Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- entity enti_sim_harb_skonrvy3x6
- Transfer
- acht_sim_harb_1rf59phk9b5 · $801.82 · ach outgoing
- Skoor at alert
- 30 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An alert fired on entity enti_sim_harb_skonrvy3x6 (Business "High Risk Trading 1") because screening marks it high risk. The detector for sanctions/PEP status always routes such entities to review. The triggering transfer is an outgoing ACH credit of $801.82 USD, settled on 2026-09-14, to a first-time counterparty whose country is unknown.
What the evidence shows. The entity is BUSINESS-verified, not PEP, with no review reasons listed, and was last screened 2026-08-27, before the transfer date. Alert score is 30, band review, hard_signal is false, and the route reason is simply that the detector always reviews high-risk entities. The transfer itself settled normally with no return code. Signals on the transfer are entity.high_risk(+20) and counterparty.first_time(+10), both expected attributes rather than anomalies. Program KRIs show most metrics ok or watch; two are in breach (manual_review_aging_hours=1438.1 hours, ach_unauthorized_return_rate=0.82%), but neither is tied in the evidence to this entity or this transfer specifically.
What was checked. Entity verification status, PEP flag, review reasons, screening recency, transfer settlement status and return code, counterparty history, and program-level KRIs for related risk indicators (sanctioned_country_transfers, verification_denial_rate, stale_screening_share, high_risk_entity_share).
What is recommended. No hold is warranted because the transfer already settled with no return and no adverse screening findings beyond the standing high-risk flag that triggers automatic review. The entity is verified, not PEP, and has no open review reasons. This alert can be closed. The two breaching program KRIs (manual_review_aging_hours, ach_unauthorized_return_rate) are not evidenced as connected to this entity or transfer and should be tracked separately at the program level, not through this alert.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Entity is VERIFIED, PEP no, review reasons none, screened 2026-08-27 (within a month of the transfer).
- Hard_signal is false and score (30) sits at the low end of the review band; routeReason confirms this alert exists only because the detector always reviews high-risk-flagged entities.
- Transfer status is SETTLED with return code none, so there is no held transfer to release or hold.
- Signals present (entity.high_risk, counterparty.first_time) are attributes already known and screened, not new adverse findings.
- Program KRIs sanctioned_country_transfers=0 and stale_screening_share=0 indicate no broader sanctions exposure tied to this profile.
- Two program KRIs are in breach (manual_review_aging_hours, ach_unauthorized_return_rate) but nothing in the evidence links them to this specific entity or transfer, so they do not change the disposition of this alert but merit separate program-level attention.
Evidence
{
"n": 2151,
"band": "review",
"skoor": 30,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening | |
| counterparty.first_time | +10 | first transfer with this counterparty |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.