Alert · reviewed · open
Activity on an entity flagged by screening (PEP status potential).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- entity enti_sim_harb_azbiyidj3x2
- Transfer
- acht_sim_harb_595mczek745 · $191.22 · ach outgoing
- Skoor at alert
- 30 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 9dad2128-dc82-4d2c-93f8-0ae62d8e82cf fired on entity enti_sim_harb_azbiyidj3x2 under the sanctions_or_pep detector after screening flagged a potential PEP match. The alert reached skoor 30 (review band, hard_signal false) and was routed to review because the detector always routes to review. The linked transfer is acht_sim_harb_595mczek745, an outgoing ACH credit of $191.22 USD, status SETTLED, with no return code.
What the evidence shows. The entity record shows a PERSON, verification status VERIFIED, high_risk false, review reasons none, and last screened 2026-08-16, one month before alert open. The pep_potential signal carries weight 15. A second signal, returns.counterparty_prior_any, also carries weight 15, indicating the counterparty has prior returns on file, but the transfer itself settled with return code none. The counterparty's country is unknown. Program KRIs show pep_flagged_entities at 1 of 30 entities (watch) and high_risk_entity_share at 0.067 (watch), both program-level and not specific to this entity or transfer. manual_review_aging_hours and ach_unauthorized_return_rate show breach status at the program level, but neither ties to this transfer, which has no return code and settled normally. There are no prior dispositions on this alert.
What was checked. Entity verification status and review reasons, screening recency, transfer status and return code, counterparty return history signal, and program-level KRIs for any pattern connecting to this specific entity or transfer.
What is recommended. The entity is verified, carries no open review reasons, and was screened within the last month. The transfer settled with no return code and a modest dollar amount ($191.22). The counterparty_prior_any signal is noted but not corroborated by any issue on this transfer. Program-level KRI breaches (manual_review_aging_hours, ach_unauthorized_return_rate) are not shown to be linked to this entity or transfer and should be tracked separately at the program level, not through this alert. No fund hold is in place, so release does not apply. Close this alert.
- Recommendation
- close
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Entity verification is VERIFIED with review reasons none, and last screened 2026-08-16, recent to alert open.
- Transfer settled with return code none; no adverse outcome tied to this transaction.
- Skoor 30 is in the review band with hard_signal false, and routeReason indicates this detector always routes to review regardless of severity.
- The counterparty_prior_any signal (+15) is present but unconfirmed by any return on this specific transfer; counterparty country is unknown, limiting further tracing.
- Program KRI breaches (manual_review_aging_hours, ach_unauthorized_return_rate) are program-wide metrics and not evidenced as connected to this entity or transfer specifically.
- No prior dispositions exist, and no fund hold is described, so escalate or release are not supported by the evidence.
Evidence
{
"n": 1231,
"band": "review",
"skoor": 30,
"signals": [
{
"code": "entity.pep_potential",
"detail": "potential PEP match",
"weight": 15
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.pep_potential | +15 | potential PEP match | |
| returns.counterparty_prior_any | +15 | 1 prior return(s) other than NSF | |
| returns.entity_rate_gt_threshold | +15 | entity unauthorized return rate 1/29 originated ACH debits in 60d |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.