Alert · reviewed · held
A $2,400.00 ach transfer was initiated for an entity whose verification was denied.
- Detector
- denied_entity_activity
- Severity
- high
- Program
- Meridian Remit (simulated)
- Subject
- transfer acht_sim_meri_6r6oon2pcdx
- Transfer
- acht_sim_meri_6r6oon2pcdx · $2,400.00 · ach outgoing
- Skoor at alert
- 100 hold
- Hard signal
- yes
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An ACH outgoing transfer of $2,400.00 (acht_sim_meri_6r6oon2pcdx) under program Meridian Remit was flagged by the denied_entity_activity detector. The transfer's counterparty entity (enti_sim_meri_3qusu9s29pg, "Denied Origin 2") has a verification status of DENIED with review reason sanctions_match, screened 2026-06-24. The transfer status is SETTLED, meaning funds have already moved.
What the evidence shows. The alert carries a skoor of 100 in the hold band with a hard signal (entity.denied, weight 60, hard=true). Two additional signals are present: returns.counterparty_prior_unauthorized (+40) and amount.gt_3x_median (+10). The entity record confirms verification DENIED with review reason sanctions_match, not merely a generic denial. Despite the hard-hold signal and autoHold flag, the transfer record shows status SETTLED with no return code, indicating the transfer completed before or without an effective hold. Program-level KRIs show three breaches: reserve_coverage_ratio (0.801, breach), manual_review_aging_hours (1146.9, breach), and ach_unauthorized_return_rate (0.0143, breach), alongside a watch-level pep_flagged_entities (1 of 30) and hold_aging_hours (1364.97, watch). These are program-wide metrics, not specific to this transfer, but they indicate broader review-capacity and reserve strain in the program at the same time this settled transfer bypassed a hard hold.
What was checked. Detector signals and weights, transfer status and settlement state, entity verification status and review reason, program declared volume and rails, and program KRI panel for corroborating strain. Prior dispositions: none on file for this alert.
What is recommended. This is not a case for hold, since the transfer has already settled and there are no funds in a held state to act on. The combination of a hard sanctions-related denial signal on a settled transfer, a prior-unauthorized-counterparty signal, and concurrent program KRI breaches (reserve coverage, unauthorized return rate, manual review aging) indicates a pattern beyond this single alert that needs review by a person, including whether the autoHold mechanism failed to intercept this transfer before settlement. Escalate for review of the entity relationship, the settled transfer, and the autoHold gap.
- Recommendation
- escalate
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Hard signal entity.denied (weight 60) with review reason sanctions_match on the counterparty entity
- skoor 100 in hold band with autoHold=true, yet transfer status is SETTLED with no return code, indicating the hold did not prevent settlement
- Additional corroborating signals: returns.counterparty_prior_unauthorized (+40) and amount.gt_3x_median (+10)
- Program KRIs show three concurrent breaches (reserve_coverage_ratio, manual_review_aging_hours, ach_unauthorized_return_rate) suggesting broader strain beyond this single alert
- No prior dispositions exist for this alert, so no established handling precedent to rely on
- Cannot recommend release because this alert is not about a transfer currently held; cannot recommend hold because funds have already settled
Evidence
{
"n": 755,
"band": "hold",
"skoor": 100,
"signals": [
{
"code": "entity.denied",
"hard": true,
"detail": "entity verification DENIED",
"weight": 60
}
],
"autoHold": true,
"routeReason": "hard signal"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.denied | +60 | yes | entity verification DENIED |
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) | |
| amount.gt_3x_median | +10 | amount > 3× program median (66220) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.