Alert · reviewed · open
Activity on an entity flagged by screening (PEP status potential).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Meridian Remit (simulated)
- Subject
- entity enti_sim_meri_28dfpclz9pj
- Transfer
- acht_sim_meri_cozesqcj9z3 · $301.13 · ach outgoing
- Skoor at alert
- 15 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert f37eed74-abcf-49c6-9e95-496686c04718 fired on entity enti_sim_meri_28dfpclz9pj under the sanctions_or_pep detector because screening flagged a potential PEP match. The alert is routed to review by policy (routeReason: 'detector always reviewed'), not because of an elevated score. The linked activity is a single outgoing ACH credit of $301.13 USD (acht_sim_meri_cozesqcj9z3), already SETTLED, with no return code.
What the evidence shows. Transfer-level skoor is 15, band clear, with hard_signal false; the only contributing signal is entity.pep_potential at weight 15 (n=72, confidence 0.395). The entity record shows PERSON 'Potential Pep 2', verification VERIFIED, high_risk false, review reasons none, country US, last screened 2026-06-25T12:01:30.000Z (about seven weeks before the transfer). No sanctioned-country nexus is indicated; counterparty country is listed unknown but the transfer settled without a return. Program-level KRIs show pep_flagged_entities at a 'watch' level (1 of 30 entities, 3.3%), but most other KRIs are unmeasured (n=0) and the two that are measured (stale_screening_share, verification_denial_rate) sit at ok levels (3.3%). There are no prior dispositions on this entity or alert.
What was checked. Detector and score fields, hard_signal flag, route reason, transfer status and return code, entity verification and risk flags, entity screening recency, program KRI panel, and prior disposition history. No sanctions hit, adverse media, or high-risk flag is present in the evidence provided.
What is recommended. The entity is verified, not flagged high risk, has no open review reasons, and was screened within the last two months. The associated transfer already settled with no return code, so there is no pending movement to hold. The single supporting signal (potential PEP match) is the reason the detector always routes to review, not an indication of elevated risk on its own. Nothing in the evidence points to a need for further action by a person at this time; the program-level PEP watch metric is based on a small population (n=30) and does not itself implicate this entity beyond what is already reflected. Recommend closing the alert. If screening cadence or entity risk classification changes, or if a review reason is later populated, the alert should be reopened.
- Recommendation
- close
- Confidence
- 0.68
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:30Z
- Rationale
- Transfer skoor is 15 in the 'clear' band with hard_signal false, and the sole signal is entity.pep_potential at weight 15.
- Entity is VERIFIED, high_risk false, and review reasons are listed as none, with last screening on 2026-06-25T12:01:30.000Z.
- The transfer (acht_sim_meri_cozesqcj9z3) is already SETTLED with no return code, so there is no fund movement to hold or release.
- Route reason is 'detector always reviewed,' indicating routing is policy-driven rather than evidence of elevated risk.
- Program KRI pep_flagged_entities is at 'watch' (1/30) but this is a small-population metric and does not add entity-specific adverse evidence.
- Most other program KRIs are unmeasured (n=0), and prior dispositions are none, so confidence is moderated rather than high.
Evidence
{
"n": 72,
"band": "clear",
"skoor": 15,
"signals": [
{
"code": "entity.pep_potential",
"detail": "potential PEP match",
"weight": 15
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.pep_potential | +15 | potential PEP match |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.