An adverse media false positive is an alert generated when the underlying article, match, or signal has nothing to do with the flagged person or entity, or isn’t relevant to the compliance program reviewing it.
Screening programs search millions of articles across hundreds of thousands of publishers, which means some degree of irrelevant matching is built into the process.
Independent analysis from Datos Insights puts false positive rates in AML screening at 90 to 95%, and adverse media generates some of the highest volumes of any screening type. At that rate, the drain on analyst capacity is significant, and alerts that warrant attention get less of it.
This guide explains what drives false positives in adverse media and what compliance teams can do to bring them under control.
Key takeaways:
- Different false positive types have different root causes and fixes
Identity, context, materiality, and temporal false positives each originate at a different stage of the screening process. Addressing the wrong type wastes effort without reducing alert volume. - Customer data quality at onboarding determines alert volume throughout the relationship
Name-only matching is the single biggest source of identity false positives. Capturing secondary identifiers upfront costs less than remediating alert queues downstream. - Over-suppression carries the same regulatory risk as under-screening
Regulators expect documented rationale for every discounted alert, not just evidence that screening ran. Programs that clear alerts to manage volume without recording why they did so remain exposed. - Reduction requires action at the data, configuration, and technology levels together
Each layer tackles a different source of false positive volume, and addressing one without the others produces only limited, temporary improvement. - Sigma360 narrows the alert queue before analysts are involved
Entity resolution, materiality scoring, and event consolidation reduce irrelevant volume at the point of generation, so analyst time goes to alerts that warrant a decision.
How does an adverse media false positive happen?
Adverse media screening searches public sources, including news outlets, regulatory filings, court records, and investigative reports, for negative information about customers, counterparties, and beneficial owners.
When the system returns a hit, an analyst reviews it to determine whether it represents a genuine risk.
A hit becomes a false positive in one of three ways:
- The right person appears but in an unrelated context, such as a quote from an industry panel or a reference in a background piece.
- The coverage concerns a different individual who shares the same name.
- The event is genuine adverse media but too old, too minor, or too far outside the program’s scope.
In each case, the alert still requires full review before it can be dismissed.
As news volumes grow and screening programs extend to more entities and data sources, the operational burden of managing false positive volume has become one of the most pressing challenges in adverse media compliance.
The four types of adverse media false positives
Most compliance teams treat false positives as a single problem, but each type has a different root cause, and targeting the wrong one leaves alert volume unchanged.
1. Identity false positives
Identity false positives occur when the screening system returns an article about a different person or entity that shares the same name, or has a name similar enough to trigger a match.
Common names, particularly in markets with limited naming diversity, generate high volumes of irrelevant hits. For instance, a search for “John Lee” in a global screening program will return hundreds of unrelated individuals.
Without secondary identifiers such as date of birth, nationality, or address to confirm or rule out identity, every one of those hits ends up in front of an analyst.
This is the most common source of false positive volume in adverse media programs and the one most directly tied to data quality during onboarding.
2. Context false positives
Context false positives occur when the right person or entity appears in an article, but their mention has nothing to do with financial crime risk.
Common examples include:
- A customer named as a fraud prevention expert
- A company referenced as a victim rather than a perpetrator
- An individual quoted as a government official commenting on a criminal case
Without natural language processing (NLP) that reads the role a subject plays in an article, these hits are indistinguishable from genuine alerts until an analyst reads the flagged text.
3. Materiality false positives
Materiality false positives occur when the right person appears in the right kind of article, but the risk it describes does not meet the threshold the program is designed to catch. A decade-old civil dispute or a regulatory notice from an out-of-scope jurisdiction are common examples.
Programs that apply the same materiality standard across all customer types and risk categories generate significant alert volume from events that should never reach an analyst.
Risk-based filtering, configured by risk type, geography, and severity, keeps review effort on material risk rather than administrative volume.
4. Temporal false positives
Temporal false positives occur when old adverse media events resurface in new coverage (anniversary pieces, retrospective reporting, or new articles citing old facts), and the system treats them as fresh alerts.
Programs that re-screen the full customer base at each periodic cycle are especially exposed to this. Two controls address it at different levels:
- Deduplication logic recognizes previously reviewed events and suppresses re-alerting on the same underlying facts.
- Perpetual KYC tracks risk signals in real time, flagging only genuine new developments so historical coverage never re-enters the queue.

Why false positives in adverse media are so common
False positives are a data quality problem, and one that configuration issues make considerably worse.
Poor customer data at onboarding
Incomplete customer data is the most common upstream cause of false positive volume. When records lack date of birth, nationality, or a consistent name format, the screening engine has nothing to anchor a match against beyond the name itself.
The effects flow downstream into every stage of the screening process:
- Irrelevant hits reach the analyst’s queue at higher volume.
- Secondary identifier checks happen manually rather than automatically.
- Remediation at the alert level costs more than prevention at onboarding would.
Overly broad matching logic
Many screening tools apply conservative, broad name-matching rules by default, catching every possible name variation, including those that bear only a passing resemblance to the target.
This creates an alert queue that grows faster than teams can clear it, particularly when matching rules have not been recalibrated since initial deployment.
The underlying logic is sound (a threshold set too tight risks missing a genuine match), but default settings are rarely revisited once a program is live.
Insufficient risk-based filtering
When a program applies the same screening depth to a low-risk retail customer and a politically exposed person (PEP), the alert burden it generates has no relationship to actual risk distribution. The highest volume ends up concentrated on the segment least likely to produce a genuine match.
Unstructured data at scale
Adverse media arrives in free-text form across millions of sources, unlike the structured fields of a sanctions list or PEP database.
To a keyword-based system, a FinCEN enforcement notice and a local newspaper opinion column mentioning the same name are indistinguishable. Both generate an alert, regardless of source credibility or context.
The over-suppression risk
Compliance teams spend most of their time fighting alert volume. The regulatory risk of suppressing too aggressively (and missing genuine risk in the process) is equally serious but far less visible.
When analysts are overwhelmed by false positive volume, informal workarounds develop and accumulate over time:
- Alerts get cleared faster than the evidence warrants
- Patterns get assumed without verification against the source
- Thresholds get raised to reduce the queue rather than to reflect genuine risk appetite
The Wolfsberg Group’s Negative News Screening guidance is explicit on this point: Materiality and relevance filters should reduce unnecessary review burden, but institutions must be able to demonstrate that discounted alerts were reviewed for defensible reasons, not merely cleared to manage volume.
FATF’s risk-based approach guidance treats adverse media screening as a substantive control. A program that technically runs screening but consistently discounts alerts without documented rationale does not satisfy that obligation.
Read more: Is Adverse Media Screening a Regulatory Requirement or Just Best Practice?
What false positives cost compliance teams
False positive volume carries costs that extend well beyond analyst hours. They fall into three categories:
- Direct labor is the most visible cost: Each alert requires review, a disposition decision, and documentation (typically between 15 and 30 minutes per alert for a trained analyst). At a false positive rate of 90% across a program processing 1,000 alerts per month, that is up to 450 hours of analyst time spent on review with no investigative outcome.
- Operational impact is less obvious and harder to quantify: Alert fatigue sets in quickly at high volumes, and teams that cannot absorb the load tend to hire more analysts instead of fixing the underlying configuration problem. This adds headcount without reducing the volume.
- Regulatory exposure is the cost that rarely appears in budgets: Enforcement actions in the adverse media space consistently cite poor monitoring and insufficient documentation of risk decisions. Programs that cannot demonstrate how alerts were reviewed and discounted carry exposure that only surfaces when regulators come looking.
How to reduce false positives in adverse media
False positive volume has more than one root cause, and no single intervention fixes it. The sections below cover what compliance teams can address at the data, configuration, and technology levels.
Increase data quality
Fixing customer data issues before screening begins reduces alert volume more effectively than any downstream tuning.
Steps to address at onboarding:
- Capture secondary identifiers (including date of birth, nationality, and registered address) at onboarding for every customer, not just high-risk ones.
- Validate name formats against corporate registry data for entity customers before screening.
- Maintain a consistent transliteration standard for non-Latin script names across your customer records.
- Review and clean existing customer data regularly as part of periodic KYC refresh.
Adjust program configuration
Configuration determines which alerts reach analysts and how they are prioritized. Programs that treat all customers and all risk types the same way generate alert volume that doesn’t reflect actual risk.
Key configuration decisions:
- Apply risk-based screening depth, with higher coverage and lower match thresholds for PEPs, high-net-worth individuals, and customers in elevated-risk jurisdictions, and lighter-touch screening for verified, low-risk retail customers.
- Define materiality thresholds by risk category, specifying which types of adverse media are in scope for your program and which are not, and document those definitions.
- Build a suppression rationale library, a documented set of approved reasons for discounting common false positive patterns, so analysts can apply consistent standards instead of individual judgment.
- Set deduplication rules to prevent the same underlying event from generating repeated alerts across multiple coverage cycles.
Use the right technology
The right technology applies entity resolution, contextual classification, and risk scoring before alerts reach analysts. This reduces the volume that requires human review without decreasing coverage of genuine risk.
Capabilities to prioritize:
- Use entity resolution models that cross-reference secondary identifiers, not name matching alone.
- Implement NLP-based context classification that distinguishes subject from reference mentions within articles.
- Configure risk scoring at the article level so materiality can be assessed automatically.
- Apply event consolidation logic that groups related articles about the same underlying event into a single alert instead of generating separate hits for each piece of coverage.
Platforms built for AML investigations apply all of these layers in a single workflow. The filtering that happens before an alert is created reduces the review burden without requiring analysts to make more dismissal decisions.

The audit trail requirement
The programs that struggle most during regulatory examinations are not the ones with high false positive rates but the ones that cleared them without any recorded justification.
A note that says “cleared, no match” gives a regulator no basis for assessment. Specifying that the alert was dismissed because the date of birth and nationality did not match, and the subject was confirmed as a different individual based on [source], is what defensible documentation actually looks like.
Getting the documentation right has three practical benefits:
- Audit trails hold up under regulatory scrutiny because every dismissal has a recorded rationale.
- Configuration improvements become data-driven, since disposition records show which false positive types are most common.
- Escalation decisions become defensible, and when an analyst escalates a hit to enhanced due diligence, the disposition trail shows the analytical path that led to that escalation.
Watch: The Future of Generative AI in Compliance
How Sigma360 addresses adverse media false positives
False positive volume builds up at three points: when articles are ingested, when entities are matched, and when analysts review hits. Sigma360’s risk intelligence platform addresses each one:

- Before an alert is created: Sigma360 applies named entity recognition to identify whether the screened entity is the subject of an article or merely mentioned in it, filtering incidental references at source.
- Before an alert reaches an analyst: The platform applies materiality scoring by risk type, geography, and severity, consolidating related articles into a single risk event and producing a structured summary via the Adverse Media Agent.
- At the point of review: The AI Investigator Agent automatically clears alerts where the mismatch between the screened entity and the article subject can be confirmed through secondary identifiers, reducing the volume of manual match reviews by up to 90%.
The result is a program that grows without scaling headcount, with analyst attention concentrated on alerts that are worth their time.
If false positive volume is eating into your program’s capacity to investigate real threats, explore Sigma360’s adverse media screening or try HyperScan to screen entities and see the difference in match quality firsthand.
Read more: How a Top 10 Global Financial Institution Transformed Adverse Media Screening with AI
FAQ
Is it possible to reduce false positives without missing real risk?
Yes, but it requires calibration rather than just raising thresholds. The most effective programs combine secondary identifier matching, materiality scoring, and documented suppression criteria so that alert volume drops at the source, not through undocumented clearances.
What is the difference between a false positive and a false negative in adverse media?
A false positive flags someone when no genuine risk exists, while a false negative misses a genuine risk entirely. False negatives are harder to catch because they produce no alert, which is why threshold changes should always be tested and documented before deployment.
Does adverse media screening cover existing customers or just new ones?
It covers both. FATF guidance and most national AML frameworks require ongoing monitoring throughout the customer lifecycle, with frequency and depth tiered to each customer’s risk level.
Which sources tend to generate the most false positives?
Broad news aggregators with no editorial filtering and social media content without entity verification are the biggest contributors. Programs that screen against structured, pre-filtered databases with consistent source quality typically see lower alert volumes for the same coverage depth.
How often should adverse media screening thresholds be reviewed?
Thresholds should be reviewed at minimum annually, and whenever customer volumes, risk appetite, or regulatory guidance changes significantly. Programs that track false positive rates against true positive conversion rates are better placed to catch calibration drift before a regulator does.
