Most advertisers have a brand safety policy. Very few have a brand suitability policy. The gap between those two things is where a lot of display budget quietly goes wrong.
Brand safety is close to universal. Almost nobody wants their ad next to terrorist propaganda, child exploitation, or graphic violence. Vendors sell this as a solved problem, and for the most extreme categories it broadly is.
Brand suitability is the harder question, and it has no universal answer. It asks whether a placement is right for you — your category, your audience, your risk appetite, this quarter. A gambling site is unsafe for nobody in a legal sense, and completely unsuitable for a debt-counselling charity. A hard news site running war coverage is perfectly safe, and unsuitable for an airline running a holiday campaign that week.
Nobody can answer that for you. Which is exactly why most teams never answer it at all.
Safety is a floor, suitability is a position
It helps to be precise about what each term is doing.
Brand safety is a floor. It is largely defined for you — by law, by platform policy, and by the GARM framework that most of the industry now uses as shared vocabulary. It is about harm and legality. The list of things that fail it is short, extreme, and fairly stable.
Brand suitability is a position you take. It is defined by you, it changes by campaign, and reasonable people at the same company will disagree about it. It is about fit and association, not harm.
The practical consequence: if you buy a brand safety product and assume it handles suitability, you have bought a floor and called it a strategy. Your ads will avoid the genuinely dangerous places and still run in hundreds of environments that no one at your company would have chosen.
What actually shows up in an unaudited placement list
When we score a real GDN or PMAX placement report, the domains that fail on suitability grounds — not safety grounds — usually fall into a handful of buckets.
Made-for-advertising sites. Thin or scraped content, enormous ad density, built to arbitrage traffic rather than serve readers. Nothing on them is unsafe. They are also not places where anyone reads anything. This is the single largest category by spend in most accounts we look at.
AI-generated content farms. A fast-growing version of the same problem. Plausible-looking articles, no real author, no editorial process, high ad load. They pass every safety filter because there is nothing offensive on them.
Category-adjacent embarrassment. A weight-loss ad on a site about eating disorders. A car insurance ad next to a crash report. Each individually defensible, collectively the kind of thing that ends up in a screenshot.
Hard news during hard weeks. Sites that are entirely legitimate and entirely wrong for a light-hearted creative running against a disaster story. This is the one where blunt keyword blocking does the most damage — it defunds serious journalism while barely improving anything.
Copycat and interception sites. Specific to some categories. In travel, for example, lookalike booking sites that capture high-intent users and resell them. Not unsafe. Very much not suitable if you are the brand being copied.
Only the last two are arguable. The first three are close to pure waste, and they clear brand safety checks every single time.
Write the policy down in one page
The reason suitability rarely gets implemented is that it lives in people's heads. Someone senior has strong opinions, nothing is written, and the media team guesses. Fix that with one page.
1. Name your three non-negotiables. Not twenty. Three. The environments where an appearance would trigger a real internal problem. Be specific enough to act on: "sites whose primary editorial position is political advocacy in either direction" beats "controversial content".
2. Name your grey zone, and who decides. These are the categories you will accept in some campaigns and not others — hard news, dating, gambling, alcohol, religion. The value here is not the list, it is naming the person who rules on it so the decision is not made by default.
3. Decide your position on quality, separately from safety. Do you want to pay for impressions on sites with no identifiable author, no editorial process, and eight ad slots above the fold? Almost every brand says no when asked directly. Almost every brand does it anyway, because nobody asked.
4. Say what happens to the money. A suitability policy that only removes inventory is a budget cut in disguise. Say where the freed spend goes — usually into the environments that survived the audit.
5. Put a review date on it. Quarterly is realistic. Suitability drifts, and the supply side invents new junk faster than anyone's blocklist updates.
One page. If it does not fit on one page, it will not get used.
Turning the policy into an exclusion list
A policy becomes real when it is a list of domains applied to an account. The path from one to the other is mechanical.
Pull your placement report from Google Ads — Reports → Predefined reports → Other → Campaign URL performance — over the last 90 days, and sort by cost. Everything below is judgement applied to that file.
Score every domain, not just the expensive ones. The long tail is where MFA sites live, and individually none of them look like much. Collectively they are frequently a double-digit percentage of display spend. Manual review does not scale past a few hundred rows, which is the entire reason automated scoring exists.
Then apply the result at the account level. Since Google's January 2026 rollout, a single placement exclusion list applied once covers every Display and PMAX campaign in the account, including campaigns launched later. The complete guide to account-level exclusions walks through the exact steps. This changed the economics of this work significantly: the marginal cost of adding a domain to your list dropped to roughly zero, so a good list is now worth far more than it used to be.
Keep the evidence. Every exclusion should be defensible when someone senior asks why a site they have heard of is on the list. Scores without evidence get overturned in meetings.
The part people get wrong
Suitability is not maximum restriction. A blocklist so aggressive that it removes all news, all politics, and every keyword with a negative connotation will reliably produce clean reports and bad campaigns. You will have excluded most of the quality inventory on the open web and concentrated your spend into exactly the low-quality environments you were trying to avoid — because those are what is left.
The goal is not fewer placements. It is deliberate placements. Those are different targets, and only one of them makes money.
If you want to see where your own account currently sits, that is the whole point of running an audit: not to produce a longer blocklist, but to find out which of the places you are already paying for you would have chosen on purpose.