Alert · reviewed · held
A $2,400.00 ach transfer was initiated for an entity whose verification was denied.
- Detector
- denied_entity_activity
- Severity
- high
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_619wbdb5ej7
- Transfer
- acht_sim_lant_619wbdb5ej7 · $2,400.00 · ach outgoing
- Skoor at alert
- 60 hold
- Hard signal
- yes
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. A $2,400.00 outgoing ACH transfer (acht_sim_lant_619wbdb5ej7) under Lantern Lending was flagged because the associated entity's verification was denied. The alert scored 60, mapped to the hold band, and was auto-held due to a hard signal.
What the evidence shows. The entity (enti_sim_lant_9312rknkcja, 'Denied Origin 3') has verification status DENIED with review reason sanctions_match, last screened 2026-06-24. The single signal driving the alert is entity.denied, weighted 60, hard=true. Despite the hold band and autoHold flag, the transfer record shows status SETTLED, meaning the $2,400.00 credit already moved before or without an effective hold. No return code is present, and counterparty country is unknown.
What was checked. Transfer status, entity verification and screening detail, program KRIs, and prior dispositions. Program-level KRIs are mostly ok or watch: verification_denial_rate 3.0% (ok, n=33), pep_flagged_entities 1 (watch), stale_screening_share 0 (ok), sanctioned_country_transfers 0 (ok). manual_review_aging_hours is in breach (1433.6 hours, n=6), indicating reviews in this program are running well behind. No prior dispositions exist for this alert.
What is recommended. This is not a case for close, since a sanctions_match denial with a settled transfer is not resolvable without a person's review. It is also not a hold candidate in the operational sense, since the funds have already settled and cannot be intercepted; 'release' does not apply because no transfer is currently held. The combination of a sanctions_match denial reaching settlement, plus a program-level manual_review_aging_hours breach, suggests this may not be an isolated control gap. Escalate for review of how a denied/sanctions-flagged entity's transfer settled despite the hard-signal hold logic, and to check for other transfers tied to this entity or program during the aging backlog window.
- Recommendation
- escalate
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Hard signal entity.denied with review reason sanctions_match on a settled $2,400.00 transfer indicates the hold mechanism did not prevent settlement.
- Transfer status is SETTLED despite band=hold and autoHold=true, which is inconsistent and warrants a control review beyond a single-alert disposition.
- Program KRI manual_review_aging_hours is in breach (1433.6h, n=6), consistent with a possible systemic review backlog rather than an isolated event.
- Other KRIs (denial rate, stale screening, sanctioned country transfers) are ok, so this does not appear to be a widescale sanctions exposure, but the settlement-despite-hold pattern still needs human investigation.
- No prior dispositions exist, so there is no established resolution path to rely on for closing.
Evidence
{
"n": 613,
"band": "hold",
"skoor": 60,
"signals": [
{
"code": "entity.denied",
"hard": true,
"detail": "entity verification DENIED",
"weight": 60
}
],
"autoHold": true,
"routeReason": "hard signal"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.denied | +60 | yes | entity verification DENIED |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.