Alert · reviewed · held
Transaction Risk Skoor 80 (hold band) on a $2,400.00 ach transfer: entity.denied, entity.high_risk.
- Detector
- skoor_hold
- Severity
- high
- Program
- Northwind Payroll (simulated)
- Subject
- transfer acht_sim_nort_1c6mqyec3s6
- Transfer
- acht_sim_nort_1c6mqyec3s6 · $2,400.00 · ach outgoing
- Skoor at alert
- 80 hold
- Hard signal
- yes
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert a576dc60-c4b3-4d64-a8ef-a18df27c9b4f fired on ACH outgoing transfer acht_sim_nort_1c6mqyec3s6 for $2,400.00 under program Northwind Payroll (simulated). The transaction risk skoor was 80, placing it in the hold band, driven by a hard signal entity.denied (weight 60) and entity.high_risk (weight 20).
What the evidence shows. The counterparty entity enti_sim_nort_4ndrgqqi3r is a PERSON record with verification status DENIED, high_risk true, and review reason sanctions_match, last screened 2026-06-24. The transfer status is SETTLED with no return code, meaning the $2,400.00 has already moved despite the denied verification and sanctions match flag. The hard signal flag is true and routeReason is 'hard signal,' confirming the system intended this for auto-hold, but the transfer record shows settlement already occurred.
What was checked. Reviewed the alert evidence block (n=675, confidence 0.7, autoHold true), the transfer record (status SETTLED, no return code, counterparty country unknown), the entity record (DENIED verification, sanctions_match reason, pep no), and program-level KRIs. Verification_denial_rate is 0.030 (n=33, ok band), high_risk_entity_share is 0.061 (watch), pep_flagged_entities is 1 (watch), and manual_review_aging_hours is 1434.7 (n=8, breach). No prior dispositions exist for this alert.
What is recommended. This transfer is already settled, so it cannot be held or released; funds have moved. The combination of a DENIED verification with a sanctions_match reason and settlement having occurred anyway indicates a possible control gap between screening/hold logic and settlement processing, not an isolated alert. Given the manual_review_aging_hours breach and watch-level high_risk_entity_share and pep_flagged_entities KRIs, this should be escalated for review of why a hard-signal, sanctions-flagged transfer settled rather than being held, and whether other transfers from this entity or program followed the same path.
- Recommendation
- escalate
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Hard signal entity.denied with sanctions_match reason present on a settled transfer indicates the auto-hold control may not have prevented settlement.
- Transfer status is SETTLED with no return code, so 'hold' or 'release' actions do not apply to funds already moved.
- Program KRIs show manual_review_aging_hours in breach and high_risk_entity_share/pep_flagged_entities in watch band, suggesting broader review backlog and risk concentration beyond this single alert.
- Evidence confidence on the skoor evaluation is 0.7 (not maximal), and counterparty country is unknown, limiting full certainty on entity risk classification.
- No prior dispositions exist to indicate this pattern has already been reviewed or explained.
Evidence
{
"n": 675,
"band": "hold",
"skoor": 80,
"signals": [
{
"code": "entity.denied",
"hard": true,
"detail": "entity verification DENIED",
"weight": 60
},
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"autoHold": true,
"confidence": 0.7,
"routeReason": "hard signal"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.denied | +60 | yes | entity verification DENIED |
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.