Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Meridian Remit (simulated)
- Subject
- entity enti_sim_meri_5if3mzfr9pn
- Transfer
- acht_sim_meri_4egp7fyjcal · $931.04 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 296eeb44-5247-47a7-b94f-131fdb15b66d fired on entity enti_sim_meri_5if3mzfr9pn under the sanctions_or_pep detector because screening marked the entity high risk. The route is 'reviewed' because this detector is always reviewed, not because the score triggered escalation. The linked transfer is an outgoing ACH credit of $931.04 USD (acht_sim_meri_4egp7fyjcal), already SETTLED as of 2026-09-15, with no return code.
What the evidence shows. The transfer-level skoor is 20, band clear, with a single signal: entity.high_risk (+20). Hard_signal is false. The entity record shows verification status VERIFIED, high_risk true, pep no, review reasons none, and last screened 2026-08-27T06:42:58.000Z, which is within a normal screening cycle. The counterparty country is unknown but there is no sanctioned-country signal on this transfer specifically. Program-level KRIs show several breaches unrelated to this specific alert: reserve_coverage_ratio (0.48, breach), manual_review_aging_hours (1146.87, breach), ach_unauthorized_return_rate (0.0118, breach), and sanctioned_country_transfers (2 of 923, breach). None of these breaches are tied by the evidence to this entity or this transfer.
What was checked. Checked alert score and band (20, clear), hard_signal flag (false), and the single contributing signal (entity.high_risk). Checked entity screening details: PEP status, verification, review reasons, last screening date. Checked transfer status and return code for the linked ACH credit. Checked program KRIs for any entity- or transfer-specific linkage to the breaches listed; none of the KRI breach descriptions reference this entity or transfer ID. Checked prior dispositions: none on file.
What is recommended. No hold or escalation is supported by the evidence tied to this specific alert. The transfer has already settled, so release is not applicable. The entity is verified, not PEP, has no review reasons, and was screened within the past month. The alert's own risk signal is limited to a generic high-risk flag with clear band and no hard signal. Recommend closing this alert. Separately, the program-level KRI breaches (reserve coverage, manual review aging, unauthorized return rate, sanctioned country transfers) are not evidenced as connected to this entity or transfer and should be tracked at the program level, not as part of this alert's disposition.
- Recommendation
- close
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer skoor is 20, band clear, hard_signal false, with only one low-weight signal (entity.high_risk +20).
- Entity is VERIFIED, PEP status no, review reasons none, last screened within the past month.
- Transfer already SETTLED with no return code, so no funds-movement action (hold/release) applies.
- Program KRI breaches (reserve_coverage_ratio, manual_review_aging_hours, ach_unauthorized_return_rate, sanctioned_country_transfers) are not linked in the evidence to this entity or transfer, so they do not support escalation of this specific alert.
- No prior dispositions exist for context or pattern comparison.
Evidence
{
"n": 1049,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.