Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Northwind Payroll (simulated)
- Subject
- entity enti_sim_nort_91eod4q93y
- Transfer
- acht_sim_nort_8vmdxl1k1mp · $2,072.52 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 8688b89e-de29-4ffd-8c20-b5f14eab2f0f fired on entity enti_sim_nort_91eod4q93y under the sanctions_or_pep detector because screening marked the entity high risk. The linked transaction is an ACH outgoing credit acht_sim_nort_8vmdxl1k1mp for $2,072.52 USD, status SETTLED, with no return code.
What the evidence shows. The alert score is 20, band clear, hard_signal false, driven solely by the entity.high_risk signal (weight 20). The entity record shows verification VERIFIED, pep no, review reasons none, and last screened 2026-06-26T12:01:30.000Z. The transfer itself carries the same clear-band score (20, n=552, confidence 1) with no additional signals. The counterparty country is listed as unknown, which is a gap in the evidence but is not flagged by any signal or KRI. Program-level KRIs are mostly ok: sanctioned_country_transfers=0, ach_unauthorized_return_rate=0, verification_denial_rate=0.030 (33 entities), reserve_coverage_ratio=3.86. Two KRIs sit at watch (pep_flagged_entities=1/33, high_risk_entity_share=0.061/33) and one is in breach (manual_review_aging_hours=1434.7 hours, n=3), but none of these are specific to this entity or this transfer.
What was checked. Reviewed the alert signals and score, the entity's verification and screening status, the transfer's status and return code, the counterparty record, and the program KRI panel for corroborating patterns (sanctioned-country activity, return rates, concentration, PEP/high-risk shares).
What is recommended. No hold is warranted: the transfer has already settled, carries no return code, and the alert band is clear with no hard signal. The entity is verified with no open review reasons. The program-level manual_review_aging_hours breach is a separate operational issue (backlog of reviews) and does not implicate this specific entity or transfer; it should be tracked independently rather than attached to this alert. Close this alert.
- Recommendation
- close
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Alert score 20 falls in the clear band with hard_signal false, and the only contributing signal is entity.high_risk at its base weight.
- Entity is VERIFIED, not PEP, with no review reasons and a screening date within the last three months.
- Transfer is SETTLED with no return code, so no funds-in-transit decision is needed and release is not applicable.
- Program KRIs directly relevant to sanctions/high-risk exposure (sanctioned_country_transfers, verification_denial_rate, stale_screening_share) are all in the ok range.
- Counterparty country is unknown, which limits certainty; this is noted as a residual gap rather than a basis for holding, given the otherwise clear evidence.
- The manual_review_aging_hours breach and the two watch-level KRIs (pep_flagged_entities, high_risk_entity_share) point to a program-wide condition, not to this alert specifically, so escalation of this individual alert is not supported.
Evidence
{
"n": 552,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening | |
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.