Skip to content
Adverse Media Screening
Whitepaper · 2026

Adverse Media Screening Best Practices

Sanctions lists tell you who is designated today.

Adverse media can surface risk before a designation does.

12 min read2026DOJ · SEC · FinCEN · PEP context
01 · The Gap

Why Sanctions Lists Alone Are Not Enough

Sanctions lists are reactive. OFAC designates an individual or entity after sufficient evidence has been gathered, reviewed, and approved through a formal interagency process. By the time a name appears on the SDN list, the underlying behavior has often been underway for months or years.

DOJ indictments, SEC enforcement actions, FinCEN penalties, and investigative journalism surface compliance-relevant information weeks, months, or years before formal designation.

The challenge is volume. Government enforcement databases, court filings, and global news produce thousands of data points daily. A defensible program uses AI-assisted triage to reduce low-confidence noise while routing genuine ambiguity to human reviewers.

Shadow
Default Mode
Does not block access
Pilot
Human Review
AI-assisted triage
AI
Categorized
Category and severity
Linked
Evidence
Source link on each item
02 · Intelligence Sources

Enforcement Intelligence Sources

A production-grade adverse media screening program aggregates intelligence from government enforcement databases, international law enforcement, and AI-curated news.

DOJ Press Releases

Department of Justice

Public Department of Justice press releases on prosecutions, indictments, guilty pleas, and sentencing, found through web search limited to justice.gov. A charge is an allegation until it is resolved, so these items inform review rather than decide it.

SEC EDGAR Filings

Securities & Exchange Commission

Company filings in SEC EDGAR, such as 8-K current reports, that mention enforcement actions, penalties, or fraud, found through EDGAR full-text search.

FinCEN Enforcement Actions

Financial Crimes Enforcement Network

Entries on FinCEN’s public enforcement actions page covering Bank Secrecy Act and anti-money-laundering penalties, classified from their published titles.

FCA (UK) Enforcement News

Financial Conduct Authority

Enforcement items, such as fines and prohibitions, from the Financial Conduct Authority’s public news feed. Useful context for organizations with UK exposure.

OpenSanctions Wanted-Person Data

Aggregated Datasets

Wanted-person datasets published through OpenSanctions, including INTERPOL Red Notices, FBI Most Wanted, and FBI terrorism listings. Coverage depends on pilot configuration.

News Search

Commercial news search services

English-language news results for fraud, sanctions, export, money-laundering, and bribery terms. Outlets vary with what the search services return. AI reads each headline and snippet and records the primary named party, a category, and a severity.

03 · AI Triage

AI-Assisted Triage & Human Review

AI-assisted triage helps prioritize findings, set aside low-confidence noise, and route genuine ambiguity to human reviewers with context.

AI Classification

Every Item

A language model reads each headline and snippet, extracts the primary named party, and assigns a category, a severity, and a confidence score.

Flagged for Review

Human Judgment

Items with high or critical severity and middling confidence are flagged for human review rather than settled by the model.

How Confidence Thresholds Are Used

< 0.50
Set Aside
Likely noise
0.50 to 0.85
Indexed
Medium or low severity
0.50 to 0.85, High
Human Review
Left for a reviewer
≥ 0.85
Indexed
High confidence

These thresholds sort items in a shared index of enforcement and news items. They do not block access, and findings about a monitored party wait for a reviewer's decision.

04 · Scoring

Source Credibility & Recency Scoring

Not all adverse media is created equal. A composite scoring formula weighs entity match quality, AI confidence, source credibility, and recency.

Composite Scoring Formula

60%
Entity Match
20%
AI Confidence
10%
Source Credibility
10%
Recency

Name-match threshold of 0.65, lower than the default used for restricted-party screening, because adverse media is an informational signal, not a blocking control.

Source Credibility Tiers

Government (DOJ, SEC, FinCEN)0.95 - 1.0
Wire Services (Reuters, AP)0.90
Major Press (WSJ, FT, BBC)0.80 - 0.85
Trade Press (Law360)0.70 - 0.75
Other and Regional Outlets0.50

Recency Weighting

Under 30 days1.0
30 - 90 days0.9
90 - 180 days0.8
6 - 12 months0.7
1 - 2 years0.5
2 - 5 years0.3
5+ years0.2
05 · PEP Context

Politically Exposed Persons as Review Context

PEP signals can represent elevated risk due to political connections and exposure to bribery, corruption, and illicit financial flows. They should inform review, not replace a compliance decision.

PEP context is not part of default screening. Where it is enabled for a pilot, matches are informational review aids
Useful PEP context includes political position, country, term dates, and alternative name spellings, where the source provides them
PEP matches are informational signals alongside sanctions and adverse media context, not compliance decisions
06 · Categories

Adverse Media Risk Categories

Each indexed item is assigned one category and one severity for prioritized review.

Fraud
Sanctions Evasion
Money Laundering
Bribery
Corruption
Export Violations
Terrorism
Tax Evasion
Insider Trading
Regulatory Action
Environmental Crime
Human Trafficking
Cybercrime
Organized Crime
Other

Severity Levels

Severity is assigned by AI, guided by these definitions.

CriticalConfirmed conviction, active sanctions, terrorism, or a major enforcement action
HighIndictment, formal charges, or significant regulatory action
MediumInvestigation, settlement, or minor violations
LowAllegations only, or minor compliance issues
07 · Operations

Building an Operational Monitoring Program

1

Load Your Roster

Import third parties, companies or individuals, as a CSV file or as JSON through the application. Each entity gets a risk tier (low, standard, elevated, or high) and a review cadence (monthly, quarterly, semi-annual, or annual).

2

Run Monitoring Cycles

A daily job adds new enforcement and news items to a shared index. Your team starts monitoring runs against the roster, and each run checks entities against restricted-party lists, that index, and live enforcement and news lookups. Review cadences mark when each entity is next due.

3

Use AI to Triage, People to Decide

AI-assisted triage sets aside low-confidence items and brings ambiguous or serious ones to your compliance team with a summary, a rationale, and a link to the source.

4

Record Decisions and Attestations

Choose a review type: quarterly, annual, ad hoc, or event-triggered. Reviewers can record a decision and notes for each third party. A cycle is completed only after a reviewer and an approver attest its latest monitoring run. Pilot deliverables can include a PDF review report.

08 · SecurePoint USA

SecurePoint USA Screening Architecture

Named Enforcement and News Sources

DOJ press releases, SEC EDGAR filings, FinCEN and FCA enforcement publications, OpenSanctions wanted-person datasets, and English-language news search. A daily job adds new items to a shared index and skips items already indexed.

AI Classification with Source Links

AI identifies the primary named party in each item and records a category, a severity, a confidence score, and a short rationale alongside the source link.

Sanctions Screening with Shadow Context

A monitoring run pairs restricted-party screening with adverse media context. By default, adverse media and PEP signals are informational: they do not change screening risk scores or block access. Reviewers record decisions per third party.

Review Lifecycle and Attestations

Reviews move through draft, in progress, pending adjudication, and completed. A cycle is completed only when a reviewer and an approver attest its latest run, and a new run needs new attestations. They must be two different people unless SecurePoint enables single-signer attestation for an organization with one compliance signer, and the record and the PDF report show when that exception was used.

Roster-Based Monitoring Cycles

Assign a risk tier and review cadence to each entity. Operators run monitoring cycles against a shared index that a daily job keeps current. When a run surfaces entities that need attention, compliance contacts receive one summary email for that run.

Look Beyond
the Sanctions Lists

Sanctions lists are reactive. Adverse media can surface early warning context. Screen enforcement sources with AI-assisted triage and human review.

Spend reviewer time on the items that need judgment.

Frequently asked questions

Does adverse-media screening block a visit or a transaction in SecurePoint?

No. By default, adverse-media screening runs in a monitoring capacity. It does not block a visit, hold a transaction, or drive an adjudication decision on its own. Sanctions and restricted-party screening are the controls that gate access.

Is adverse-media screening generally available?

It is offered as a controlled pilot rather than general self-service. A pilot runs against your own roster so you can see the report format and the review workflow before committing to anything longer term.

Does adverse media replace sanctions screening?

No. Restricted-party screening answers a legal question about whether a party is listed, or owned by listed persons. Adverse media is contextual information that may inform a human review. They are different controls carrying different weight, and they should not be substituted for one another.

Who decides what an adverse-media finding means?

Automated triage proposes and people decide. Triage sorts and summarizes items and gives each monitored third party a provisional triage state, labeled as automated. A reviewer can record a decision and rationale for any third party, and a review cycle is completed only after a reviewer and an approver attest its latest monitoring run, including a run with no findings.

Can adverse-media findings be exported as evidence?

Findings, reviewer decisions, attestations, and review activity are stored with the case record. Attestations and decisions are append-only, so application users cannot edit or delete them, and a finding keeps the source evidence its run recorded. Audit entries are kept rather than overwritten. Confirm what a specific pilot scope produces before relying on it for a particular review.

Informational only. This whitepaper is provided for general informational purposes only and does not constitute legal, regulatory, or compliance advice. It is not a substitute for review by qualified sanctions or AML counsel familiar with your program.

Source-credibility weights, recency curves, and triage examples describe SecurePoint USA program guidance as of the “Last reviewed” date in the PDF version. Actual outcomes depend on configuration, enabled sources, and roster composition. © 2026 SecurePoint USA. All rights reserved.

Adverse Media Screening Best Practices | SecurePoint USA