Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Meridian Remit (simulated)
- Subject
- entity enti_sim_meri_5if3mzfr9pn
- Transfer
- acht_sim_meri_bc9gkqw9c94 · $470.54 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 8b8d135f-6256-48ff-a571-9c807dcef0cb fired on entity enti_sim_meri_5if3mzfr9pn under the sanctions_or_pep detector, which is routed to review by design regardless of score. The entity is flagged by screening as high risk. The alert cites a single ACH outgoing credit transfer (acht_sim_meri_bc9gkqw9c94) for $470.54 USD, settled on 2026-09-14, with no return code.
What the evidence shows. The transfer-level skoor is 20, band clear, hard_signal false, driven by a single signal: entity.high_risk (weight 20). The entity record shows verification status VERIFIED, pep no, review reasons none, last screened 2026-08-27, country US. The transfer settled cleanly with no return code, so there is no indication of a rejected or reversed payment. Program-level KRIs show several breaches (reserve_coverage_ratio, ach_unauthorized_return_rate, manual_review_aging_hours, sanctioned_country_transfers), but none of these are tied in the evidence to this specific entity or this specific transfer. There are no prior dispositions on this entity.
What was checked. Entity screening status (high risk, not PEP, verified, screened within the last month), the transfer's settlement status and return code, the alert's score and band, and the program KRI panel for any linkage to this entity or transfer. No linkage was found between the program-level breaches and this specific alert's subject or transfer.
What is recommended. Close this alert. The evidence available is limited to one settled transfer with no return code, a clear-band score, a verified non-PEP entity, and a routing reason that is procedural (detector always reviewed) rather than substantive. Nothing in the evidence for this specific alert requires a person to intervene before funds move, and the transfer has already settled so there is no hold to release. The program-level KRI breaches (e.g., sanctioned_country_transfers=2, reserve_coverage_ratio=0.48) are noted for separate program-level monitoring but do not attach to this entity or transfer in the evidence provided.
- Recommendation
- close
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer skoor is 20, band clear, hard_signal false; only signal present is entity.high_risk at weight 20.
- Entity is verified, not PEP, with no review reasons and screening current as of 2026-08-27.
- Transfer status is SETTLED with no return code, so no reversal or hold applies; release is not applicable since no hold exists.
- Route reason is procedural (detector always reviewed), not evidence of elevated risk on this specific transfer.
- Program KRI breaches are present but the evidence does not connect them to this entity or transfer; treating them as grounds to escalate this specific alert would go beyond what is shown.
- No prior dispositions exist on this entity to suggest a repeating pattern tied to this alert.
Evidence
{
"n": 1012,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.