Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- entity enti_sim_harb_skonrvy3x6
- Transfer
- acht_sim_harb_4vsjcy6h5jl · $487.14 · ach outgoing
- Skoor at alert
- 35 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Sanctions/PEP screening detector fired on entity enti_sim_harb_skonrvy3x6, a US business named 'High Risk Trading 1', in connection with a single outgoing ACH credit transfer of $487.14 settled on 2026-07-28 with no return code.
What the evidence shows. The entity carries a static high-risk screening flag (20-point signal) but is marked PEP: no, verification status VERIFIED, and has no listed review reasons. Last screening date is 2026-06-26, prior to alert open, and program-wide stale_screening_share is 0.00 (ok), so screening is current. The transfer itself settled normally with no return code. A secondary signal, returns.counterparty_prior_any (+15), indicates the counterparty has some prior return history, but this transaction shows no return and program ach return rates (overall 1.95%, unauthorized 0%, administrative 0.65%) are all within normal range. Combined score is 35, placing it in the review band with hard_signal false; route reason is 'detector always reviewed,' meaning this alert type is routed for review regardless of score.
What was checked. Entity profile (business type, verification, PEP status, high-risk flag, screening date, country), the single associated transfer (amount, rail, status, return code, counterparty country), transfer-level score and signals, program declared volume and rails, and program KRIs. KRIs show pep_flagged_entities=1/30 (watch) and high_risk_entity_share=6.67% (watch), both program-level and not specific to this entity's transaction. manual_review_aging_hours shows a breach (1438 hours, n=2), which is a program operational metric unrelated to this specific transfer's disposition. No prior dispositions exist for this alert.
What is recommended. Close this alert. The entity is verified, not PEP, screening is current, and the flagged transfer settled with no return or adverse outcome. The high-risk designation alone, absent PEP status or a hard signal, does not indicate a person needs to intervene on this specific transfer. Separately, the manual_review_aging_hours breach at the program level should be tracked outside this alert as it reflects review queue backlog, not this transaction.
- Recommendation
- close
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:30Z
- Rationale
- Entity verification status is VERIFIED with PEP: no and no review reasons listed.
- hard_signal is false and score (35) sits at the low end of the review band.
- Transfer settled with no return code; program-wide return rates are all within normal ranges.
- Screening date (2026-06-26) predates alert open and stale_screening_share is 0.00, indicating screening is current, not overdue.
- Route reason indicates this detector is always routed to review regardless of score, meaning the review band alone does not signal elevated risk beyond baseline policy.
- Program KRI breach (manual_review_aging_hours) is an operational metric with n=2 and is not specific to this entity or transfer, so it does not change the disposition of this alert but should be noted separately.
Evidence
{
"n": 564,
"band": "review",
"skoor": 35,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening | |
| returns.counterparty_prior_any | +15 | 1 prior return(s) other than NSF |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.