Who this is for: MLROs, compliance officers and financial crime leads at FCA regulated firms, including insurers, intermediaries and Lloyd’s managing agents. It explains where the adverse media obligation actually comes from, because it is not where most people look. It is general information, not legal advice.
Last reviewed 23 August 2026.
This is worth knowing before anything else, and it explains why practice varies so widely between firms.
Neither the FCA Handbook nor the Money Laundering Regulations 2017 contain a provision requiring adverse media screening by name. No regulation says do it, sets a frequency, or defines what counts.
The obligation is real, but it is derived. It falls out of three separate requirements that each assume you know things about your customer which only external information can tell you. Firms that go looking for the rule, fail to find it, and conclude the exercise is discretionary have made a mistake a supervisor will not accept.
Regulation 33(1) of the Money Laundering Regulations 2017 requires enhanced customer due diligence in defined situations, including:
Where it applies, regulation 33(3A) requires measures including:
Regulation 33(5) adds that a firm may seek independent verification, build an understanding of the customer’s background and ownership, and increase monitoring.
Additional information on the customer, and source of wealth, cannot be satisfied from the customer’s own file. That is the hook. The regulation requires you to know things that in practice only external published information will tell you.
Regulation 28(11) requires:
The second limb is where adverse media actually lives. A risk profile built at onboarding and never revisited is not up to date. If a customer is charged with fraud in year three, a file that still reads low risk is not current, and the regulation requires it to be.
Regulation 33(1)(a) triggers enhanced due diligence for any case the firm itself identifies as high risk. A firm that never looks at public information has quietly narrowed the set of cases it is capable of identifying as high risk. That gap is self inflicted and it is visible in a supervisory review.
The FCA published FG25/3, Treatment of politically exposed persons, on 7 July 2025, revised 15 July 2025, updating guidance first issued as FG17/6 in July 2017. Five points are directly relevant.
Domestic PEPs start lower. “The starting point for the risk assessment for a domestic PEP or their family members and known close associates is that they present a lower level of risk than a non-domestic PEP.”
Public information sources are named. The FCA points firms to “public domain information such as websites of parliaments and governments, reliable news sources and work by reputable pressure groups.”
Commercial databases are optional, and you must understand them. “In line with the firm’s nature and size, it can choose, but is not required, to use commercial databases that contain lists of PEPs… A firm doing so would need to understand how such databases are populated.”
That last sentence is a vendor due diligence obligation in a single line. If you cannot explain how your screening provider builds its data, you have not met it.
Proportionality is explicit. “Firms should only take additional measures beyond this Guidance where: This is justified on the basis of their risk assessment.” The FCA is pushing back on blanket escalation as firmly as on under screening.
Declassification has a floor. “If a person who is a PEP no longer has a prominent public function, that person should continue to be subject to risk-based enhanced due diligence for a period of at least 12 months after the date they ceased to hold that public function.”
Because the obligation is derived rather than prescribed, there is no compliant configuration to copy. There are, however, four failure patterns that recur.
| Failure | Why it fails |
|---|---|
| Screening once at onboarding | Regulation 28(11)(b) requires information to be kept up to date. A single check at day one cannot satisfy a continuing obligation. |
| Treating a database hit as a decision | A hit is an input. The regulation requires the firm to reach and record a view. An unexamined flag is not due diligence. |
| Escalating everything | FG25/3 is explicit that additional measures need justification from the risk assessment. Blanket escalation is a finding in its own right, and it buries the cases that matter. |
| Not knowing how the data is built | FG25/3 requires a firm using a commercial database to understand how it is populated. Very few firms can answer that question about their own provider. |
The practical distinctions that separate a usable adverse media process from a noisy one are relevance, meaning is the subject the actor or merely mentioned, recency, severity, and whether the allegation is connected to financial crime at all. A twenty year old civil dispute and a current fraud charge are not the same signal and should not arrive in the same queue at the same priority.
Not by that name. Neither the FCA Handbook nor the Money Laundering Regulations 2017 contain a provision requiring adverse media screening as such. The obligation is derived from regulation 33 on enhanced due diligence, which requires additional information on the customer and on source of wealth, from regulation 28(11)(b), which requires customer due diligence information to be kept up to date, and from the firm’s own risk assessment under regulation 33(1)(a).
Under regulation 33(1), in any case the firm identifies as high risk, where a person is established in a high risk third country subject to a FATF call for action, in correspondent relationships, where the customer is a PEP or a family member or known close associate of one, where false or stolen identification has been provided, where transactions are unusually complex or unusually large or follow an unusual pattern or lack apparent economic or legal purpose, and in any other higher risk case.
Regulation 33(3A) requires obtaining additional information on the customer and the beneficial owner, additional information on the intended nature of the business relationship, information on the source of funds and source of wealth, information on the reasons for the transactions, senior management approval for establishing or continuing the relationship, and enhanced ongoing monitoring.
No. FG25/3 states that a firm can choose, but is not required, to use commercial databases containing lists of PEPs, in line with the firm’s nature and size. It adds that a firm doing so would need to understand how such databases are populated. That is a vendor due diligence obligation: if you cannot explain how your provider builds its data, you have not discharged it.
No. FG25/3 states that the starting point for the risk assessment of a domestic PEP, or their family members and known close associates, is that they present a lower level of risk than a non-domestic PEP. The FCA also states that firms should only take additional measures beyond the guidance where justified by their risk assessment.
FG25/3 states that where a person no longer holds a prominent public function they should continue to be subject to risk based enhanced due diligence for a period of at least 12 months after the date they ceased to hold that function. That is a floor, not a deadline, and the assessment remains risk based after it.
No. Regulation 28(11)(b) requires reviews of existing records and keeping customer due diligence information up to date. A profile built at onboarding and never revisited does not meet that. The obligation is continuing, and the trigger for revisiting it is a change in the information, not a calendar date.
Global RADAR provides adverse media screening that ranks by recency, severity and how directly the subject is involved, rather than returning every mention of a name. Every disposal carries a reason code, a rationale and a confidence score, and the record is exportable, which is what turns a database hit into a documented decision.
On the FCA’s point about understanding how a database is populated, we will answer that directly rather than treat it as commercially sensitive. Our data provenance, the split between official lists ingested from the issuing authority and commercially licensed data, our model governance and our validation approach are all published. Suppliers are named to clients under mutual NDA as part of vendor due diligence.
Read the data provenance and security position, the alert clearing methodology and model governance, or the UK sanctions and OFSI obligations.