Alert · reviewed · open
Activity on an entity flagged by screening (PEP status no, high risk).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Meridian Remit (simulated)
- Subject
- entity enti_sim_meri_5if3mzfr9pn
- Transfer
- acht_sim_meri_8iva8oitbfn · $931.21 · ach outgoing
- Skoor at alert
- 20 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert ee78684c-545f-4f48-ac7e-5a867428818e fired from the sanctions_or_pep detector on entity enti_sim_meri_5if3mzfr9pn, flagged only because screening marked it high risk (PEP status no). The route was reviewed because this detector is always reviewed, not because of an unusual score.
What the evidence shows. The entity-level skoor is 20, band clear, hard_signal false, driven by a single signal: entity.high_risk (weight 20). No review reasons are listed, PEP is no, verification status is VERIFIED, and the entity was last screened 2026-06-26, about three months before the alert opened. The linked ACH transfer (acht_sim_meri_8iva8oitbfn, $931.21 debit) is SETTLED with no return code, and the counterparty's country is unknown but there is no sanctioned-country signal on the transfer. The transfer's own skoor is also 20, band clear, with n=654 and confidence 1, and the only contributing signal is the same entity.high_risk flag. Program KRI sanctioned_country_transfers=0 (n=537, ok) and stale_screening_share=0 (n=30, ok) do not support a sanctions concern tied to this entity.
What was checked. Reviewed the alert evidence, the entity record, the linked transfer and its settlement/return status, the transfer-level skoor and signals, program declared volume and rails, and all listed program KRIs. Prior dispositions: none. Program KRIs show some values in watch or breach (reserve_coverage_ratio 0.896 breach, manual_review_aging_hours 1146.86 breach, ach_unauthorized_return_rate 0.008 breach, hold_aging_hours watch, pep_flagged_entities watch), but none of these are tied by the evidence to this specific entity or transfer, and no signal in this alert references them.
What is recommended. Close this alert. The only driver is a generic high-risk classification with no PEP hit, no adverse review reasons, a verified entity, a settled transfer with no return code, and a clear band score with no hard signal. The program-level KRI breaches (reserve coverage, manual review aging, ACH unauthorized returns) are noted for the risk team's general awareness but are not evidenced as connected to this entity or transfer, so they do not change the disposition of this specific alert. A person should independently track those KRI breaches outside this alert if not already being monitored.
- Recommendation
- close
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Entity and transfer skoor are both 20, band clear, hard_signal false.
- Single contributing signal is entity.high_risk; no PEP, no review reasons, no sanctioned-country signal.
- Entity is VERIFIED and was screened within the last three months (2026-06-26).
- Linked transfer is SETTLED with no return code, no unauthorized or administrative return flags at the transfer level.
- Program KRI breaches (reserve_coverage_ratio, manual_review_aging_hours, ach_unauthorized_return_rate) exist but the evidence does not tie them to this entity or transfer, so they do not independently justify escalation of this alert.
- No prior dispositions exist to indicate a recurring or worsening pattern for this entity.
Evidence
{
"n": 654,
"band": "clear",
"skoor": 20,
"signals": [
{
"code": "entity.high_risk",
"detail": "entity marked high risk by screening",
"weight": 20
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.