Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Northwind Payroll (simulated)
- Subject
- entity enti_sim_nort_91eod4q93y
- Transfer
- acht_sim_nort_7g8jt9omvv · $2,117.52 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 58346d17-91da-4306-b775-794e08cfea2e fired on entity enti_sim_nort_91eod4q93y under the sanctions_or_pep detector after a $2,117.52 outgoing ACH debit (acht_sim_nort_7g8jt9omvv) settled on 2026-07-22 under the Northwind Payroll program. The alert is routed for review because this detector is always reviewed, not because the score triggered escalation.
What the evidence shows. The entity screening record shows PEP status no, high risk true, verification VERIFIED, review reasons none, and last screened 2026-06-26T12:01:30.000Z. The single contributing signal is entity.high_risk (+20), producing a skoor of 20 in the clear band with hard_signal false. The transfer itself carries the same skoor of 20, clear band, with confidence 0.865 on n=246. The transfer settled with no return code, and sanctioned_country_transfers at the program level is 0 (n=38, ok). Counterparty country is listed as unknown, but no sanctions or country-risk signal fired on the transfer or entity.
What was checked. I checked the entity screening fields (PEP, verification, review reasons, last screened date), the transfer status and return code, the skoor/band/hard_signal fields for both alert and transfer, and the program KRI panel. Program KRIs are mostly ok or watch: high_risk_entity_share 0.061 (watch, n=33), pep_flagged_entities 1 (watch, n=33), manual_review_rate 0.026 (watch, n=38), verification_denial_rate 0.030 (ok), stale_screening_share 0 (ok), ach return rates 0 (ok), sanctioned_country_transfers 0 (ok). One KRI, manual_review_aging_hours, shows breach status but n=1, which is too thin to draw a program-level conclusion and is not tied to this specific alert. Prior dispositions: none on file.
What is recommended. Close this alert. The entity is verified, not PEP, has no open review reasons, and was screened within the last two months. The only contributing signal is a static high-risk flag, which alone produced a clear-band score with no hard signal. The transfer settled normally with no return code and no sanctioned-country involvement. The counterparty country being unknown is a data gap worth flagging for screening data quality, but it does not by itself warrant holding funds already settled or escalating, since no pattern signal (PEP watch count, high-risk share) has breached at the program level.
- Recommendation
- close
- Confidence
- 0.78
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:30Z
- Rationale
- Skoor 20 is in the clear band with hard_signal false for both the alert and the transfer.
- Entity is VERIFIED, PEP no, review reasons none, last screened 2026-06-26.
- Transfer acht_sim_nort_7g8jt9omvv settled with no return code; sanctioned_country_transfers KRI is 0 across the program.
- Program-level PEP and high-risk share KRIs are at watch, not breach, and are not directly attributable to this single alert.
- The one breach KRI (manual_review_aging_hours) has n=1 and is too thin to support escalation or a hold on this transfer.
- Counterparty country unknown is a data completeness gap, not a sanctions or PEP signal, and does not change the disposition.
Evidence
{
"n": 246,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.