Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Meridian Remit (simulated)
- Subject
- entity enti_sim_meri_5if3mzfr9pn
- Transfer
- acht_sim_meri_6jto1nx7c08 · $447.29 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert bb7df757-c991-46a1-bb33-5358c74fe4ff fired on entity enti_sim_meri_5if3mzfr9pn under the sanctions_or_pep detector because screening marked the entity high risk. The detector always routes to review regardless of score. The associated activity is a single outgoing ACH credit transfer (acht_sim_meri_6jto1nx7c08) for $447.29, already settled, with no return code.
What the evidence shows. The entity-level skoor is 20, banded clear, with hard_signal false, driven solely by the entity.high_risk signal (+20). The entity record shows PEP status no, verification VERIFIED, no review reasons listed, last screened 2026-08-27, business type, US country. The transfer itself carries the same skoor of 20, clear band, based on n=914 with confidence 1, and no return or unauthorized flags. Program-level KRIs show several breaches (reserve_coverage_ratio 0.53, ach_unauthorized_return_rate 0.0105, sanctioned_country_transfers=2, manual_review_aging_hours 1146.9) but these are aggregate program metrics, not specific to this entity or transfer. There are no prior dispositions on this alert.
What was checked. Reviewed the alert signal composition, entity screening attributes (PEP, verification, review reasons, last screen date), the linked transfer's status and return code, the transfer-level skoor and band, and the program KRI panel for any entity-specific linkage. No sanctions match, no PEP flag, no adverse review reason, and no return/unauthorized activity were found tied to this specific entity or transfer.
What is recommended. Close this alert. The only driver is a generic high-risk flag with no PEP, no unresolved review reason, recent screening, and a settled transfer with no return issues. The program-level KRI breaches (reserve coverage, unauthorized returns, sanctioned country transfers) are not connected in this evidence to this specific entity and should be tracked separately at the program level rather than through this alert.
- Recommendation
- close
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Skoor 20, band clear, hard_signal false at both entity and transfer level.
- Entity is verified, PEP no, has no review reasons, and was screened within the last month.
- The single associated transfer is settled with no return code and no unauthorized or administrative return flags.
- Program KRI breaches (reserve_coverage_ratio, ach_unauthorized_return_rate, sanctioned_country_transfers) exist but the evidence does not tie them to this specific entity or transfer, so they do not support escalating this particular alert.
- No prior dispositions exist to indicate a recurring pattern for this entity.
Evidence
{
"n": 914,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.