Alert · reviewed · open
Activity on an entity flagged by screening (PEP status potential).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Lantern Lending (simulated)
- Subject
- entity enti_sim_lant_866sn4vcjd
- Transfer
- acht_sim_lant_4p5nxr48dcn · $2,441.74 · ach outgoing
- Skoor at alert
- 15 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 9a7b3782-2e8b-47cf-981f-7b6c43b908a7 was opened by the sanctions_or_pep detector on 2026-09-17 for entity enti_sim_lant_866sn4vcjd, a person named 'Potential Pep 3' under the Lantern Lending program. The alert cites a single potential PEP match. The route was 'reviewed' because this detector is always reviewed, not because of elevated risk.
What the evidence shows. The entity-level skoor is 15, placing it in the 'clear' band, with hard_signal false. The only contributing signal is entity.pep_potential at weight 15. The entity record shows verification status VERIFIED, high_risk false, and review reasons none, with last screening on 2026-06-25T12:01:30.000Z. The single associated transfer, acht_sim_lant_4p5nxr48dcn, is an outgoing ACH credit for $2,441.74 USD, status SETTLED, with no return code. The transfer's own skoor is also 15/clear with n=295 and confidence 0.88. Program-level KRIs are mostly in the 'ok' range: stale_screening_share 6.06%, high_risk_entity_share 3.03%, verification_denial_rate 3.03%, ach return rates all 0%. Two KRIs show elevated readings: pep_flagged_entities at 1/33 (watch) and manual_review_aging_hours at 1433.5 hours (breach), but neither is specific to this entity or transfer.
What was checked. Confirmed the alert score and band, hard_signal flag, and the single signal driving the alert. Reviewed the entity's verification status, high-risk flag, review reasons, and screening recency. Reviewed the transfer's status, return code, and amount against the program's declared monthly volume of $900,000.00. Reviewed program KRIs for any pattern indicating broader sanctions or PEP exposure. Checked prior dispositions: none exist for this alert.
What is recommended. No signal in this alert requires a person to intervene before the transfer, which has already settled with no return. The entity is verified, not flagged high risk, has no review reasons, and screening is current (not in the stale share). The program-level PEP watch (1 of 33 entities) and manual review aging breach are not tied to this specific alert and are not evidence of a pattern involving this entity or transaction. Recommend closing this alert. The manual_review_aging_hours breach may warrant separate attention at the program level, but that is outside the scope of this entity-specific alert.
- Recommendation
- close
- Confidence
- 0.80
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Alert skoor 15, band clear, hard_signal false.
- Single contributing signal is entity.pep_potential (potential match only, not confirmed).
- Entity is VERIFIED, high_risk false, review reasons none, last screened 2026-06-25 (not in stale_screening_share).
- Transfer is already SETTLED with no return code; alert is not about a held transfer, so release is not applicable.
- Program KRIs are largely ok; the two elevated KRIs (pep_flagged_entities watch, manual_review_aging_hours breach) are program-wide metrics not specific to this entity or transfer and do not by themselves indicate a pattern requiring escalation of this alert.
- No prior dispositions exist to inform pattern recognition.
Evidence
{
"n": 295,
"band": "clear",
"skoor": 15,
"signals": [
{
"code": "entity.pep_potential",
"detail": "potential PEP match",
"weight": 15
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.pep_potential | +15 | potential PEP match |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.