Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- entity enti_sim_harb_skonrvy3x6
- Transfer
- acht_sim_harb_66tynfmi4n2 · $428.72 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert bc5dfff8 fired from the sanctions_or_pep detector on entity enti_sim_harb_skonrvy3x6 after screening flagged it as high risk. The detector routes all high-risk-screening hits to review regardless of score. The linked transfer is a completed ACH outgoing credit of $428.72 to counterparty cpty_sim_harb_47kc6pf044k, with no return code recorded.
What the evidence shows. The alert score is 20, banded clear, driven by a single signal: entity.high_risk (+20). Hard signal is false. The entity record shows verification status VERIFIED, PEP status no, review reasons none, and a last-screened date of 2026-08-27, about three weeks before this alert opened. The transfer itself completed with no return code, so there is no evidence of a failed or reversed payment. Program-level KRIs show some items in watch or breach status (manual_review_aging_hours, ach_unauthorized_return_rate) but these are portfolio-wide metrics with no field tying them specifically to this entity or transfer.
What was checked. Reviewed the alert signal composition, entity screening and verification status, the transfer status and return code, the program's declared volume and rails, and the program KRI panel for any entity-specific linkage. No prior dispositions exist for this entity.
What is recommended. Close the alert. The single driver is a routed-by-policy high-risk flag on an already-verified, non-PEP entity, the transfer completed without a return code, and no other signal in this alert's evidence indicates unresolved risk. The program-level KRI breaches (manual_review_aging_hours, ach_unauthorized_return_rate) are noted for awareness but are not tied to this entity or transfer in the evidence provided, so they do not support escalation on this specific alert.
- Recommendation
- close
- Confidence
- 0.78
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Score 20 in clear band with only one signal, entity.high_risk (+20); hard_signal is false.
- Entity is VERIFIED, PEP no, review reasons none, last screened 2026-08-27T13:10:35.000Z, about 3 weeks before alert open.
- Transfer acht_sim_harb_66tynfmi4n2 status COMPLETED, return code none; no evidence of a block, reversal, or held funds, so release is not applicable.
- routeReason is 'detector always reviewed', meaning this alert would fire regardless of underlying risk level, consistent with a routine clear-band disposition.
- Program KRI breaches (manual_review_aging_hours, ach_unauthorized_return_rate) are portfolio-level and not linked in the evidence to this entity or transfer, so they do not meet the bar for escalate.
- Counterparty country is unknown, which is a minor evidence gap; confidence is set below 0.85 to reflect this.
Evidence
{
"n": 231,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.