditional and digital news media, regulatory and enforcement publications such as SEC, FCA and Office of Foreign Assets Control releases, court and litigation records, sanctions and watchlist data, investigative leaks and datasets, and vetted social media. Tier-one vendors aggregate enormous volumes; LSEG World-Check, for example, publishes coverage of 240 countries and over 4 million records, which is exactly what drives high match volume and false positives.

Sanctions screening checks official government lists, and a true hit creates a binding legal obligation to freeze and report. Adverse media screening is forward-looking and judgement-based: it surfaces reporting of possible wrongdoing before any formal designation exists, and a hit triggers a documented review rather than an automatic block. They are complementary controls, not substitutes, and a sound programme runs both alongside politically exposed person screening.

At onboarding and then continuously through ongoing monitoring. High-risk customers warrant continuous or near-continuous monitoring; standard-risk customers are re-screened periodically, from quarterly to annual, scaled to their risk tier. On top of that schedule, trigger-based re-screening should fire on new transactions, watchlist updates or changes to customer data. Ongoing monitoring is an explicit AML expectation, not an optional add-on.

No single statute names it verbatim, but it operationalises FATF Recommendations 10 and 12 and enhanced due diligence expectations. United States examiners expect negative media search programmes as a risk-based factor under the FFIEC manual, and the EU Anti-Money Laundering Regulation, applicable from 10 July 2027, builds the same ongoing-monitoring duties into a single rulebook. In practice it is expected as part of risk-based customer due diligence.

Facctum puts AML screening false positives at 85 to 95 percent and LexisNexis Risk Solutions reports institutions at 95 percent or more, though neither figure is specific to adverse media and no regulator publishes an official one. The causes are structural: matching on name alone, flagging unproven allegations the same as convictions, failing to de-duplicate the same event reported many times, and re-screening siloed identities from scratch each cycle. Strong entity resolution against a resolved, reusable identity is what cuts the noise.

AML compliance without the PII liability

Screening, monitoring and reporting built on a privacy-first identity layer.

See Zyphe AML