Alert · reviewed · open
Activity on an entity flagged by screening (PEP status potential).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Northwind Payroll (simulated)
- Subject
- entity enti_sim_nort_sr7cv2o3u
- Transfer
- acht_sim_nort_42x3377w24h · $3,141.10 · ach outgoing
- Skoor at alert
- 15 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 68ae8b2f-38c8-42f4-bcd6-c97050801b8e fired from the sanctions_or_pep detector on entity enti_sim_nort_sr7cv2o3u due to a potential PEP match. The alert was routed to review because this detector always routes to review, not because of the score. The linked activity is a single outgoing ACH debit of $3,141.10 (transfer acht_sim_nort_42x3377w24h), already settled, with no return code.
What the evidence shows. The alert skoor is 15, banded 'clear', with hard_signal false. The transfer carries the same skoor 15 (band clear, n=781, confidence 0.955), driven solely by the entity.pep_potential signal (+15). The entity record shows verification status VERIFIED, high_risk false, review reasons none, country US, last screened 2026-06-25. The counterparty's country is listed as unknown, and no return code was posted on the settled transfer. Program-level KRIs are mostly ok: ach_overall_return_rate 0.99%, ach_unauthorized_return_rate 0%, sanctioned_country_transfers 0, reserve_coverage_ratio 2.39. Two KRIs sit in watch (pep_flagged_entities 1/33, high_risk_entity_share 6.06%) and one is in breach (manual_review_aging_hours 1434.67 hours, n=7), but none of these are specific to this entity or this transfer.
What was checked. Reviewed the alert evidence block, the linked ACH transfer and its settlement/return status, the entity screening record (verification, high-risk flag, review reasons, last screened date), the program's declared volume and rail/country profile, and the full set of program KRIs for corroborating signals. No prior dispositions exist for this alert or subject.
What is recommended. No evidence here indicates an unresolved PEP finding: the entity is verified, not flagged high risk, and carries no open review reasons. The transfer has already settled with no return, so there is no held transfer to release. The single watch-level program KRI on pep_flagged_entities (1 of 33) and the manual_review_aging_hours breach reflect program-wide review capacity, not this specific alert, and should be tracked separately rather than driving this disposition. Close this alert; a person should still review the program-level manual_review_aging_hours breach as a separate operational matter if not already tracked.
- Recommendation
- close
- Confidence
- 0.78
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Alert skoor 15 is banded clear and hard_signal is false, per the alert evidence.
- Entity enti_sim_nort_sr7cv2o3u is VERIFIED, high_risk false, and has review reasons listed as none.
- The only transfer tied to this alert has settled with no return code, so 'release' does not apply.
- Program-level sanctioned_country_transfers and ach_unauthorized_return_rate are both 0, showing no corroborating pattern of sanctions or fraud activity.
- Counterparty country is unknown, which is a gap in the evidence and slightly lowers confidence.
- Watch-level KRIs (pep_flagged_entities, high_risk_entity_share) and the manual_review_aging_hours breach are program-wide metrics, not specific to this alert, so they do not change the disposition of this individual alert but warrant separate attention.
Evidence
{
"n": 781,
"band": "clear",
"skoor": 15,
"signals": [
{
"code": "entity.pep_potential",
"detail": "potential PEP match",
"weight": 15
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.pep_potential | +15 | potential PEP match |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.