Alert · reviewed · held
The entity's first transfer, $2,400.00, above the program median, came 0.0 hours after verification.
- Detector
- rapid_onboarding
- Severity
- medium
- Program
- Northwind Payroll (simulated)
- Subject
- transfer acht_sim_nort_1c6mqyec3s6
- Transfer
- acht_sim_nort_1c6mqyec3s6 · $2,400.00 · ach outgoing
- Skoor at alert
- 80 hold
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 05a75642 fired on the rapid_onboarding detector for the first transfer on program Northwind Payroll: a $2,400.00 outgoing ACH credit that occurred 0.0 hours after entity verification, above the program's $1,831.02 median transfer size.
What the evidence shows. The transfer is already SETTLED, so no funds are currently held by this alert. The linked entity, enti_sim_nort_4ndrgqqi3r, has verification status DENIED, high_risk true, and review reasons listing sanctions_match, last screened 2026-06-24. The skoor of 80 (band hold) is driven by entity.denied(+60, hard) and entity.high_risk(+20). The alert header lists hard signal as false, which is inconsistent with the entity.denied signal being flagged hard in the signal list; this discrepancy is noted but not resolved by the evidence provided. Program KRIs show verification_denial_rate at 3.0% (n=33, ok) and high_risk_entity_share at 6.1% (watch), with manual_review_aging_hours in breach (1434.7 hours, n=10). No prior dispositions exist for this alert.
What was checked. Transfer record (status, amount, counterparty, return code), entity verification and screening fields, program declared volume and KRI panel, and prior disposition history. Counterparty country is listed as unknown; no return code is present on the settled transfer.
What is recommended. A transfer that settled despite the associated entity carrying a DENIED verification status and a sanctions_match review reason is not something this alert can resolve on its own. Funds have already moved, so hold or release do not apply. This pattern, an onboarding entity with a sanctions match completing a settled transfer, indicates a possible control gap between verification denial and payment execution. Recommend escalation for a person to review why a DENIED/sanctions_match entity was able to settle a transfer, and to check whether the hard-signal flag mismatch (alert-level false vs. signal-level hard) reflects a labeling defect elsewhere in the pipeline.
- Recommendation
- escalate
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Entity verification is DENIED with review reason sanctions_match, and this generated the dominant +60 hard signal plus +20 high_risk signal driving the skoor to 80.
- The associated transfer has already SETTLED, meaning the underlying funds movement is not something a hold or release action can address; this points beyond a routine transfer-level disposition.
- The alert header's hard signal:false conflicts with the entity.denied(+60,hard) entry in the signals list, an inconsistency that itself warrants human review rather than automated closure.
- Program KRIs show manual_review_aging_hours in breach and pep_flagged_entities/high_risk_entity_share in watch status, consistent with broader review-pipeline strain rather than an isolated event.
- No prior dispositions exist to indicate this pattern (denied entity completing a transfer) has already been reviewed and cleared.
Evidence
{
"n": 675,
"band": "hold",
"skoor": 80,
"autoHold": true,
"typology": "rapid_onboarding",
"confidence": 0.7,
"thresholds": {
"hours": 24
},
"medianCents": "183102",
"routeReason": "detector not auto-closable",
"hoursSinceVerification": 0
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.denied | +60 | yes | entity verification DENIED |
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.