Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Northwind Payroll (simulated)
- Subject
- entity enti_sim_nort_91eod4q93y
- Transfer
- acht_sim_nort_3tzcp74a3o6 · $1,565.00 · ach outgoing
- Skoor at alert
- 35 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 971c8d6d-7677-4963-8ace-d0dd143469e9 was generated by the sanctions_or_pep detector on entity enti_sim_nort_91eod4q93y, flagged high risk by screening. The alert routed to review because the detector always routes to review, not because of a specific match. The transfer in question, acht_sim_nort_3tzcp74a3o6, is a $1565.00 USD outgoing ACH credit that settled with no return code.
What the evidence shows. The entity record shows verification status VERIFIED, pep flag no, and review reasons none, last screened 2026-08-18. Hard_signal on the alert is false. The transfer-level skoor is 35 (band review), with two signals: entity.high_risk(+20) and returns.counterparty_prior_any(+15). The counterparty has a prior-returns history, but this specific transfer settled with return code none, indicating no failure on this transaction. Program KRIs show ach_overall_return_rate at 1.24% (ok), sanctioned_country_transfers at 0 (ok), and stale_screening_share at 0 (ok). Two program-level KRIs are outside normal range: manual_review_aging_hours is in breach (1434.69 hours, n=13) and hold_aging_hours and pep_flagged_entities and high_risk_entity_share are at watch level, but none of these are specific to this entity or transfer.
What was checked. Entity verification status, PEP flag, review reasons, and screening date. Transfer status, return code, and settlement. Alert score, band, and signal composition. Program-level KRIs for sanctioned-country exposure, return rates, and screening staleness. Prior dispositions on this alert, of which there are none.
What is recommended. Close this alert. The entity is verified, not PEP-flagged, has no open review reasons, and was screened within the last 30 days. The transfer settled without a return. The only driver of the review-band score is the standing high-risk flag plus a counterparty prior-returns signal that did not materialize on this transaction. No sanctions or PEP match is present in the evidence. Separately, the program-level manual_review_aging_hours breach (1434.69 hours) is not tied to this specific alert and should be tracked at the program level, not as a basis for holding this transfer.
- Recommendation
- close
- Confidence
- 0.78
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Entity is VERIFIED, pep=no, review reasons none, screened 2026-08-18 (within 30 days).
- hard_signal is false; alert routed to review only because detector always reviews for this entity class.
- Transfer acht_sim_nort_3tzcp74a3o6 settled with return code none, so the counterparty_prior_any signal did not manifest on this transaction.
- No sanctioned_country_transfers, no stale screening, and ach return rates are within normal program range.
- Program-level manual_review_aging_hours breach and watch-level KRIs (pep_flagged_entities, high_risk_entity_share) are noted but are not specific to this alert's entity or transfer and do not change the disposition of this individual alert.
- No prior dispositions exist on this alert to indicate a recurring pattern.
Evidence
{
"n": 1449,
"band": "review",
"skoor": 35,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening | |
| returns.counterparty_prior_any | +15 | 1 prior return(s) other than NSF |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.