Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Meridian Remit (simulated)
- Subject
- entity enti_sim_meri_5if3mzfr9pn
- Transfer
- acht_sim_meri_38ztfuwwbhk · $987.45 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 98a881de-ff80-4b76-ac6c-8abe33b0d4f1 was generated by the sanctions_or_pep detector on entity enti_sim_meri_5if3mzfr9pn under the Meridian Remit program. The entity was flagged solely because screening marked it high risk; screening did not flag it as PEP. The alert is tied to one settled outgoing ACH credit transfer, acht_sim_meri_38ztfuwwbhk, for $987.45 USD, dated 2026-08-24, with no return code.
What the evidence shows. The transfer-level skoor is 20, band clear, hard_signal false, driven by a single signal: entity.high_risk (+20). No other signals fired (no sanctioned-country match, no PEP match, no stale screening). The entity record shows verification status VERIFIED, pep false, review reasons none, and a screening date of 2026-06-26, which is recent relative to the transfer date. The counterparty's country is unknown, but the entity itself is US-domiciled. The transfer settled with no return code, meaning no rail-level rejection or dispute occurred. Program-level KRIs show breaches in reserve_coverage_ratio, manual_review_aging_hours, and ach_unauthorized_return_rate, but these are program-wide metrics not specific to this entity or transfer and are not cited as signals in this alert's evidence.
What was checked. Reviewed the alert evidence block, the transfer record, the entity screening record, and program KRIs. Confirmed the transfer status is SETTLED (funds already moved, not held), confirmed no prior dispositions exist for this alert, and confirmed the only contributing signal is the generic high-risk entity flag with no PEP, sanctions-country, or stale-screening signals present.
What is recommended. Close this alert. The transfer already settled, so no fund-movement decision remains. The evidence shows a single low-weight signal (entity.high_risk) with a clear-band score, a verified entity, no PEP status, and recent screening. Nothing in the evidence indicates a person needs to intervene on this specific alert. The program-level KRI breaches (reserve_coverage_ratio, ach_unauthorized_return_rate, manual_review_aging_hours) are noted for separate program-level review but do not attach to this entity or transfer in the evidence provided.
- Recommendation
- close
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Alert skoor is 20, band clear, hard_signal false, with only one contributing signal (entity.high_risk +20).
- Entity is verified, not PEP, has no review reasons, and was screened recently (2026-06-26).
- Transfer is already SETTLED with no return code, so there is no pending fund-movement decision; release is not applicable.
- Program KRI breaches (reserve_coverage_ratio, manual_review_aging_hours, ach_unauthorized_return_rate) are program-wide and not linked to this entity or transfer in the evidence, so they do not by themselves justify escalation of this specific alert.
- No prior dispositions exist, and counterparty country is unknown, which slightly limits full confidence in closing without further program-level context.
Evidence
{
"n": 684,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.