Alert · reviewed · held
A $2,400.00 ach transfer was initiated for an entity whose verification was denied.
- Detector
- denied_entity_activity
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_1x9rcs6c9kf
- Transfer
- acht_sim_harb_1x9rcs6c9kf · $2,400.00 · ach outgoing
- Skoor at alert
- 90 hold
- Hard signal
- yes
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An outgoing ACH credit transfer of $2,400.00 (acht_sim_harb_1x9rcs6c9kf) was initiated under the Harbor Marketplace Payouts program for entity enti_sim_harb_130qwgg53wz, whose verification status is DENIED. The transfer has already settled.
What the evidence shows. The entity is a PERSON labeled 'Denied Origin 1' with verification DENIED, high risk flagged true, and review reason sanctions_match, last screened 2026-06-24. The transfer skoor is 90 (band hold, n=1737, confidence 0.715) driven by a hard signal entity.denied (+60), plus entity.high_risk (+20) and amount.gt_3x_median (+10). autoHold is true and routeReason is 'hard signal', indicating the system intended to hold this transfer, yet the transfer status shows SETTLED with no return code. Counterparty country is unknown. Program KRIs show verification_denial_rate at 3.3% (ok), high_risk_entity_share at 6.7% (watch), pep_flagged_entities=1 (watch), manual_review_aging_hours in breach (1438 hours), and ach_unauthorized_return_rate in breach (0.88%). There are no prior dispositions for this alert.
What was checked. Transfer status and settlement details, entity verification and screening record, review reasons, skoor and signal breakdown, program declared volume and rails, and program-level KRIs including denial rate, high-risk share, and aging metrics. No counterparty country or additional entity screening detail beyond what is listed was available.
What is recommended. This alert involves a settled transfer to a denied, high-risk entity with a sanctions_match review reason, despite an autoHold/hard-signal routing that should have stopped it before settlement. This points to a control gap in the hold mechanism (transfer settled despite autoHold=true) combined with a sanctions-relevant denial, which is a pattern larger than this single alert. A person should review the hold-enforcement gap and the sanctions_match finding together with related transfers from this program.
- Recommendation
- escalate
- Confidence
- 0.60
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Hard signal entity.denied (+60) with autoHold=true and routeReason 'hard signal' indicates the system flagged this for hold before movement, but the transfer status is SETTLED, suggesting the hold did not prevent settlement.
- Review reason sanctions_match on a DENIED, high-risk entity is a compliance-sensitive finding that exceeds a single-alert disposition.
- Program KRIs show manual_review_aging_hours and ach_unauthorized_return_rate both in breach, consistent with broader control strain that could relate to how this hold was processed.
- No prior dispositions exist for this alert or apparent related pattern review, so escalation is needed to determine scope (e.g., whether other denied-entity transfers also settled despite autoHold).
- Confidence is moderate because the context does not explain why a SETTLED transfer shows autoHold=true; this discrepancy needs human clarification rather than assumption.
Evidence
{
"n": 1737,
"band": "hold",
"skoor": 90,
"signals": [
{
"code": "entity.denied",
"hard": true,
"detail": "entity verification DENIED",
"weight": 60
}
],
"autoHold": true,
"routeReason": "hard signal"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.denied | +60 | yes | entity verification DENIED |
| entity.high_risk | +20 | entity marked high risk by screening | |
| amount.gt_3x_median | +10 | amount > 3× program median (41558) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.