Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Northwind Payroll (simulated)
- Subject
- entity enti_sim_nort_91eod4q93y
- Transfer
- acht_sim_nort_2hsf6s2x1um · $1,863.13 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An alert fired on entity enti_sim_nort_91eod4q93y under the sanctions_or_pep detector, which is configured to always route to review regardless of score. The entity is flagged by screening as high risk. The associated transfer is a single settled outgoing ACH debit of $1,863.13 dated 2026-08-10, already settled with no return code.
What the evidence shows. The score at alert is 20, band clear, with hard_signal false. The only contributing signal is entity.high_risk (+20). The entity record shows verification VERIFIED, pep status no, no review reasons listed, last screened 2026-06-26, country US. The transfer is SETTLED with no return code, so there is no held transfer to act on. Program KRIs show most metrics ok; two are flagged watch (pep_flagged_entities=1 of 33, high_risk_entity_share=0.0606), and one is flagged breach (manual_review_aging_hours=1434.67 over n=6). Screening data is not stale (stale_screening_share=0). No prior dispositions exist for this entity or alert.
What was checked. Detector and routing metadata, transfer status and return code, entity verification and PEP/high-risk fields, screening recency, program KRI panel, and prior disposition history. All fields present in the evidence were reviewed; no external data was assumed.
What is recommended. Close this alert. The score is clear, the hard signal is false, the entity is verified and not PEP, screening is current, and the transfer has already settled with no return code indicating a problem. The manual_review_aging_hours breach and the two watch-level KRIs (pep_flagged_entities, high_risk_entity_share) are program-level metrics not specific to this alert or entity; they warrant separate operational attention but do not change the disposition of this single alert. A person should confirm the aging-hours breach is being tracked elsewhere, but no fund action is needed here since the transfer already settled.
- Recommendation
- close
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Detector routes to review by policy regardless of score; score itself is clear (20) and hard_signal is false.
- Only one contributing signal (entity.high_risk +20); no PEP flag, no stale screening, no adverse review reasons.
- Transfer is SETTLED with no return code; there is no held transfer to release or hold, and reversal is not supported by the evidence.
- Entity is VERIFIED and screened recently (2026-06-26), reducing concern about identity or outdated risk assessment.
- Program KRI breach (manual_review_aging_hours) and watch flags (pep_flagged_entities, high_risk_entity_share) are portfolio-level and not tied specifically to this entity or transfer in the evidence provided; they support a separate operational follow-up rather than escalation of this specific alert.
- No prior dispositions exist to indicate a repeat pattern for this entity.
Evidence
{
"n": 670,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.