Here's how brand safety usually works: you plan the campaign, pick the channels, set the targeting, and then hand the whole thing to a verification vendor to screen out the worst of it before or after the buy goes live. But I think that order is backward.
By the time you're applying a keyword block list to a plan that's already built, the real decisions (which platforms you’re running on, whether you’re buying open exchange or curated inventory, how much of your budget goes programmatic versus direct) have already been made. Those choices set your actual risk exposure, and no verification step afterward can undo them.
I like to think of it this way: brand safety applied after the plan is the cleanup crew. Brand safety built into the plan from the start is the architect. When safety standards shape the plan itself, they influence:
Before any of this gets built into a plan, it helps to separate two ideas that tend to get used interchangeably.
Brand safety is objective and universal. It’s all about keeping your brand’s ads away from content that's widely agreed to be illegal, harmful, or inappropriate. The goal here is straightforward: avoid reputational damage.
Brand suitability works differently, though. It's specific to a brand's own values, tone, and audience, which means the same piece of content can be safe for one advertiser and completely wrong for another. For instance, a late-night comedy site might clear every brand safety threshold and still be the wrong environment for a family-focused brand.
Suitability is less about avoiding harm and more about building the kind of positive association that actually moves a brand forward.
Knowing which standard you're applying, and why, shapes everything that follows in a media plan.
Without a defined risk tier set before planning begins, brand safety doesn't enter the conversation until the campaign's already live, usually in the form of a verification report. By then, the budget's spent, and there's not much left to do but clean up around the edges.
The alternative is what's known as a suitability tier. Just like a building's blueprint specifies load limits and materials before construction starts, a suitability tier is a fixed category, set during planning, that specifies exactly how much content exclusion a campaign is built to withstand.
Most teams work with something like three levels:
Deciding which tier fits isn't a media buyer's call to make alone, though. Legal, PR, and marketing all have a stake in it, and that conversation should happen at the planning table, before anyone's picked a platform or channel. A brand-building campaign usually calls for something closer to "strict," while a lower-funnel retargeting push can often live comfortably in "expanded," since the exposure risk just isn't the same.
That same planning window is also where flighting and pacing around known high-risk moments (like elections, breaking news, a cultural flashpoint that comes out of nowhere) gets built in ahead of time. By building your brand safety blueprint at the start, you can be more proactive around these moments instead of just going dark during high-risk times.
Once a suitability tier is set, it’s time to actually build these brand safety standards into your campaign. Here are a few best practices I recommend to clients:
Before any platform gets touched, legal, PR, and marketing need to agree on the exact line between safe, suitable, and strictly prohibited content for that brand. Establishing core guidelines turns the suitability tier into a documented list spelling out exactly what "strict" excludes.
Inclusion lists (also called allowlists) name the trusted domains and apps a campaign is allowed to run on. Exclusion lists block specific keywords, URLs, and controversial topics.
Both Google Display & Video 360 and Amazon DSP support this work directly with:
One important note: These lists only hold their value if they're updated regularly. Saving a given set of lists as a reusable template also means a new campaign can launch with guardrails already in place, rather than rebuilding the same exclusions from scratch every time.
Vetting a partner well means asking direct questions about their audience targeting, inventory sources, and built-in fraud prevention. That same due diligence also shapes supply path decisions more broadly, rather than assuming a vendor's default settings already match a brand's risk tolerance.
These three practices are what actually turn a suitability tier from a decision on paper into a campaign that runs the way it was designed to.
Guidelines, lists, and vetted partners give a campaign its foundation, but none of that structure holds up without regular upkeep.
Because new slang appears constantly and a cultural moment can get picked up by the news cycle within hours, a keyword list built six months ago might not reflect what a brand needs to avoid today. Going back into these lists on a set cadence, rather than leaving them untouched after the initial setup, is what keeps that foundation solid.
Verification data deserves the same ongoing attention. When a team only reviews that data after a campaign wraps, you miss the chance to act on those insights. When you treat that verification data as a feedback loop instead, it shapes the next campaign's suitability tier, exclusion lists, and channel mix.
The same gap shows up in a more specific way: assuming a verification vendor's default settings already match a brand's risk tolerance. Nothing about the campaign looks broken, which is exactly why active-but-mismatched settings are so easy to miss.
Vendor settings are only part of the picture, though, since even a well-configured campaign can still end up running on a placement that was never actually vetted.
A useful operating principle here is to add every reasonable protection up front and pull back later based on performance data, rather than starting loose and trying to tighten things after something's already gone wrong.
Vetting a publisher, app, or streaming service means checking whether the content:
Streaming adds a layer of complexity many teams overlook. A lot of these platforms run on shared household accounts, so a placement built for an adult audience can still end up in front of a child using a parent's login. That's exactly the kind of scenario content age restrictions in your DSP are built to catch (no mature content, no unrated content, etc.). Some apps and sites aren't rated at all, and for those, the smart move is steering clear regardless of how good the deal looks on paper.
However, the "add everything, then pull back" approach only works if that inventory can actually be reviewed, and doing that by hand across dozens of accounts simply isn't realistic. For instance, strict keyword blocking alone can accidentally flag a benign news site for using a single sensitive word in an otherwise unrelated story.
The good news is that AI can help here. Natural language processing tools read the actual context and tone of a page before an ad ever bids on the space, moving suitability decisions past static block lists into genuine context analysis. That same technology helps flag heavily ad-stacked, made-for-advertising sites designed to rack up impressions rather than deliver anything real, catching those before the budget is wasted rather than after.
An architect doesn't design a building for the risks that existed when the blueprint was drawn and call it finished. The plan gets built to hold up as conditions change around it. That's exactly what brand suitability asks of a media plan: not a one-time box checked during planning, but a structure that holds over the life of a campaign.
Treated as a planning input from the start, brand safety standards become a chance to build smarter into every platform choice, every targeting decision, and every partnership along the way.
The architect mindset is what we bring to every media plan we build. If your team wants a second set of eyes on where brand safety and suitability fit into your next campaign, we'd love to talk through what that could look like.