How to Reduce False Positives in AML and Adverse Media Screening

Ask a compliance analyst what consumes their day, and the answer is rarely "investigating financial crime." It is clearing alerts that never should have fired: the customer who shares a name with a sanctioned individual, the news article about a different company entirely, the passing mention with no bearing on risk. False positives are the single largest operational cost in screening, and in the run-up to the EU's new AML framework, they are also becoming a supervisory concern: a programme drowning in noise cannot demonstrate that it manages risk effectively.

This guide covers what false positives are, why screening produces so many of them, what they actually cost, and the practical levers that reduce them without weakening your risk coverage.

How to Reduce False Positives in AML and Adverse Media Screening

What is a false positive in AML screening?

A false positive is an alert flagged by a screening system that, on investigation, turns out not to represent genuine risk: the flagged entity is not actually the sanctioned party, or the adverse media hit is not actually about your customer, or the event is real but has no material bearing on the relationship. Its counterpart, the false negative, is the dangerous one: genuine risk the system fails to flag. Every screening programme lives on the trade-off between the two, and reducing false positives only counts as progress if false negatives do not rise with it.

Why screening produces so many false positives

False positives are not random noise; they have identifiable causes:

Name matching without identity resolution. Common names, transliteration from non-Latin scripts, and aggressive fuzzy matching mean one sanctioned “Mohammed Khan” can generate alerts against thousands of innocent ones. Matching on names alone, without secondary identifiers such as date of birth, jurisdiction, or corporate registration data, guarantees volume.

Keyword-based adverse media screening. Legacy negative news screening searches for a company name near words like “fraud” or “corruption.” It cannot tell whether the company is the perpetrator, the victim, the prosecutor, or an analyst quoted in paragraph nine. Every mention becomes an alert.

No materiality assessment. Even a correctly matched, genuinely negative article may not matter: a decades-old resolved dispute, a trivial regulatory footnote, an event at an unrelated namesake subsidiary. Systems that do not ask “does this event meaningfully affect this entity?” pass every hit to a human.

Over-broad calibration. Screening every customer segment at maximum sensitivity feels safe and is the opposite: it buries the alerts that matter. The risk-based approach required under EU AML rules means measures proportionate to assessed risk: enhanced scrutiny where risk is higher, proportionate (but never absent) screening where it is lower. Applied to calibration, that legal principle is also what keeps alert queues meaningful.

Stale or duplicated data. Poorly maintained lists, duplicate records, and repeated syndicated copies of the same news story multiply alerts without adding information.

  • 90 to 95% of alerts from traditional monitoring systems are false positives. McKinsey reports that at most banks more than 90% of transaction monitoring alerts are false positives, only one or two alerts per hundred are typically acted upon, and even among alerts that lead to a suspicious activity report, 80 to 90% see no further action.  
  • Sanctions screening runs at up to 90% false positives according to ACAMS estimates, driven by common names, transliteration, and name-only matching. 
  • The cost per alert is heavy: US regulators estimate around two hours to file a suspicious activity report, while independent studies put the full burden at up to 22 hours per alert once investigation, documentation, and review are counted, contributing to global AML compliance costs estimated above $274 billion annually. 
  • AI adoption is shifting the curve: the EY 2025 Nordic Transaction Monitoring Survey found 30% of Nordic banks had implemented AI in their transaction monitoring, with 75% planning further investment.
  • Regulatory tolerance is ending. Under AMLA’s direct supervision model, the question shifts from whether an alert fired to whether the firm can show defensible reasoning for escalating or dismissing it. A 95% noise floor stops being an accepted cost of coverage and starts looking like a control deficiency. 
  • In Business Radar’s own data, the materiality flag automatically excludes 62% of irrelevant hits before they reach an analyst, without reducing risk coverage.

The pattern across all of these numbers: false positives are not an edge problem. They are the structural condition of legacy, rules-based screening, and fixing them is now both an efficiency play and a supervisory expectation.

What false positives actually cost

The obvious cost is analyst hours: in many programmes, well over 90% of alerts are cleared as irrelevant, which means most of the compliance budget is spent proving the absence of risk. The less obvious costs are worse.

The first is dropout. “If your engine is not effective enough and you have a lot of false positives, the client drops out of the automated flow and into a manual process. It takes longer, and onboarding stalls,” notes an ESG risk expert who has led screening integration at a major European bank. Adverse media screening in particular tends to become the bottleneck in the client journey, and every dropout is friction the business side feels directly.

The second is the volume multiplier. Onboarding is a one-off event, but monitoring runs against the full client base, permanently. An engine that produces noise does not add cost; it multiplies it across every entity in the portfolio, every day. For a bank monitoring hundreds of thousands of business clients, a small inefficiency per entity becomes an enormous operational burden in aggregate.

And there is the quality cost. Alert fatigue degrades judgement, and the true positive hiding in a queue of hundreds of false ones gets the same thirty-second glance as its neighbours. Supervisors increasingly read a high false positive rate not as diligence but as a poorly calibrated programme, precisely as the EU’s incoming framework raises the bar for demonstrating that risk-based decisions are justified and traceable.

How to reduce false positives without missing real risk

1. Resolve entities, not names. Match against identifiers beyond the name: registration numbers, jurisdictions, dates of birth, addresses, and corporate structure. Knowing that a counterparty’s trade name, legal name, and parent all resolve to one entity eliminates whole classes of duplicate and mistaken-identity alerts, and ownership data makes name-sharing coincidences distinguishable from genuine connections.

2. Validate context with AI, then keep it explainable. Modern language models can read an article the way an analyst would: is this actually our entity, is it the subject or a bystander, is the event negative and relevant? Automating that first read removes the bulk of irrelevant hits. The condition is explainability: every automated exclusion and every surviving alert must be traceable to its source, or the efficiency gain becomes an audit problem.

3. Assess materiality before alerting. The question is not only “is this hit correct?” but “does this event meaningfully affect this entity?” Materiality assessment, applied before an alert reaches a human, converts a feed of mentions into a feed of signals.

4. Calibrate by risk, not by fear. Apply enhanced sensitivity where the risk assessment says it belongs (high-risk jurisdictions, complex ownership, exposed sectors) and proportionate settings elsewhere. “If you can tune your thresholds and your topics to your actual risk exposure, then it all fits together. That is when screening becomes effective,” as the same expert puts it: a portfolio of EU food companies does not need the same category set as one with suppliers in high-risk sourcing markets, and screening a topic where your exposure is genuinely limited produces only noise. Document the rationale; a defensible calibration is a feature of a mature programme, not a shortcut.

5. Deduplicate at the event level. One incident reported by forty outlets is one event. Grouping coverage into events, with a timeline showing how the story develops, replaces forty alerts with one investigation.

6. Measure both error types. Track your false positive rate and test for false negatives (through sampling, back-testing, and known-case replays) so that tuning demonstrably reduces noise without opening gaps. This evidence is exactly what the incoming EU supervisory regime will ask for.

False positives in fraud detection: the same problem, different system

The fraud world has its own version of this problem. In fraud detection and payment screening, a false positive is a legitimate transaction blocked or a genuine customer declined, and the cost lands on revenue and customer experience rather than on analyst queues. The mechanics differ (transaction rules and behavioural models instead of name matching and news screening), but the principle is identical: false positive reduction that comes from crude threshold-raising trades one error type for the other, while reduction built on better context (who is this customer, what is normal for them) improves both. For counterparty-level fraud risk, the AML-style levers above apply directly: entity resolution, ownership context, and adverse media on the counterparty catch the fake supplier or shell-company customer that transaction rules never see.

How Business Radar reduces false positives

Business Radar was built around the conviction that an alert should be worth an analyst’s time. AI validation reads every hit in context, checking that the entity matches (including trade names and ownership links via Dun & Bradstreet data) and that the content is genuinely adverse. The materiality flag then assesses whether the event meaningfully affects the monitored entity, and it is this materiality assessment that automatically excludes 62% of irrelevant hits before they ever reach an analyst. The events timeline groups related coverage so one incident is one investigation, not forty alerts. Analysts can give feedback on every output, and that feedback flows back into the models, which is why the exclusion rate improves over time rather than plateauing. Every exclusion and every signal remains explainable, time-stamped, and linked to its source, which is what keeps a leaner alert queue defensible in front of auditors and supervisors.

The results compound: risk teams report a 32% average efficiency increase over traditional screening software, and 9 out of 10 compliance teams find critical risks that legacy screening missed entirely, because analysts finally have the time to investigate what matters.

See it in action

Frequently asked questions

What is a false positive in screening? A false positive is an alert that, on investigation, does not represent genuine risk: a mistaken identity match, an irrelevant news mention, or an immaterial event.

What causes false positives in AML screening? The main causes are name-only matching without secondary identifiers, keyword-based adverse media screening without context, missing materiality assessment, over-broad calibration, and duplicated data.

What is a good false positive rate? There is no universal benchmark; supervisors care about whether the rate is understood, justified by your risk assessment, and improving. A programme where nearly all alerts are cleared as irrelevant signals poor calibration rather than diligence.

Can reducing false positives increase false negatives? Yes, if done crudely (for example, simply raising match thresholds). Sustainable reduction comes from better entity resolution, context validation, and materiality assessment, verified by testing that real risks are still caught.

What is a false positive in fraud detection? A legitimate transaction or customer incorrectly flagged as fraudulent, for example a blocked payment or a declined onboarding. As in AML screening, sustainable false positive reduction in fraud detection comes from better context rather than looser rules.

Get in touch met us naar discuss hoe Business Radar kan help uw bedrijfsvoering make meer profound risico decisions