Adverse media · GuideLast reviewed 2026-09-04
    Sanctions News Desk

    "Five to ten years" is a vendor default, not a rule. Here is how to set a lookback you can defend

    "Five to ten years" circulates in vendor content as though a regulator wrote it. No EU instrument states a lookback period for adverse media, and the ones that come closest fix something else entirely: how often you must refresh a file, how long you must keep it, and how you must treat an allegation that never became a conviction. So the window is a policy parameter you have to argue for, and what follows is the argument we would put in a file, worked end to end on one invented subject.

    Published By ScreenVeritAI Team
    AT A GLANCE
    Lookback period in EU AML law
    None stated
    Neither Regulation (EU) 2024/1624 nor the EBA ML/TF Risk Factors Guidelines names a period. The Guidelines judge an allegation on source quality, independence and persistence of reporting — not on age.
    Maximum interval between CDD updates
    1 year higher risk, 5 years otherwise
    Regulation (EU) 2024/1624, Article 26(2): the period between updates depends on risk and shall not in any case exceed 1 year for higher-risk customers under enhanced due diligence, or 5 years for all others. Applies from 10 July 2027.
    Retention of the record you produce
    5 years, plus up to 5 on demand
    Article 77(3): 5 years from termination of the relationship, the occasional transaction, or refusal; personal data deleted on expiry; competent authorities may require a further period not exceeding 5 years, case by case.
    Floor for a person who ceases to be a PEP
    12 months, and longer while risk persists
    Article 45(2): enhanced measures apply until the risks no longer exist, but in any case for not less than 12 months after the person ceased to hold the prominent public function.
    Cited URLs that stop resolving
    50% in US Supreme Court opinions
    Zittrain, Albert & Lessig (2014) found that more than 70% of URLs in the Harvard Law Review and other journals, and 50% in US Supreme Court opinions, no longer link to the originally cited information.

    Short answer

    SUMMARY

    EU law fixes the cadence of review, the retention of the record and the treatment of an allegation — never the depth of the search. No instrument states a lookback period for adverse media and no supervisor publishes one, so the window is your policy parameter, and the only test that matters is whether you can write down why it is what it is. A defensible default: three years for a standard-risk customer with no control role, the full life of the relationship with a five-year floor wherever enhanced due diligence applies, and unbounded for PEPs and control persons in higher-risk structures. Then handle the three things that break historical searches: link rot, allegations that never became convictions, and the point where a deletion request meets a retention duty.

    What EU law fixes, and what it leaves open

    LAW

    Regulation (EU) 2024/1624 — the AML Regulation, directly applicable from 10 July 2027 under its Article 90 — never uses the phrase "adverse media". It fixes four adjacent things instead.

    ProvisionWhat it fixesNumber
    Article 26(2)Maximum interval between CDD updates1 year for higher-risk customers under enhanced due diligence; 5 years for all others
    Article 45(2)Enhanced measures after a PEP leaves officeuntil the risk ceases, and not less than 12 months
    Article 77(3)Retention of the record5 years from termination, occasional transaction or refusal; personal data deleted on expiry; competent authorities may require up to 5 more, case by case
    Article 78Ability to answer an FIU enquirycovering the five-year period prior to the enquiry

    Article 40 of Directive (EU) 2015/849 is the predecessor of Article 77 — the Regulation's own Annex VI correlation table says so — and national implementations of it govern until July 2027.

    Two further provisions decide how a finding may be handled, and they are the ones most vendor content skips. Article 76(2)(b) requires that data of this kind originate from reliable sources and be accurate and up to date. Article 76(3)(b) requires procedures that allow "the distinction, in the processing of such data, between allegations, investigations, proceedings and convictions", taking into account the right to a fair trial, the right of defence and the presumption of innocence.

    The nearest thing to EU guidance on adverse media itself is the EBA ML/TF Risk Factors Guidelines (EBA/GL/2021/02, consolidated 1 March 2021), which list adverse media reports as a customer-reputation risk factor and then say how to weigh them: credibility is determined "on the basis of the quality and independence of the source of the data and the persistence of reporting of these allegations". And, in a sentence worth pinning to the wall: firms should note that the absence of criminal convictions alone may not be sufficient to dismiss allegations of wrongdoing.

    Age appears nowhere in that test.

    There is one place where EU law does require a public-information reputation check by name, and it is narrow: for cross-border correspondent relationships, Articles 36 and 37 AMLR require the institution to determine the respondent's reputation "from publicly available information" before entering into the relationship. Everywhere else, adverse media is an inference from the risk-based approach rather than a stated obligation — which is exactly why the window has to be argued rather than cited.

    "Five to ten years" comes from vendor pages, repeated until it acquired the grammar of a rule. Checked on 4 September 2026, the pages ranking for adverse media historical data carry the range without citing an EU instrument, an EBA guideline or a national supervisor for it. It is not wrong as a starting point. It is unusable as a justification, because a supervisor asking "why ten years?" gets the answer "a vendor's default".

    The decision tree

    FRAMEWORK

    Three inputs, one output, and a sentence you commit to the file.

    Input 1 — risk tier, from your own customer risk assessment. Standard; higher risk with enhanced due diligence under Section 4 of Chapter III; PEP, family member or close associate.

    Input 2 — entity type, because exposure is not symmetric. A retail customer with no control role; a natural person exercising control (director, authorised signatory, beneficial owner); an operating legal entity; a holding or arrangement whose economic purpose is not obvious from its filings.

    Input 3 — jurisdiction of the reporting, not only of the subject. An EU member state with searchable, archived press and published court reporting is not the same information environment as a country where the online record starts in 2015, or one where reporting on certain subjects does not appear at all.

    Risk tierEntity typeReporting environmentWindowThe line you write in the file
    StandardNatural person, no control roleEU/EEA, well archived3 years"Standard risk, no control role, EU press archive complete for the period. Three years covers the interval since the last review with margin."
    StandardLegal entity, operatingEU/EEA5 years"Aligned to the Article 26(2)(b) maximum review interval, so no gap can open between two reviews."
    StandardAnyShort or constrained online archive5 years + named gap"Extended to five years and recorded that the local archive does not reach before 2016; absence of findings before that date is not evidence of absence."
    Higher risk (EDD)Natural person with controlAnyFull relationship, floor 5 years"EDD applies; adverse media is one of the Article 34(4) measures relied on. Reviewed annually per Article 26(2)(a)."
    Higher risk (EDD)Legal entity or arrangementAnyFull relationship + pre-incorporation history of the controllers"The entity is three years old; the search covers the controllers' prior roles, because the entity's own history cannot carry the risk."
    Higher riskAnyHigh-risk third countryUnbounded, local-language"Country designated under Article 29; search run in the local language and script, sources recorded with retrieval dates."
    PEP or ex-PEPAnyAnyFull period in office + tail"Article 45(2) floor of 12 months after leaving office; extended to the full term plus three years because the former function still confers influence."

    Two rules make the table work. First, the window is a floor on the search, not a cap on the finding: a credible 2009 report that goes to source of wealth does not become irrelevant because your policy says three years — it becomes a finding you record and explain. Second, every branch that narrows the window has to name what it is giving up. "Three years" is a defensible sentence. "Three years" with no reason attached is a default.

    One subject, carried through

    WORKED EXAMPLE

    The subject below is invented, including the company, the people and the publications. Any resemblance to a real party is coincidental.

    A Dutch payment institution is onboarding Nordvent Bulk Chartering B.V. (Rotterdam, incorporated 2019), a dry-bulk charterer applying for a EUR account and a working-capital facility. Sole director and 62% shareholder: Marek Zielarz, 54, Polish national, resident in the Netherlands. Minority shareholder: a Cypriot holding company.

    Risk assessment: higher risk. Not because of the individual, but because of the sector — shipping and chartering, with a third-country holding layer and counterparties in jurisdictions subject to restrictive measures. Enhanced due diligence applies, so Article 26(2)(a) sets an annual review and the framework puts the search at the full life of the relationship with a five-year floor, extended to Zielarz's prior roles because Nordvent itself is only seven years old.

    Search run 4 September 2026, Dutch, Polish and English, plus Greek for the Cypriot layer. Five items:

    DatedFindingStatus on 4 Sep 2026Disposition
    Mar 2011Regional Polish paper names Zielarz in passing in a customs dispute at a former employer; he is not a partyOriginal URL dead; item known only from a citation in a later pieceRecorded as uncorroborated, source unavailable. Not used to raise risk
    Jun 2017Dutch trade title reports he was questioned in a fraud investigation into a former chartererArticle liveRecorded as allegation, with the 2019 item attached
    Feb 2019Same title reports the investigation closed with no charges broughtArticle live, poorly indexed, four paragraphsRecorded as outcome. Reviewer note: the allegation stands as a fact about 2017; it is not evidence of wrongdoing
    Aug 2023Cypriot judgment names the minority shareholder in a civil dispute over a vessel arrestJudgment publishedRecorded against the shareholder, not Zielarz. Civil, no criminal element
    Jul 2026Latvian outlet reports a Nordvent-chartered vessel called at a port under an EU restrictive measureArticle liveEscalated. Not adverse media in substance — a sanctions exposure question, routed to the sanctions workflow

    Outcome: onboard with enhanced due diligence, annual review, and a documented watch on the chartering pattern. The adverse media file is four recorded items and one escalation, and the two entries that decide it are the 2017/2019 pair and the 2011 item that cannot be verified.

    Three things that break a historical lookback

    FAILURE MODES

    1. Link rot, and the delisted article. The 2011 item is the ordinary case, not the unlucky one. Zittrain, Albert and Lessig found in 2014 that more than 70% of URLs cited in the Harvard Law Review and other journals, and 50% of those in US Supreme Court opinions, no longer resolved to the material they were cited for. Legal citations are the careful end of the web. A regional newspaper archive from 2011 is not.

    The consequence is procedural, not technical: snapshot at screening time and never re-fetch to reconstruct a past decision. A finding is stored with its text, its source URL, its publication date and its retrieval date, and the stored copy is what a reviewer or an auditor reads afterwards. Re-fetching produces a different file — sometimes emptier, sometimes changed — and quietly rewrites what you knew on the day. This is why our own Adverse Media Check stores each finding with its cited source as it stood at screening time rather than recomputing it later.

    Re-running a search is a different act from re-fetching a source. Re-run to find what is new. Re-fetch nothing.

    2. Allegations that were later dismissed. The 2017/2019 pair is the hardest entry in the file, and the temptation runs both ways. Deleting the 2017 item because the investigation closed is wrong: the EBA Guidelines say plainly that the absence of criminal convictions alone may not be sufficient to dismiss allegations of wrongdoing. Leaving the 2017 item to stand alone is also wrong, and now unlawfully so — Article 76(3)(b) AMLR requires procedures that distinguish allegations from investigations, proceedings and convictions, with the presumption of innocence in view.

    The working rule is: record the state of the matter, not the headline. One record, four fields — what was alleged, what stage it reached, what the outcome was, and the dated source for each. And search deliberately for the outcome, because the follow-up is always shorter, later and less indexed than the accusation. The 2019 piece in this file is four paragraphs; the 2017 piece was the lead item.

    3. Erasure requests against retention duties. Suppose Zielarz asks, in 2027, for the 2017 material to be erased. Article 17(1) GDPR gives him the right in principle; Article 17(3) removes it where processing is necessary for compliance with a legal obligation under Union or Member State law, or for the establishment, exercise or defence of legal claims. AML record-keeping is such an obligation, so the answer during the relationship is no.

    The answer is not "no, forever", and this is where most policies are thin. Article 77(3) AMLR sets the retention period at five years from the end of the relationship and then says obliged entities shall delete the personal data on expiry, unless a competent authority has required a further period — which may not exceed five more years, and must be justified case by case. So the correct response to an erasure request has three parts: the ground on which you are refusing now, the date on which the obligation ends, and a deletion process that actually runs on that date. A firm that cannot state the second and third is not relying on Article 17(3); it is keeping data because deleting it is inconvenient.

    What goes in the file

    RECORD

    For each finding, six fields, and all six are load-bearing:

    1. The finding, in your own words.
    2. The source: publisher, title, URL, publication date.
    3. The retrieval date, and the stored copy.
    4. The stage: allegation, investigation, proceeding, conviction, or outcome.
    5. The disposition and who made it.
    6. The date the retention obligation for this record ends.

    For the search itself, four more: the window applied, the languages and scripts used, the sources that were not reachable, and the reason for the window. That last one is the whole post. A lookback you cannot explain is not a control; it is a setting.

    Frequently asked questions

    Q&A

    Is there a legally required adverse media lookback period in the EU?

    No. Regulation (EU) 2024/1624 does not state one, and the EBA ML/TF Risk Factors Guidelines assess an allegation on the quality and independence of the source and the persistence of reporting rather than on its age. What EU law does fix is the maximum interval between customer due diligence updates — one year for higher-risk customers, five years for everyone else — and how long the resulting record must be kept.

    Where does the "5 to 10 years" adverse media figure come from?

    Vendor and consultancy content, repeated until it reads like a rule. Checked on 4 September 2026, no page carrying that range cites an EU instrument, an EBA guideline or a national supervisor for it. Treat it as a starting point someone else chose, not a standard, and write down the reason for whatever window you adopt.

    How should we treat an allegation that was later dropped?

    Record the outcome alongside the allegation, with both dates and both sources; do not delete the allegation and do not treat it as a conviction. Article 76(3)(b) of Regulation (EU) 2024/1624 requires procedures that distinguish allegations, investigations, proceedings and convictions, taking account of the presumption of innocence. The EBA Guidelines add the other half: the absence of a criminal conviction alone may not be enough to dismiss an allegation of wrongdoing.

    Do we have to delete adverse media findings if the subject asks under GDPR Article 17?

    Not while a legal obligation requires you to hold them. Article 17(3)(b) disapplies the right to erasure where processing is necessary for compliance with a legal obligation under Union or Member State law, and Article 17(3)(e) where it is needed for the establishment, exercise or defence of legal claims. The obligation is bounded, though: Article 77(3) AMLR requires deletion of personal data once the five-year retention period expires, unless a competent authority has required a longer period.

    Should we re-run adverse media searches or re-read the stored result?

    Both, for different purposes. Re-run to find what is new since the last check; that is monitoring. Never re-fetch the sources behind an old result to reconstruct it — the article may have moved, been amended or been delisted, and what you reconstruct will not be what you decided on. The old decision is defended by the snapshot taken on the day.

    Does a longer lookback make screening better?

    It makes it wider, not better. A ten-year window on a low-risk domestic customer mostly adds name collisions and stale items you then have to dismiss, each of which is a decision you must document. Depth is worth buying where the risk assessment says the subject's history matters — control roles, complex ownership, higher-risk jurisdictions — and not as a default setting.

    What should the adverse media section of our policy actually say?

    Four things: the window applied to each risk tier and why; how sources are stored so a result can be reproduced; how an allegation, an investigation, a proceeding and a conviction are recorded differently; and when the record is deleted. If a supervisor can read those four paragraphs and reconstruct why a specific file looks the way it does, the policy is doing its job.

    Informational analysis of published regulatory sources. Not legal advice. Verify the primary sources before acting.