Alert · reviewed · open
Activity on an entity flagged by screening (PEP status potential).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Lantern Lending (simulated)
- Subject
- entity enti_sim_lant_866sn4vcjd
- Transfer
- acht_sim_lant_k4vimpld72 · $1,297.62 · ach outgoing
- Skoor at alert
- 15 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An automated sanctions/PEP screening alert was opened on entity enti_sim_lant_866sn4vcjd ("Potential Pep 3") after a potential PEP match was flagged during screening. The alert is tied to a single ACH outgoing credit transfer (acht_sim_lant_k4vimpld72) for $1,297.62 USD, which settled with no return code.
What the evidence shows. The alert skoor is 15, placing it in the clear band, and hard_signal is false, meaning no hard sanctions or watchlist match was made. The only contributing signal is entity.pep_potential (+15), described as a potential PEP match, not a confirmed one. The entity record shows verification status VERIFIED, high_risk false, and review reasons listed as none. The entity was last screened 2026-06-25, roughly two months before this alert opened, which is within the program's stale_screening_share threshold (0.061, marked ok). The transfer itself settled normally with no return code, and program-level ACH return rates are all 0. Program KRIs are largely in the ok/watch range: pep_flagged_entities=1 (watch, n=33), manual_review_aging_hours=1433.5 (breach, n=2), but these are program-wide metrics not specific findings against this entity or transfer.
What was checked. Reviewed the alert's skoor and band, the hard_signal flag, the entity's verification and risk status, review reasons, last screening date, the transfer's settlement status and return code, and the program-level KRI panel for corroborating signals of a broader pattern (sanctioned_country_transfers=0, verification_denial_rate=0.03, high_risk_entity_share=0.03, reserve_coverage_ratio=8.67). No prior dispositions exist for this alert.
What is recommended. Close the alert. The entity is verified, not flagged high risk, has no listed review reasons, and the PEP match is potential rather than confirmed. The associated transfer settled without incident and program-level indicators do not show a pattern implicating this entity beyond the single watch-level KRI (pep_flagged_entities). The manual_review_aging_hours breach is a program-level metric with n=2 and is not evidenced as connected to this specific alert; if a person wants to confirm that separately, that is a distinct KRI review, not a reason to hold this transfer or entity.
- Recommendation
- close
- Confidence
- 0.74
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:30Z
- Rationale
- Skoor 15 in clear band; hard_signal false; only one weighted signal (entity.pep_potential, potential match, not confirmed).
- Entity verification status is VERIFIED, high_risk false, review reasons none.
- Transfer settled with no return code; ACH return rates across the program are 0.
- Program KRIs show no sanctioned-country transfers, low verification denial rate, and stale_screening_share within ok range.
- Manual_review_aging_hours breach is a separate program-level metric (n=2) not directly tied to this entity or transfer, so it does not by itself justify escalation of this specific alert.
- No prior dispositions to indicate recurring concern for this entity.
Evidence
{
"n": 226,
"band": "clear",
"skoor": 15,
"signals": [
{
"code": "entity.pep_potential",
"detail": "potential PEP match",
"weight": 15
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.pep_potential | +15 | potential PEP match |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.