Alert · reviewed · held
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- entity enti_sim_harb_130qwgg53wz
- Transfer
- acht_sim_harb_1x9rcs6c9kf · $2,400.00 · ach outgoing
- Skoor at alert
- 90 hold
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 684755dc-42f9-4c23-9e23-d64a59d8f792 fired on entity enti_sim_harb_130qwgg53wz under the sanctions_or_pep detector, severity high, alert skoor 90 (band hold). The entity is tied to one ACH outgoing credit transfer, acht_sim_harb_1x9rcs6c9kf, for $2,400.00 USD, dated 2026-09-02, which has already settled.
What the evidence shows. The entity record shows verification status DENIED, high_risk true, pep no, and review reasons listed as sanctions_match, last screened 2026-06-24. The alert-level evidence lists only entity.high_risk (+20) and reports hard_signal false, but the transfer-level skoor record for acht_sim_harb_1x9rcs6c9kf shows three signals: entity.denied (+60, hard), entity.high_risk (+20), and amount.gt_3x_median (+10), for a transfer skoor of 90 (band hold, n=1737, confidence 0.715). This is inconsistent with the alert's stated hard_signal=false. The transfer status is SETTLED, meaning the $2,400.00 already moved despite the entity carrying a DENIED verification status and a sanctions_match review reason. The counterparty country is unknown. Program-level KRIs show pep_flagged_entities and high_risk_entity_share at watch, manual_review_aging_hours and ach_unauthorized_return_rate at breach, but these are program-wide figures and not specific to this entity or transfer.
What was checked. Reviewed the alert evidence block, the transfer record and its skoor/signals, the entity screening record, and program KRIs. No prior dispositions exist for this alert. The mismatch between the alert's hard_signal=false and the transfer's hard entity.denied signal was checked and could not be reconciled from the evidence provided.
What is recommended. This is not a case where the flagged transfer is currently held; the $2,400.00 ACH credit already settled, so a release action does not apply and a simple close is not appropriate given the entity's DENIED verification and sanctions_match reason. The hard entity.denied signal on a settled outgoing transfer, combined with the discrepancy between alert-level and transfer-level hard-signal reporting, indicates this needs review by a person beyond this single alert, including checking whether other transfers moved for this same entity after the DENIED determination. Recommend escalation.
- Recommendation
- escalate
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Entity verification status is DENIED with review reason sanctions_match, yet a $2,400.00 outgoing ACH transfer for this entity has SETTLED status.
- Transfer-level skoor evidence includes a hard signal entity.denied(+60,hard) that is not reflected in the alert-level hard_signal=false field, an unexplained discrepancy in the record.
- Because the transfer already settled, hold/release actions do not apply to it; the concern is whether funds moved for a denied, sanctions-flagged entity and whether other transfers followed the same pattern.
- Program KRIs show manual_review_aging_hours and ach_unauthorized_return_rate at breach status, and high_risk_entity_share and pep_flagged_entities at watch, which supports escalation to check for a broader pattern rather than treating this as an isolated alert.
- No prior dispositions exist to indicate this entity or pattern was already reviewed.
Evidence
{
"n": 1737,
"band": "hold",
"skoor": 90,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"autoHold": true,
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.denied | +60 | yes | entity verification DENIED |
| entity.high_risk | +20 | entity marked high risk by screening | |
| amount.gt_3x_median | +10 | amount > 3× program median (41558) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.