Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Northwind Payroll (simulated)
- Subject
- entity enti_sim_nort_91eod4q93y
- Transfer
- acht_sim_nort_9n1qo3q8334 · $1,369.06 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 3c8b534f-51c9-4740-ae1a-4cd2cd9eb3df fired from the sanctions_or_pep detector on entity enti_sim_nort_91eod4q93y after an outgoing ACH debit of $1,369.06 (acht_sim_nort_9n1qo3q8334) settled on 2026-09-03. The detector routes to review on every hit regardless of score, and the route reason confirms this ("detector always reviewed").
What the evidence shows. The entity is a VERIFIED business, marked high risk by screening but PEP status is no, with no review reasons listed and a screening date of 2026-08-18, about a month before the transfer. The only signal driving the score is entity.high_risk (+20), producing skoor 20 in the 'clear' band with hard_signal false. The transfer itself settled normally with no return code, and program-level KRIs show sanctioned_country_transfers at 0 (n=1048) and stale_screening_share at 0 (n=33), both ok. Counterparty country is unknown but concentration (top1=0.099) and velocity vs declared (0.333) are within normal ranges.
What was checked. Reviewed the entity's verification status, PEP flag, review reasons, and screening recency. Reviewed the transfer's settlement status and return code. Reviewed the alert's score, band, and hard-signal flag. Reviewed program KRIs for related risk indicators (high_risk_entity_share=0.061, watch; pep_flagged_entities=1 of 33, watch; manual_review_aging_hours=1434.68, breach). Confirmed no prior dispositions exist for this alert or entity.
What is recommended. Close the alert. The entity is verified, not a PEP, has no open review reasons, and was screened within the last month. The transfer has already settled with no return code, so there is no held transfer to release. The score band is clear and the hard signal is false; the only driver is a static high-risk flag already known to screening. Separately, the manual_review_aging_hours KRI is in breach (1434.68 hours, n=10) at the program level; this is not specific to this alert but should be flagged to the review-queue owner outside this disposition.
- Recommendation
- close
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Entity is VERIFIED, PEP no, review reasons none, last screened 2026-08-18 (recent).
- Alert skoor is 20, band clear, hard_signal false; sole signal is entity.high_risk, a static attribute already known to screening.
- Transfer acht_sim_nort_9n1qo3q8334 is SETTLED with return code none; nothing is held, so release does not apply.
- Program KRIs show no breach directly tied to this entity or transfer (sanctioned_country_transfers=0, stale_screening_share=0, counterparty_concentration_top1=0.099 ok).
- Route reason is procedural ("detector always reviewed"), not evidence of elevated risk beyond the known high-risk flag.
- Confidence is not higher because counterparty country is listed as unknown and no direct sanctions-list match detail is provided in the evidence, and manual_review_aging_hours is in breach at the program level though not specific to this alert.
Evidence
{
"n": 1160,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.