Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Northwind Payroll (simulated)
- Subject
- entity enti_sim_nort_91eod4q93y
- Transfer
- acht_sim_nort_9x41edsw2ry · $3,645.20 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert enti_sim_nort_91eod4q93y was opened by the sanctions_or_pep detector because screening flagged the entity as high risk. Score at alert time was 20, band clear, hard signal false. The route is 'reviewed' because this detector is always reviewed, not because the score triggered escalation.
What the evidence shows. The single signal driving the score is entity.high_risk (weight 20). The entity record shows PEP status no, review reasons none, verification status VERIFIED, and last screened 2026-08-18, about a month before the transfer. The linked transfer (acht_sim_nort_9x41edsw2ry, $3,645.20 USD ACH outgoing credit) is already SETTLED with no return code, so there are no funds currently held on this alert. The transfer's own skoor is also 20/clear with the same single signal. Counterparty country is unknown, which limits what can be confirmed about the receiving side, but no other signal (sanctioned_country_transfers, velocity anomaly, concentration) fired on this transfer.
What was checked. Reviewed entity verification and PEP status, screening recency, transfer status and return code, and transfer-level score signals. Reviewed program KRIs for context: most are in the 'ok' band (ach_overall_return_rate 1.13%, reserve_coverage_ratio 1.62, sanctioned_country_transfers 0, counterparty_concentration_top1 10.3%). Three KRIs sit at 'watch' (hold_aging_hours, pep_flagged_entities, high_risk_entity_share) and one is at 'breach' (manual_review_aging_hours, 1434.7 hours on n=8). None of these breach/watch KRIs are specific to this entity or this transfer; they describe program-wide review timing and composition, not evidence that this particular transfer is problematic. Prior dispositions: none on file for this alert.
What is recommended. Close this alert. The entity is verified, not PEP, has no open review reasons, and was screened within the last month. The associated transfer settled without a return code and carries no elevated transfer-level score. Nothing in the evidence requires holding funds (the transfer already settled) or requires escalation tied specifically to this entity. Separately, the program-level manual_review_aging_hours breach (1434.7 hours, n=8) is worth flagging to the risk team as an operational backlog issue, but it is not evidence against this entity or transfer and should be tracked outside this alert.
- Recommendation
- close
- Confidence
- 0.78
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Score 20, band clear, hard_signal false; single signal entity.high_risk with no corroborating signals
- Entity verified, PEP no, review reasons none, screened 2026-08-18 (about a month before the transfer)
- Transfer already SETTLED with no return code; no funds are currently held so 'release' does not apply
- Program KRIs mostly ok; watch/breach items (hold_aging_hours, pep_flagged_entities, high_risk_entity_share, manual_review_aging_hours) are program-wide and not specific to this entity or transfer
- Counterparty country unknown limits full certainty, which caps confidence below very high
Evidence
{
"n": 1053,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.