Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Northwind Payroll (simulated)
- Subject
- entity enti_sim_nort_91eod4q93y
- Transfer
- acht_sim_nort_1kb5v50y17p · $1,842.98 · ach outgoing
- Skoor at alert
- 35 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert b489c2f6-c95a-44c7-b8b7-326ec946076a was opened on 2026-09-17 by the sanctions_or_pep detector on entity enti_sim_nort_91eod4q93y, following an outgoing ACH credit of $1,842.98 (transfer acht_sim_nort_1kb5v50y17p) that settled with no return code.
What the evidence shows. The entity is a verified US business, flagged high risk by screening but not PEP, with no review reasons on file and a screening date of 2026-06-26, about three months before this alert opened. The alert score is 35, placing it in the review band, and hard_signal is false. The transfer itself scored 35/review with two signals: entity.high_risk (+20) and returns.counterparty_prior_any (+15); no detail is given on what prior returns the counterparty is associated with, and the counterparty's country is unknown. The route reason states this detector always routes to review, independent of score. Program KRIs show high_risk_entity_share and pep_flagged_entities in watch status, and manual_review_aging_hours in breach (1434.7 hours average, n=3), but these are program-level metrics not specific to this entity or transfer. No prior dispositions exist for this alert.
What was checked. Entity verification status, PEP flag, high-risk flag, and last screening date. Transfer status, return code, and settlement outcome. Alert score, band, and hard-signal flag. Program KRIs for related risk indicators. Prior disposition history.
What is recommended. Close the alert. The transfer has settled with no return, the entity is verified and not PEP, and screening is current. The counterparty_prior_any signal lacks supporting detail and the counterparty's country is unknown, which limits certainty but does not by itself indicate an unresolved issue on this specific transfer. The program-level manual_review_aging_hours breach should be flagged separately to the program owner as an operational matter, not tied to this alert's disposition.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:30Z
- Rationale
- Entity is VERIFIED, not PEP, with no review reasons and screening within the last three months.
- Transfer settled with no return code; no evidence of a failed or blocked payment.
- Alert score (35) is in the review band but hard_signal is false, and routeReason indicates this detector always routes to review regardless of risk level.
- The returns.counterparty_prior_any signal lacks detail on the nature or recency of prior returns, and counterparty country is unknown, introducing some uncertainty.
- Program KRI manual_review_aging_hours is in breach, but this is a program-wide metric (n=3) not specific to this entity or transfer and does not change the disposition of this alert.
- No prior dispositions exist to indicate a recurring pattern for this entity.
Evidence
{
"n": 390,
"band": "review",
"skoor": 35,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening | |
| returns.counterparty_prior_any | +15 | 1 prior return(s) other than NSF |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.