Alert · reviewed · open
Activity on an entity flagged by screening (PEP status potential).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Lantern Lending (simulated)
- Subject
- entity enti_sim_lant_866sn4vcjd
- Transfer
- acht_sim_lant_6rnw6vfte4l · $1,991.68 · ach outgoing
- Skoor at alert
- 25 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert c57a9e80-6a67-4b03-b2f9-d3a073f598e9 fired on entity enti_sim_lant_866sn4vcjd (PERSON, 'Potential Pep 3') under the sanctions_or_pep detector due to a potential PEP match. The entity is linked to one settled ACH outgoing debit of $1,991.68 (acht_sim_lant_6rnw6vfte4l) dated 2026-09-02, to a first-time counterparty with unknown country.
What the evidence shows. The alert score is 25, band clear, hard_signal false, with routing driven by a standing rule ('detector always reviewed') rather than an elevated score. The entity record shows verification VERIFIED, high_risk false, and review reasons none, with last screening on 2026-09-01, one day before the transfer. The transfer itself carries the same clear-band score (25) with two contributing signals: entity.pep_potential (+15) and counterparty.first_time (+10), neither individually or combined reaching a concerning threshold. The transfer settled with no return code. Program KRIs are mostly ok; pep_flagged_entities is at watch (1/33) and manual_review_aging_hours is in breach (1433.6 hrs, n=6), but these are program-level metrics not specific to this transfer or entity, and stale_screening_share is 0 (ok), indicating screening currency is not a program-wide problem.
What was checked. Reviewed alert scoring and band, hard-signal flag, entity screening status and verification, review reasons field, transfer status and return code, counterparty first-time signal, program declared volume and rails, and relevant program KRIs (pep_flagged_entities, stale_screening_share, manual_review_aging_hours) for corroborating pattern signals. No prior dispositions exist for this alert.
What is recommended. Close the alert. The entity is verified, has no open review reasons, was screened recently, and the only transfer tied to the alert is small relative to declared program volume, already settled, and scored clear band with no hard signal. The manual_review_aging_hours breach is a program-level operational metric and does not present entity- or transfer-specific evidence requiring a hold on this alert; it may warrant separate operational follow-up outside this disposition.
- Recommendation
- close
- Confidence
- 0.74
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Alert band is clear (25) with hard_signal false.
- Entity is VERIFIED, high_risk false, review reasons none, screened 2026-09-01, one day before the transfer.
- Transfer is SETTLED with no return code; nothing is pending or held.
- Contributing signals (entity.pep_potential +15, counterparty.first_time +10) are individually modest and do not raise the transfer above clear band.
- Program KRIs show no sanctioned_country_transfers, ach_unauthorized_return_rate 0, and stale_screening_share 0, indicating no broader screening failure pattern.
- manual_review_aging_hours is in breach but is a program-wide operational metric, not evidence tied to this specific entity or transfer, so it does not meet the bar for escalation of this alert.
Evidence
{
"n": 637,
"band": "clear",
"skoor": 25,
"signals": [
{
"code": "entity.pep_potential",
"detail": "potential PEP match",
"weight": 15
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.pep_potential | +15 | potential PEP match | |
| counterparty.first_time | +10 | first transfer with this counterparty |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.