Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Northwind Payroll (simulated)
- Subject
- entity enti_sim_nort_91eod4q93y
- Transfer
- acht_sim_nort_9oxn8gh81ba · $1,811.13 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An alert fired on entity enti_sim_nort_91eod4q93y ("High Risk Trading 0") under the sanctions_or_pep detector due to its high-risk screening flag. The associated transfer is a settled outgoing ACH credit of $1,811.13 dated 2026-07-30, under the Northwind Payroll program.
What the evidence shows. The entity is VERIFIED, PEP status is no, and there are no review reasons on file. Last screened 2026-06-26, which is within a normal screening cycle. The transfer skoor is 20, band clear, based on n=405 with confidence 1, driven solely by the entity.high_risk signal (+20). The route reason is "detector always reviewed," meaning this alert opens automatically whenever the flagged entity transacts, independent of transaction-specific risk. The transfer settled with no return code, indicating no rail-level rejection. Program KRIs show sanctioned_country_transfers=0, ach_unauthorized_return_rate=0, and stale_screening_share=0, none of which implicate this entity or transfer. Two KRIs merit note: high_risk_entity_share is at 0.061 (watch, n=33) and pep_flagged_entities=1 (watch, n=33), both program-level and not specific to this alert. manual_review_aging_hours shows breach (1434.7 hours, n=3), which reflects review queue timing, not this transaction's legitimacy.
What was checked. Entity verification status, PEP flag, review reasons, and last screening date. Transfer status, return code, and skoor band. Route reason for the alert. Program-level KRIs for sanctioned-country activity, screening staleness, and high-risk share. Prior dispositions, of which there are none.
What is recommended. Close this alert. The entity is verified, not PEP, has no open review reasons, and was screened within the prior two months. The transfer settled cleanly with no return code, and the transfer-level skoor sits in the clear band. The alert opened only because the detector always reviews activity on any high-risk-flagged entity, not because of a fact specific to this transfer. The elevated high_risk_entity_share and pep_flagged_entities KRIs are program-level watch items and do not point to unresolved risk in this specific alert; they may warrant separate program-level attention outside this disposition.
- Recommendation
- close
- Confidence
- 0.78
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:30Z
- Rationale
- Entity is VERIFIED, PEP=no, review reasons=none, last screened within a normal window (2026-06-26).
- Transfer settled with no return code; transfer skoor is 20, band clear, confidence 1.
- Alert routing reason is a standing rule (detector always reviewed on flagged entities), not a transaction-specific escalation trigger.
- Program KRIs directly relevant to sanctions/high-risk activity (sanctioned_country_transfers, stale_screening_share, ach_unauthorized_return_rate) are all at 0 or ok.
- No prior dispositions exist to indicate a recurring or escalating pattern for this entity.
- high_risk_entity_share and pep_flagged_entities are watch-level and program-wide, not specific evidence against this entity or transfer, so they lower confidence slightly but do not justify hold or escalate on this alert alone.
Evidence
{
"n": 405,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening | |
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.