6th Cyber Security Conference · with MastercardDetails
Infocredit Group
Insight

Adverse media screening: a practical guide

What adverse media (negative news) screening is, why regulators expect it, where it fits in KYC/KYB onboarding, and how to run it without drowning in false positives.

Adverse media screening — often called negative news screening — is the process of checking a customer, supplier or counterparty against news media and other public sources for information that connects them to financial crime, fraud, corruption, sanctions evasion, regulatory action or other misconduct. It sits alongside sanctions and PEP screening as one of the three standard screening pillars in a KYC/KYB programme.

Unlike sanctions lists, which are structured and definitive, adverse media is unstructured: a name in an article, in any language, with no guarantee that the person named is your customer. That ambiguity is exactly why adverse media screening is both essential and operationally hard — and why the quality of the tooling matters more here than anywhere else in screening.

Why regulators expect it

FATF's risk-based approach expects obliged entities to understand who they are dealing with, and publicly available negative information is an obvious input to that understanding. EU AML directives require enhanced due diligence for higher-risk situations, and EDD in practice means looking beyond list matches — into reputational and criminal-history signals that only media and public records carry.

Local regulators apply the same logic. CySEC's AML directive for CIFs, the MFSA's expectations for Maltese licence holders and the Bank of Greece's requirements under Law 4557/2018 all expect adverse media to inform customer risk assessment, particularly at onboarding, for high-risk customers, and when trigger events occur.

What adverse media screening actually covers

  • Financial crime allegations — fraud, money laundering, bribery, corruption, tax evasion, embezzlement.
  • Sanctions-adjacent news — reported links to sanctioned persons or jurisdictions before a formal listing exists.
  • Regulatory and enforcement actions — fines, licence withdrawals, cease-and-desist orders, criminal charges.
  • Litigation and insolvency — court cases, bankruptcies, winding-up petitions and creditor actions.
  • Reputational events — scandals and controversies that change the risk of being associated with the entity.

Where it fits in the onboarding and monitoring lifecycle

At onboarding, adverse media screening runs as part of initial due diligence, alongside identity verification, registry checks and sanctions/PEP screening. For standard-risk customers a clear result supports the file; a hit triggers review and possibly enhanced due diligence.

The bigger gap in most programmes is ongoing monitoring. Risk changes after onboarding: a customer who was clean in January can be indicted in June. Event-driven or continuous adverse media monitoring catches that change and triggers a review, which is what examiners increasingly ask to see.

The false-positive problem

A raw name search against the open web produces mostly noise: common names, unrelated industries, stories in languages nobody on the team reads, and articles that mention the name in passing. Programmes that route all of this to analysts produce backlogs and, eventually, rubber-stamped dispositions.

The controls that actually reduce noise are entity resolution (matching on identifiers, age, jurisdiction and associates, not just the name), relevance categorisation (only financial-crime-relevant stories surface), deduplication of syndicated stories, and language coverage matched to the customer base. Every alert that survives should end in a documented disposition — confirmed, discounted with a reason, or escalated.

How Infocredit Group approaches it

ComplianceSuite runs adverse media screening as part of its KYC/KYB onboarding and ongoing monitoring workflow, combining global adverse media coverage with the local-language press of Cyprus, Greece, Malta and the wider region — coverage that global-only tools frequently miss. Hits are categorised, deduplicated and routed into case management with a full audit trail.

For teams that want screening inside their own systems, the same capability is available through the ComplianceSuite and partner screening APIs.

Frequently asked questions

What is adverse media screening in AML?

It is the practice of checking customers and counterparties against news and public sources for links to financial crime, fraud, corruption, sanctions or regulatory action. Regulators expect it as an input to customer risk rating, and as a mandatory part of enhanced due diligence for higher-risk customers.

Is adverse media screening a regulatory requirement?

Rarely by name, but in practice yes. FATF guidance and EU AML directives require a risk-based approach and EDD for higher-risk situations, and supervisors — including CySEC, the MFSA and the Bank of Greece — expect adverse media to be considered. Auditors treat its absence as a finding in higher-risk files.

How is adverse media different from sanctions screening?

Sanctions screening matches against structured, official lists with legal consequences. Adverse media searches unstructured news and public records for risk signals that may never result in a listing. The two are complementary: adverse media often surfaces risk months before a formal listing or enforcement action.

How do you reduce false positives in adverse media screening?

Entity resolution beyond name matching, relevance filtering to financial-crime categories, deduplication of syndicated stories, language coverage matched to the customer base, and a forced documented disposition on every alert.

How often should adverse media screening run?

At onboarding for every customer, and continuously or event-driven thereafter. Annual batch rescreening leaves long blind windows; continuous monitoring flags a change within days of publication.

Newsletter

Compliance insights, straight to your inbox

Monthly analysis on AML, screening and risk technology from the teams behind ComplianceSuite, RISQO and API4ALL. No spam — unsubscribe anytime.