Alert · reviewed · open
Activity on an entity flagged by screening (PEP status potential).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- entity enti_sim_harb_azbiyidj3x2
- Transfer
- acht_sim_harb_3arf5iff68m · $215.02 · ach outgoing
- Skoor at alert
- 15 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 4dc0a631-a8c9-466e-8207-440b7ec1895a was opened on 2026-09-17 by the sanctions_or_pep detector for entity enti_sim_harb_azbiyidj3x2, which carries a potential PEP flag. The triggering activity is a single outgoing ACH credit transfer (acht_sim_harb_3arf5iff68m) for $215.02 USD, created 2026-08-06 and already SETTLED, with no return code.
What the evidence shows. The alert score is 15, band clear, with hard_signal false. The only contributing signal is entity.pep_potential at weight 15, and the route reason states this detector is always reviewed regardless of score. The entity record shows verification status VERIFIED, high_risk false, no review reasons listed, and a last screening date of 2026-06-25, which is within a normal screening cycle. The transfer itself scored 15/clear with n=860 and confidence 1, and it has already settled with no return code, so there is no pending movement to hold or release. Program-level KRIs show pep_flagged_entities at 1 of 30 (watch) and high_risk_entity_share at 6.7% (watch), along with unrelated breaches in manual_review_aging_hours and ach_unauthorized_return_rate. None of these program metrics are tied in the evidence to this specific entity or transfer.
What was checked. Reviewed the alert score and band, the entity's verification and screening status, the transfer status and return code, and program-level KRIs for any linkage to this entity. No prior dispositions exist for this alert. No adverse review reasons are recorded for the entity, and no sanctioned-country or high-risk-country counterparty data applies (counterparty country unknown, but no sanctioned_country_transfers signal fired at the program level).
What is recommended. Close the alert. The transfer has already settled, the entity is verified with no open review reasons, the alert score is in the clear band with no hard signal, and screening is current. The PEP potential flag alone, absent additional adverse signals, does not require a hold or escalation given this evidence. The program-level watch/breach KRIs (manual_review_aging_hours, ach_unauthorized_return_rate, pep_flagged_entities share) are noted for awareness but are not shown to connect to this specific alert and should be tracked separately at the program level.
- Recommendation
- close
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Alert score 15 falls in the clear band with hard_signal false.
- Entity is VERIFIED, high_risk false, and has no listed review reasons.
- Transfer is already SETTLED with no return code; there is no held transfer to release or hold.
- Last screening date (2026-06-25) predates alert open date and shows no stale_screening_share issue (0 at program level).
- Program KRIs (pep_flagged_entities, high_risk_entity_share) are at watch level but the evidence does not tie them specifically to this entity or transfer, so they do not by themselves justify escalation of this alert.
- No prior dispositions exist, so there is no history of repeated flags for this entity to suggest an emerging pattern.
Evidence
{
"n": 860,
"band": "clear",
"skoor": 15,
"signals": [
{
"code": "entity.pep_potential",
"detail": "potential PEP match",
"weight": 15
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.pep_potential | +15 | potential PEP match |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.