
Adverse Media Screening Best Practices
Sanctions lists tell you who is designated today.
Adverse media can surface risk before a designation does.
In This Whitepaper
Why Sanctions Lists Alone Are Not Enough
Sanctions lists are reactive. OFAC designates an individual or entity after sufficient evidence has been gathered, reviewed, and approved through a formal interagency process. By the time a name appears on the SDN list, the underlying behavior has often been underway for months or years.
DOJ indictments, SEC enforcement actions, FinCEN penalties, and investigative journalism surface compliance-relevant information weeks, months, or years before formal designation.
The challenge is volume. Government enforcement databases, court filings, and global news produce thousands of data points daily. A defensible program uses AI-assisted triage to reduce low-confidence noise while routing genuine ambiguity to human reviewers.
Enforcement Intelligence Sources
A production-grade adverse media screening program aggregates intelligence from government enforcement databases, international law enforcement, and AI-curated news.
DOJ Press Releases
Department of JusticePublic Department of Justice press releases on prosecutions, indictments, guilty pleas, and sentencing, found through web search limited to justice.gov. A charge is an allegation until it is resolved, so these items inform review rather than decide it.
SEC EDGAR Filings
Securities & Exchange CommissionCompany filings in SEC EDGAR, such as 8-K current reports, that mention enforcement actions, penalties, or fraud, found through EDGAR full-text search.
FinCEN Enforcement Actions
Financial Crimes Enforcement NetworkEntries on FinCEN’s public enforcement actions page covering Bank Secrecy Act and anti-money-laundering penalties, classified from their published titles.
FCA (UK) Enforcement News
Financial Conduct AuthorityEnforcement items, such as fines and prohibitions, from the Financial Conduct Authority’s public news feed. Useful context for organizations with UK exposure.
OpenSanctions Wanted-Person Data
Aggregated DatasetsWanted-person datasets published through OpenSanctions, including INTERPOL Red Notices, FBI Most Wanted, and FBI terrorism listings. Coverage depends on pilot configuration.
News Search
Commercial news search servicesEnglish-language news results for fraud, sanctions, export, money-laundering, and bribery terms. Outlets vary with what the search services return. AI reads each headline and snippet and records the primary named party, a category, and a severity.
AI-Assisted Triage & Human Review
AI-assisted triage helps prioritize findings, set aside low-confidence noise, and route genuine ambiguity to human reviewers with context.
AI Classification
Every ItemA language model reads each headline and snippet, extracts the primary named party, and assigns a category, a severity, and a confidence score.
Flagged for Review
Human JudgmentItems with high or critical severity and middling confidence are flagged for human review rather than settled by the model.
How Confidence Thresholds Are Used
These thresholds sort items in a shared index of enforcement and news items. They do not block access, and findings about a monitored party wait for a reviewer's decision.
Source Credibility & Recency Scoring
Not all adverse media is created equal. A composite scoring formula weighs entity match quality, AI confidence, source credibility, and recency.
Composite Scoring Formula
Name-match threshold of 0.65, lower than the default used for restricted-party screening, because adverse media is an informational signal, not a blocking control.
Source Credibility Tiers
Recency Weighting
Politically Exposed Persons as Review Context
PEP signals can represent elevated risk due to political connections and exposure to bribery, corruption, and illicit financial flows. They should inform review, not replace a compliance decision.
Adverse Media Risk Categories
Each indexed item is assigned one category and one severity for prioritized review.
Severity Levels
Severity is assigned by AI, guided by these definitions.
Building an Operational Monitoring Program
Load Your Roster
Import third parties, companies or individuals, as a CSV file or as JSON through the application. Each entity gets a risk tier (low, standard, elevated, or high) and a review cadence (monthly, quarterly, semi-annual, or annual).
Run Monitoring Cycles
A daily job adds new enforcement and news items to a shared index. Your team starts monitoring runs against the roster, and each run checks entities against restricted-party lists, that index, and live enforcement and news lookups. Review cadences mark when each entity is next due.
Use AI to Triage, People to Decide
AI-assisted triage sets aside low-confidence items and brings ambiguous or serious ones to your compliance team with a summary, a rationale, and a link to the source.
Record Decisions and Attestations
Choose a review type: quarterly, annual, ad hoc, or event-triggered. Reviewers can record a decision and notes for each third party. A cycle is completed only after a reviewer and an approver attest its latest monitoring run. Pilot deliverables can include a PDF review report.
SecurePoint USA Screening Architecture
Named Enforcement and News Sources
DOJ press releases, SEC EDGAR filings, FinCEN and FCA enforcement publications, OpenSanctions wanted-person datasets, and English-language news search. A daily job adds new items to a shared index and skips items already indexed.
AI Classification with Source Links
AI identifies the primary named party in each item and records a category, a severity, a confidence score, and a short rationale alongside the source link.
Sanctions Screening with Shadow Context
A monitoring run pairs restricted-party screening with adverse media context. By default, adverse media and PEP signals are informational: they do not change screening risk scores or block access. Reviewers record decisions per third party.
Review Lifecycle and Attestations
Reviews move through draft, in progress, pending adjudication, and completed. A cycle is completed only when a reviewer and an approver attest its latest run, and a new run needs new attestations. They must be two different people unless SecurePoint enables single-signer attestation for an organization with one compliance signer, and the record and the PDF report show when that exception was used.
Roster-Based Monitoring Cycles
Assign a risk tier and review cadence to each entity. Operators run monitoring cycles against a shared index that a daily job keeps current. When a run surfaces entities that need attention, compliance contacts receive one summary email for that run.
Look Beyond
the Sanctions Lists
Sanctions lists are reactive. Adverse media can surface early warning context. Screen enforcement sources with AI-assisted triage and human review.
Spend reviewer time on the items that need judgment.
Frequently asked questions
Does adverse-media screening block a visit or a transaction in SecurePoint?
No. By default, adverse-media screening runs in a monitoring capacity. It does not block a visit, hold a transaction, or drive an adjudication decision on its own. Sanctions and restricted-party screening are the controls that gate access.
Is adverse-media screening generally available?
It is offered as a controlled pilot rather than general self-service. A pilot runs against your own roster so you can see the report format and the review workflow before committing to anything longer term.
Does adverse media replace sanctions screening?
No. Restricted-party screening answers a legal question about whether a party is listed, or owned by listed persons. Adverse media is contextual information that may inform a human review. They are different controls carrying different weight, and they should not be substituted for one another.
Who decides what an adverse-media finding means?
Automated triage proposes and people decide. Triage sorts and summarizes items and gives each monitored third party a provisional triage state, labeled as automated. A reviewer can record a decision and rationale for any third party, and a review cycle is completed only after a reviewer and an approver attest its latest monitoring run, including a run with no findings.
Can adverse-media findings be exported as evidence?
Findings, reviewer decisions, attestations, and review activity are stored with the case record. Attestations and decisions are append-only, so application users cannot edit or delete them, and a finding keeps the source evidence its run recorded. Audit entries are kept rather than overwritten. Confirm what a specific pilot scope produces before relying on it for a particular review.
Informational only. This whitepaper is provided for general informational purposes only and does not constitute legal, regulatory, or compliance advice. It is not a substitute for review by qualified sanctions or AML counsel familiar with your program.
Source-credibility weights, recency curves, and triage examples describe SecurePoint USA program guidance as of the “Last reviewed” date in the PDF version. Actual outcomes depend on configuration, enabled sources, and roster composition. © 2026 SecurePoint USA. All rights reserved.