Alert · reviewed · open
The entity's first transfer, $1,104.13, above the program median, came 0.0 hours after verification.
- Detector
- rapid_onboarding
- Severity
- medium
- Program
- Meridian Remit (simulated)
- Subject
- transfer acht_sim_meri_aiqkia8j9q7
- Transfer
- acht_sim_meri_aiqkia8j9q7 · $1,104.13 · ach outgoing
- Skoor at alert
- null unscored
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. The entity's first transfer, an outgoing ACH credit of $1,104.13, settled 0.0 hours after identity verification. This amount is above the program median of $641.38. The rapid_onboarding detector fired and the alert was routed to review because the detector is not auto-closable.
What the evidence shows. The transfer has already settled, so there is no held transfer to release. The entity is flagged high risk true, is a business ('High Risk Trading 2'), and is VERIFIED with no open review reasons and no PEP flag. Screening was last done 2026-06-26, within the program's normal range (stale_screening_share is 0.03 across n=30, marked ok). The counterparty is a first-time counterparty with country unknown, and the transfer skoor is unscored (n=0, no history to compare against). Signals attached to the transfer are entity.high_risk(+20) and counterparty.first_time(+10), both descriptive rather than derived from a scored model. Program KRIs are largely ok or unmeasured; pep_flagged_entities is at watch (1 of 30) but this entity is not the PEP flagged one (pep: no). No return code is present on the transfer, and ach_overall_return_rate and ach_unauthorized_return_rate are both 0 across n=3, though that sample is small.
What was checked. Transfer status and settlement, entity verification and risk flags, screening recency, counterparty history, transfer-level skoor, program-level KRIs, and prior dispositions for this entity or transfer.
What is recommended. The transfer has already settled, so holding funds is not an option. The evidence shows a verified entity with no adverse screening findings, but the combination of high-risk designation, first-time counterparty with unknown country, and a same-day transfer above the program median warrants a person's review of the counterparty and the entity's risk classification before this pattern repeats. This is not a case for close given the unresolved counterparty country and high-risk flag; escalate to a person for counterparty verification and monitoring of subsequent transfers from this entity.
- Recommendation
- escalate
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:30Z
- Rationale
- Transfer already settled; no funds available to hold or release.
- Entity is flagged high_risk true and this is a first transfer with a first-time counterparty of unknown country, an unresolved risk pair per the evidence.
- Entity verification is current and screening is not stale, reducing urgency but not eliminating the counterparty risk gap.
- Transfer skoor is unscored (n=0) and program KRIs relevant to risk (pep_flagged_entities) show watch status at portfolio level, though not directly tied to this entity.
- No return code or negative outcome on this transfer itself, which lowers confidence that this is fraud rather than a normal but high-risk-flagged onboarding.
- Evidence is not sufficient for outright closure given the unresolved counterparty country field and the high-risk entity flag combination.
Evidence
{
"n": 0,
"band": "unscored",
"skoor": null,
"typology": "rapid_onboarding",
"confidence": null,
"thresholds": {
"hours": 24
},
"medianCents": "64138",
"routeReason": "detector not auto-closable",
"hoursSinceVerification": 0
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.high_risk | +20 | entity marked high risk by screening | |
| counterparty.first_time | +10 | first transfer with this counterparty | |
| counterparty.first_time_and_large | +15 | amount above the program p95 (109935) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.