Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Northwind Payroll (simulated)
- Subject
- entity enti_sim_nort_91eod4q93y
- Transfer
- acht_sim_nort_5b2ri9jnd2 · $1,295.04 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert a8d1929a-751b-4216-94b3-05e1d9453fc7 was generated by the sanctions_or_pep detector on entity enti_sim_nort_91eod4q93y after screening flagged the entity as high risk (PEP status: no). The alert was opened under the Northwind Payroll program in connection with a single completed ACH outgoing credit of $1,295.04 to counterparty cpty_sim_nort_8sc8a2ha4a.
What the evidence shows. The entity-level score is 20, band clear, with hard_signal false. The only contributing signal is entity.high_risk (+20); there are no additional review reasons listed. The entity is BUSINESS type, VERIFIED, PEP no, country US, last screened 2026-08-18. The transfer itself carries the same score (20, clear, n=80, confidence 0.49) and completed with no return code, indicating no rail-level rejection or unauthorized-return issue. Program KRIs show most metrics in the ok range (frozen_accounts, overdraft_events, manual_review_rate, reserve_coverage_ratio, ach return rates, sanctioned_country_transfers, counterparty_concentration_top1). A few KRIs sit at watch (hold_aging_hours, pep_flagged_entities, high_risk_entity_share) and one at breach (manual_review_aging_hours, n=11), but none of these are tied to this specific entity or transfer in the evidence provided; they describe program-wide conditions rather than facts about this alert's subject.
What was checked. Reviewed the alert score and band, the hard_signal flag, the entity's verification and PEP status, the transfer status and return code, and the program-level KRI snapshot for any signal that would connect this specific entity or transfer to the elevated program metrics. No review reasons were listed for the entity, no return code was recorded for the transfer, and there are no prior dispositions on this alert.
What is recommended. Nothing in the evidence for this specific alert requires a hold or further transaction-level action: the transfer is already completed, the entity is verified, PEP status is no, and the score is clear with hard_signal false. The route reason is 'detector always reviewed,' meaning this alert was opened as a matter of course rather than due to elevated risk. The program-level watch/breach KRIs (manual_review_aging_hours, pep_flagged_entities, high_risk_entity_share) are not shown to be caused by or connected to this entity or transfer, so they do not change the disposition of this specific alert, though they may warrant separate program-level attention outside this alert.
- Recommendation
- close
- Confidence
- 0.78
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Alert score is 20, band clear, hard_signal false, with only one contributing signal (entity.high_risk) and no additional review reasons.
- Entity is VERIFIED, PEP no, high risk true but with no listed review reasons beyond the screening flag itself.
- Transfer acht_sim_nort_5b2ri9jnd2 is COMPLETED with no return code, so there is no held transfer to release and no rail-level failure to investigate.
- Program KRIs are mostly ok; the watch/breach KRIs are program-wide and not evidenced to be specific to this entity or transfer.
- No prior dispositions exist, and the route reason indicates mandatory review rather than elevated risk, supporting closure absent further evidence.
Evidence
{
"n": 80,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.