no EU money-laundering rule requires adverse media screening.
Adverse media screening means checking a name against negative information in the public domain: news reporting, court records, regulatory disclosures, penalty notices. In practice the term describes one particular product, where a name is run against a curated, risk-tagged database at onboarding and again at review. No FATF Recommendation and no EU anti-money-laundering instrument requires it.
Applied to suppliers instead of customers, it means something different again: watching companies you already buy from, continuously, after you've signed. That matters if you're deciding whether your existing subscription covers your vendor book. The answer is usually no.
is adverse media screening required by law?
The FATF 40 Recommendations contain no mention of media as a source of due diligence information. Recommendation 10 asks for identification and verification using reliable, independent source documents, data or information, and names no media obligation. Adverse media appears in FATF material as a parenthetical example inside non-binding guidance: “carrying out additional searches (e.g., verifiable adverse media searches)”, one of five illustrative enhanced due diligence measures in the 2014 risk-based approach guidance for banking.
The Wolfsberg Group wrote the reference FAQs on this and has every reason to say otherwise. Its own introduction says FATF “do not explicitly refer to” negative news screening.
The EU AML package doesn't add the requirement either. Regulation (EU) 2024/1624, which applies from 10 July 2027, contains no occurrence of “adverse media” or “negative news”. Its enhanced due diligence article lists seven general measures and a press search is not among them, nor among the three it adds for correspondent relationships. Reputation does appear: as a risk variable in Annex I, and in Article 36, which asks for information about a respondent institution's reputation in cross-border correspondent relationships. Neither prescribes a press search, and neither is about your suppliers. Directive (EU) 2024/1640 contains no occurrence either.
The EBA's ML/TF risk factors guidelines do name it, at 4.64 and 9.13. EBA guidelines operate comply-or-explain, though, so the accurate verb is “expects”, not “requires”. AMLA's guidelines on ongoing monitoring name it too, and as at August 2026 those were still in draft, published for consultation on 3 June 2026.
That's the EU and FATF picture, and it's the one this page tests. Other regimes set their own supervisory expectations, some of them more prescriptive. The enforcement case below is a British one. Check the regime that actually binds you.
Wolfsberg is also clear that this shouldn't be a zero-tolerance process, that firms may conclude screening isn't necessary in all circumstances, and that nobody's expected to spend resources on it where the added value is negligible. Which is roughly the opposite of how the category gets sold.
adverse media screening was built for customers, not suppliers.
Article 2(1), point (19) of the AMLR defines a business relationship as one set up between an obliged entity and a customer. Every ongoing monitoring duty over a business relationship attaches there, and the customer due diligence chapter doesn't reach your own suppliers.
The regulation does look at your service providers in one place, and people cite it for this, so it's worth reading. Article 18 covers outsourcing an anti-money-laundering task, where you have to keep checking the provider carries it out properly. That's a duty about somebody doing your compliance work. Your vendor book is not in it. Article 36 is the other place reputation turns up, and it covers correspondent banking. Your server host isn't in it.
Wolfsberg says the same: firms typically focus negative news screening on customers and business relationships, and “may elect to broaden the scope… e.g., vendors or third-party suppliers” in line with risk appetite. May elect. So it's a choice, and plenty of firms make it.
So if your adverse media subscription doesn't cover your vendor book, it is doing the job it was bought for.
the fine that wasn't for missing the story.
On 14 July 2025 the FCA fined Barclays Bank Plc £39,314,700, reduced from £56,163,900 by a settlement discount. The case is worth reading if you are choosing a screening tool, because of what it was not about.
Barclays had the tool. It had the policy. It ran the check, and the check found the news. The findings are that the Authority saw no evidence the adverse media results were reviewed, or if so why they were discounted, and that the adverse media did not trigger a change to the risk rating.
Nobody was penalised for failing to find a story. The failure was having it and keeping no record of what was decided about it.
Which inverts the thing the whole category competes on. Coverage is what every vendor sells and what no auditor can test, because you can't prove a negative about what a database didn't contain. Disposition is what actually gets asked for: what surfaced, when, who looked at it, what they concluded, and where that's written down. It's also the part a screening interface tends to leave in a session nobody kept.
what we are not.
what we do with negative news.
We read the trade and regional press in the market where a supplier operates, alongside the registries, dockets, gazettes and sanctions lists that make up most of the work. Press gets treated more carefully than the rest, deliberately: a court filing is published under a legal duty, and a news article isn't.
So an alert built on reporting says what the source claims instead of asserting it as established fact, and links the original untranslated. If forty articles cover one event, which is what happens, they collapse into a single event checked once against the line you set. Below that line, you hear nothing.
Where an alert would carry material about alleged offences, one more control applies: the data processing agreement has you confirm you hold your own lawful basis for receiving it, arising from your own obligations. If you can't give that confirmation, we narrow what we watch for you rather than sending it anyway.
On data protection, “these are companies, so GDPR doesn't apply” does not hold. Recital 14 excludes legal persons, but reporting about a company names directors and officers, and the moment a person is in an alert the regulation applies to that part of it. Article 10 treats material about criminal convictions and offences more strictly again. Which is why three of the limits above are written into the data processing agreement instead of left as preferences: the company as the unit of record; the undertaking not to introduce a supplier risk score, a rating, or any feature that indexes or scores individuals without giving you notice first; and the plain statement that if something is not published we will not see it, so no alert does not mean nothing happened. The other two describe what the product is, which you should hold us to in the ordinary way.
what is actually pushing you toward supplier watching.
Not AML rules. A different set entirely, and not one of them mentions adverse media.
- DORA requires a termination right for circumstances identified through monitoring that affect “the situation of the ICT third-party service provider”, and requires you to plan and test for a provider's insolvency. What DORA does and doesn't ask for.
- NIS2 puts supply chain security into your own security obligations and requires you to act when a direct supplier's practices change. How that works in practice.
- Sanctions and export control, where a designation is immediate and the consequence is legal rather than reputational.
- Forced labour rules, including Regulation (EU) 2024/3015, which applies from 14 December 2027 and sets up a portal for anyone to submit information about alleged violations.
Corporate sustainability due diligence is worth a word, because it keeps getting listed as a driver for firms it doesn't reach. After the omnibus amendments of February 2026, the thresholds are five thousand employees and €1.5 billion in turnover, with application from 2029. Almost no mid-market company is in scope directly. You get it anyway, cascaded down in contracts from the customers who are.
There's a line in those amendments worth knowing. The recitals describe a scoping exercise based solely on reasonably available information, say companies aren't required to systematically identify impacts at entity level, and state that relying on reasonably available information “will as a general rule preclude requesting information from business partners”.
That line gets quoted on its own. In place, it describes the initial scoping step, and the recitals that follow say companies may still need to seek information from business partners where the scoping exercise points somewhere, and only where it does. The same recital adds that companies have flexibility in judging what is reasonably available to them. But the direction of travel is plain enough. The default is what you can find out yourself. We have never sent a questionnaire.
common adverse media questions.
what is adverse media screening?
Checking a name against negative information in the public domain (news reporting, court records, regulatory disclosures, penalty notices) to inform a financial-crime risk assessment. The Wolfsberg Group, whose FAQs the industry treats as the reference, defines negative news as “information available in the public domain which FIs would consider relevant to the management of Financial Crime risk”. In practice the term describes a specific product shape: a name screened against a curated, risk-tagged database, with alias and transliteration matching, at scale.
what’s the difference between adverse media and negative news?
Not much, beyond who is speaking. The Wolfsberg Group, whose FAQs the industry treats as the reference, says negative news, and defines it as “information available in the public domain which FIs would consider relevant to the management of Financial Crime risk”. Screening vendors and their buyers tend to say adverse media. Both point at the same material: press reporting, court records, regulatory disclosures and penalty notices about a name. The label isn’t where the real difference sits. Screening asks about a name, once, at a moment. Watching asks about a company you already buy from, continuously, after you have signed.
how often should adverse media screening be done?
No EU instrument sets a frequency for it. What the AMLR does set, at Article 26, is how often customer information itself must be updated: at intervals not exceeding one year for higher-risk customers under enhanced due diligence, and five years for everyone else, plus a review whenever the obliged entity becomes aware of a relevant fact about that customer. That last trigger is the interesting one, because it assumes something told you. For your own suppliers, no anti-money-laundering rule sets a cadence at all, though other regimes do set supplier review cadences of their own, so check what binds you. We read each source on an interval matched to how often it changes, the fast ones daily, and collapse the day’s findings into one email. Two exceptions, both named: a company you have marked critical goes out on its own once it is verified, and the weekly watch log arrives whatever the week did.
what's the difference between adverse media screening and sanctions screening?
A sanctions list is an official, authoritative designation with legal consequences: if a party is on it, restrictions apply. Adverse media is reporting, which may be wrong, contested, or about someone with a similar name. Sanctions screening gives you a yes or a no against a definitive list. Adverse media gives you material somebody then has to read and judge, which is why we treat the two differently.
what's the difference between screening and monitoring?
Screening is a check run at a moment, at onboarding or at a periodic review, and it describes the day it was run. Monitoring runs continuously afterwards and tells you when something changed. Most adverse media products are sold as screening with a monitoring option layered on. We only do the second kind, on a list you give us.
why does adverse media screening throw up so many false positives?
Because of what it is matching. Screening in its established sense runs a name against a curated database across a population you may not have enumerated, with alias, transliteration and secondary-identifier matching, so a similar name in another country is a hit. Then the same event arrives many times over. If forty articles cover one story, that is forty hits about one thing. We publish no figures for any of this, ours or anyone else’s, because the numbers circulating in this field come from vendors and carry no method. What we do is narrow the problem: every company on your list is resolved to a registered legal entity first, and a day’s reporting on one event collapses into a single item, checked once against the line you set.
what should you do when adverse media screening finds something?
Write down what you decided about it, and why. The FCA’s £39,314,700 fine against Barclays Bank Plc on 14 July 2025, reduced from £56,163,900 by a settlement discount, shows why. Barclays had the tool, had the policy, ran the check, and the check found the news. The findings are that the Authority saw no evidence the adverse media results were reviewed, or if so why they were discounted, and that the adverse media did not trigger a change to the risk rating. Nobody was penalised for failing to find a story. Coverage is what every vendor sells and what no auditor can test. Disposition is what actually gets asked for.
can you screen adverse media under GDPR?
Carefully, and not by claiming it falls outside. Recital 14 excludes legal persons, but reporting about a company names directors and officers, and the moment a person is in an alert the regulation applies to that part of it. Article 10 treats material about criminal convictions and offences more strictly again. Our answer is to keep the company as the unit of record: no standalone search or screening query about a named individual, no aggregation of adverse media about a person, and no cross-referencing a name across unrelated companies. Where an alert would carry material about alleged offences, the data processing agreement has you confirm your own lawful basis for receiving it. If you can’t, we narrow what we watch for you instead.
does adverse media screening apply to vendors as well as customers?
Not by obligation. The duties are customer-side: Article 2(1), point (19) of the AMLR defines a business relationship as one between an obliged entity and a customer, and the ongoing monitoring duties attach there. The Wolfsberg Group says the same. Firms typically focus negative news screening on customers, and “may elect to broaden” it to vendors or third-party suppliers in line with risk appetite. Nothing stops you extending it to suppliers, and plenty of firms do. Nothing requires it either, and the rules actually pushing firms toward supplier watching aren't adverse media rules.
Version 1.2, 26 August 2026. Every instrument cited here was checked against its text on 2 August 2026, and the AMLA guidelines were in draft then. We publish no figures for false positive rates, alert volumes or coverage. The numbers circulating in this field come from vendors and carry no method, and we haven't run long enough to have our own. When we do, they'll appear with a date on them. This page describes what we read and how we deliver it. It isn't legal or compliance advice.