Skip to main content
Category: AML and KYC

Adverse Media Screening

Also known as: Negative News Screening
Simply put

Adverse media screening is the practice of searching for and reviewing negative news or publicly available information about a person, business, or other entity to identify potential risk. It is commonly used by financial institutions and other organizations as part of checking who they are doing business with. The goal is to spot warning signs, such as links to financial crime, that might affect a decision to onboard or continue a relationship with that party.

Formal definition

Adverse media screening, also referred to as negative news screening, is a risk assessment process that identifies and evaluates negative news, information, or publicity involving individuals, organizations, or entities from publicly available sources. It is commonly deployed within anti-financial crime programs and forms a component of customer and third-party due diligence workflows, supporting broader onboarding, monitoring, and risk-rating activities. The process reviews publicly available information for indications of potential risk; the specific scope, source coverage, and matching methodology depend on implementation and the governing compliance program rather than on the term itself.

Why it matters

Adverse media screening gives financial institutions and other organizations an early signal of risk that may not yet appear on formal watchlists or sanctions lists. Negative news coverage linking a person or entity to financial crime, corruption, or other misconduct can surface before regulatory action is taken, so reviewing publicly available information helps compliance teams make more informed onboarding and ongoing monitoring decisions. Within anti-financial crime programs, it is one input among several that supports customer and third-party due diligence rather than a standalone determination of guilt or wrongdoing.

Because it draws on publicly available sources, adverse media screening extends the picture built from identity verification and watchlist checks. It is intended to help identify warning signs that might affect a decision to begin or continue a relationship with a party. Its usefulness depends heavily on source coverage, matching methodology, and how results are reviewed and dispositioned within the governing compliance program.

At the same time, adverse media screening has known limitations. Name-based matching can produce false positives, where unrelated individuals share a name, and false negatives, where relevant coverage is missed due to source gaps, language, or ambiguous reporting. Negative news is not the same as a proven fact, so results require human review and contextual judgment. The specific scope and effectiveness of any implementation depend on the program design rather than on the label alone.

Who it's relevant to

Compliance and Financial Crime Teams
Compliance officers and anti-financial crime analysts use adverse media screening as a component of due diligence to identify potential risk signals and support onboarding, monitoring, and risk-rating decisions. They are responsible for reviewing matches, resolving false positives, and documenting dispositions within the governing program.
Onboarding and KYC Teams
Teams handling customer onboarding incorporate negative news screening alongside identity verification and watchlist checks to inform decisions to begin or decline a relationship. Screening results feed into the broader due diligence picture rather than serving as a standalone decision.
Third-Party and Vendor Risk Managers
Because adverse media screening forms part of third-party due diligence, teams assessing vendors, partners, and other business relationships use it to surface warning signs that may affect whether to engage or continue working with a counterparty.
Financial Institutions and Regulated Industries
Financial institutions and other regulated organizations deploy adverse media screening as part of staying compliant and helping to prevent financial crimes. The exact scope and cadence depend on each institution's compliance program and applicable regulatory expectations.

Inside Adverse Media Screening

Negative News Sources
The public and commercial information channels searched during screening, which may include news media, regulatory notices, sanctions and enforcement actions, court records, and other publicly reported material. Coverage, language, and recency vary by data provider and region.
Risk Categories
The types of adverse activity the screening seeks to surface, such as financial crime, fraud, money laundering, terrorist financing, corruption, and other reputationally significant conduct. The specific categories in scope depend on the organization's risk appetite and applicable obligations.
Entity Matching
The process of associating a search subject (an individual or business) with retrieved media items, typically using name, identifiers, and contextual data. Matching produces potential hits that require human or automated adjudication.
Alert Adjudication and Disposition
The review workflow in which potential matches are confirmed, dismissed as false positives, or escalated. Dispositions and supporting rationale are documented to create an auditable record.
Screening Frequency
The cadence at which screening runs, which may be at onboarding, periodically, or on an event-driven or ongoing monitoring basis. Frequency choices affect how quickly newly reported information is detected.
Program Governance
The policies, roles, thresholds, and record-keeping that define how screening is configured, tuned, and evidenced. This is where an organization aligns screening to its own risk framework rather than to any single technical label.

Common questions

Answers to the questions practitioners most commonly ask about Adverse Media Screening.

Is adverse media screening a PCI DSS requirement?
No. Adverse media screening is a due-diligence and risk-management practice associated with anti-money-laundering, sanctions, and know-your-customer programs, not a control defined by PCI DSS. PCI DSS governs the protection of cardholder data and sensitive authentication data within the cardholder data environment. Adverse media screening may be part of a merchant onboarding or ongoing monitoring program run by an acquirer or payment processor, but it does not appear as a PCI DSS requirement and should not be confused with PCI DSS validation activities.
Does adverse media screening prevent fraud or confirm that an entity is guilty of wrongdoing?
No. Adverse media screening is intended to surface publicly reported negative information as an input to risk assessment; it does not prevent fraud and does not establish guilt. A media hit is an indicator that may warrant further review, not a determination of fact. Results carry both false-positive risk, such as name matches to unrelated individuals or outdated reporting, and false-negative risk, such as unreported or unindexed conduct. It should be used alongside other controls rather than treated as a standalone or conclusive measure.
How is adverse media screening typically integrated into merchant onboarding?
It is commonly performed during due diligence as one input among several, alongside identity verification, sanctions and watchlist screening, and business-history checks. Screening is generally run against the legal entity and its associated principals or beneficial owners. Organizations typically define what sources are searched, what match criteria trigger a review, and how findings are escalated. Because it is a risk input rather than a pass or fail control, results usually feed a documented risk decision instead of an automated accept or reject.
How should false positives be handled in an adverse media screening workflow?
Because name-based matching produces false positives, workflows generally include a manual review or adjudication step where analysts assess relevance, recency, and whether the report actually concerns the entity under review. Documenting the disposition of each alert, including the rationale for clearing or escalating it, supports consistency and auditability. Tuning match thresholds affects the trade-off between missed hits and review volume, so organizations typically calibrate criteria to their risk appetite and revisit them over time.
How often should adverse media screening be repeated after onboarding?
Screening is often performed at onboarding and then on an ongoing or periodic basis, since negative information can emerge after a relationship begins. The cadence depends on the organization's risk-based policy and any applicable regulatory expectations, which vary by jurisdiction. Higher-risk relationships may be monitored more frequently or continuously, while lower-risk ones may be reviewed on a set interval. Organizations should define and document the refresh approach rather than treating onboarding screening as a one-time check.
What should be documented when using adverse media screening in risk decisions?
Organizations typically document the sources searched, the match criteria applied, the alerts generated, the adjudication outcome for each alert, and the resulting risk decision with its rationale. Retaining this record supports internal governance, demonstrates a consistent process, and helps address questions from auditors or regulators. Any data handling should also respect applicable privacy and data-protection obligations, which vary by region and are separate from PCI DSS scope considerations.

Common misconceptions

Adverse media screening is a PCI DSS requirement or control.
Adverse media screening is a risk, due diligence, and financial-crime concept, not a control defined by PCI DSS or related standards such as PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, or PCI 3DS. It does not protect cardholder data or sensitive authentication data, and organizations should confirm any compliance obligations against the specific regulation or standard that actually governs them.
A clean screening result confirms that a party is not involved in illicit activity.
Screening only reflects what is publicly reported and successfully matched. It is subject to false negatives from unreported conduct, incomplete data coverage, or matching gaps, and false positives from common names or ambiguous entities. A clean result helps reduce risk but does not guarantee integrity and should be treated as one input among several.
Adverse media screening prevents fraud such as account takeover or synthetic identity fraud.
Screening is intended to surface reputational and financial-crime risk associated with a known party; it is not a fraud-detection control and does not by itself stop card-present, card-not-present, first-party, chargeback, or synthetic identity fraud. Those risks are addressed by separate detection and authentication measures, and liability outcomes depend on card brand and network rules that vary by region.

Best practices

Define the risk categories, sources, and match thresholds in a documented policy so screening reflects your organization's risk appetite rather than a vendor default, and confirm any applicable obligations against the specific regulation that governs your program.
Establish a human adjudication workflow for potential matches, recording the rationale for each disposition to maintain an auditable trail and to manage the false-positive and false-negative trade-offs inherent in matching.
Combine onboarding screening with periodic or event-driven ongoing monitoring so newly reported information can be detected, and document the chosen frequency and its justification.
Assess data provider coverage across relevant languages, jurisdictions, and source types, since gaps in coverage directly limit what screening can surface.
Treat screening results as one input among several and integrate them with your broader due diligence and fraud controls rather than relying on any single check to eliminate risk.
Periodically tune matching logic and thresholds and review alert quality metrics to balance missed hits against excessive false positives.