Alert · reviewed · open
Activity on an entity flagged by screening (PEP status potential).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- entity enti_sim_harb_azbiyidj3x2
- Transfer
- acht_sim_harb_calfj8fi5t2 · $261.66 · ach outgoing
- Skoor at alert
- 15 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert e9b7e54a fired from the sanctions_or_pep detector on entity enti_sim_harb_azbiyidj3x2 ("Potential Pep 1"), triggered by a single signal: entity.pep_potential (weight 15). This is a potential PEP match, not a confirmed one. The alert score is 15, placing it in the 'clear' band, and hard_signal is false. Route was 'reviewed' because this detector is always reviewed, per routeReason.
What the evidence shows. The entity record shows verification status VERIFIED, high_risk false, review reasons none, and last screened 2026-08-16T23:44:46.000Z, roughly one month before this alert opened. Country is US. The transfer tied to this alert (acht_sim_harb_calfj8fi5t2) is an outgoing ACH CREDIT of $261.66 with status RETURNED and return code R10 (customer advises unauthorized). This return code relates to authorization dispute, not to sanctions or PEP status, and is a separate matter from the detector's basis. The transfer's own skoor is also 15/clear. Program KRIs show pep_flagged_entities at 1 of 30 entities (watch) and high_risk_entity_share at 6.7% (watch), both program-level and not specific to this entity beyond the existing flag. Manual_review_aging_hours (breach) and ach_unauthorized_return_rate (breach) are also program-level metrics, not attributed to this entity or transfer in the evidence provided.
What was checked. Checked the alert's detector, score, and band; the entity's verification status, high-risk flag, review reasons, and last screening date; the associated transfer's status, return code, and skoor; program KRIs for related watch/breach conditions; and prior dispositions, of which there are none for this alert.
What is recommended. Close this alert. The entity is already verified, screened within the past month, carries no open review reasons, and the alert score sits in the clear band with no hard signal. The R10 return on the linked transfer concerns transaction authorization, not PEP/sanctions status, and is not evidence of a sanctions or PEP concern on this entity. The transfer is already RETURNED, not held, so no release action applies. Program-level KRI watches and breaches (pep_flagged_entities, manual_review_aging_hours, ach_unauthorized_return_rate) are noted for program-level review but do not by themselves indicate this specific alert requires escalation, since none are tied in the evidence to this entity or transfer.
- Recommendation
- close
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Detector fired on a single potential PEP signal, weight 15, alert score 15, band clear, hard_signal false.
- Entity is VERIFIED, high_risk false, review reasons none, last screened within the past month.
- Transfer is already RETURNED (R10, unauthorized), not held, so no funds-movement action is pending on this alert.
- R10 return code reflects an authorization dispute unrelated to the PEP/sanctions basis of this alert.
- Program KRI watches/breaches are entity/transfer-agnostic in the evidence given and do not establish a pattern specific to this subject.
- No prior dispositions exist to indicate recurring concern for this entity.
Evidence
{
"n": 706,
"band": "clear",
"skoor": 15,
"signals": [
{
"code": "entity.pep_potential",
"detail": "potential PEP match",
"weight": 15
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.pep_potential | +15 | potential PEP match |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.