Alert · reviewed · held
A $2,400.00 ach transfer was initiated for an entity whose verification was denied.
- Detector
- denied_entity_activity
- Severity
- high
- Program
- Northwind Payroll (simulated)
- Subject
- transfer acht_sim_nort_9d0fdqbr3s3
- Transfer
- acht_sim_nort_9d0fdqbr3s3 · $2,400.00 · ach outgoing
- Skoor at alert
- 100 hold
- Hard signal
- yes
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An outgoing ACH credit transfer of $2,400.00 (acht_sim_nort_9d0fdqbr3s3) was flagged by the denied_entity_activity detector at high severity. The transfer's counterparty entity, enti_sim_nort_4ndrgqqi3r ('Denied Origin 0'), has a verification status of DENIED with review reason sanctions_match. The transfer has already reached status SETTLED.
What the evidence shows. The alert carries a skoor of 100 in the hold band with a hard signal (entity.denied, weight 60), plus entity.high_risk (+20) and returns.counterparty_prior_unauthorized (+40), yielding routeReason 'hard signal' and autoHold true. The entity record confirms DENIED verification, high_risk true, and a sanctions_match review reason, last screened 2026-06-24. Despite the hold band and autoHold flag, the transfer status shows SETTLED with no return code, meaning funds moved before or without the hold taking effect. The prior-unauthorized-return signal on this same counterparty indicates this is not an isolated event.
What was checked. Reviewed the alert evidence, transfer record, entity verification record, program KRIs, and prior dispositions. Program KRIs show verification_denial_rate at 0.030 (n=33, ok) and high_risk_entity_share at 0.061 (n=33, watch), both within or near normal watch bands, so this does not by itself indicate a program-wide denial-rate problem. However manual_review_aging_hours is in breach (1434.7 hrs, n=11) and hold_aging_hours is at watch (518.3 hrs, n=1), suggesting reviews including holds are not being processed promptly. No prior dispositions exist for this alert.
What is recommended. This is not a transfer currently held from moving, since status is SETTLED, so 'release' does not apply. Given a hard-signal sanctions_match denial, a settled transfer to a denied entity, and a prior-unauthorized-return signal on the same counterparty, this points to a pattern beyond a single alert: a denied/sanctions-flagged entity received settled funds despite an auto-hold designation. This should be escalated for review of how the hold was bypassed, potential sanctions/OFAC exposure, and whether other transfers to this counterparty require the same scrutiny, alongside the aging breach in manual review handling.
- Recommendation
- escalate
- Confidence
- 0.78
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Hard signal entity.denied (weight 60) with skoor 100 in hold band and autoHold true indicates the system intended to stop this transfer.
- Entity review reason is sanctions_match, which raises regulatory exposure beyond a routine denial.
- Transfer status is SETTLED despite the hold band, meaning the hold did not prevent movement of funds, which is itself an anomaly worth escalation.
- Signal returns.counterparty_prior_unauthorized (+40) indicates this counterparty has a history, suggesting a pattern rather than a one-off event.
- Program KRI manual_review_aging_hours is in breach (1434.7 hrs) and hold_aging_hours is at watch (518.3 hrs), consistent with delayed handling that could explain why a hold-band transfer settled.
- Verification_denial_rate and high_risk_entity_share are within normal/watch ranges, so this is not evidence of a program-wide denial spike; the escalation is warranted on the specific sanctions/settlement facts, not systemic denial volume.
Evidence
{
"n": 1322,
"band": "hold",
"skoor": 100,
"signals": [
{
"code": "entity.denied",
"hard": true,
"detail": "entity verification DENIED",
"weight": 60
}
],
"autoHold": true,
"routeReason": "hard signal"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.denied | +60 | yes | entity verification DENIED |
| entity.high_risk | +20 | entity marked high risk by screening | |
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.