Alert · reviewed · open
Activity on an entity flagged by screening (PEP status potential).
- Detector
- sanctions_or_pep
- Severity
- high
- Program
- Northwind Payroll (simulated)
- Subject
- entity enti_sim_nort_sr7cv2o3u
- Transfer
- acht_sim_nort_4y6e3eiu1qg · $1,108.94 · ach outgoing
- Skoor at alert
- 15 clear
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An outgoing ACH debit of $1,108.94 USD from entity enti_sim_nort_sr7cv2o3u (Potential Pep 0) settled on 2026-08-07. The sanctions_or_pep detector fired because screening flagged the entity for potential PEP status, and this detector is routed to review regardless of score.
What the evidence shows. The alert score is 15, placing it in the 'clear' band, and hard_signal is false. The entity is VERIFIED, high_risk is marked false, and review reasons are listed as none. Last screening was 2026-06-25, recent relative to the alert open date. The transfer itself settled with no return code. Program-level KRIs show pep_flagged_entities and high_risk_entity_share at 'watch' (n=33, small sample), but sanctioned_country_transfers, ach return rates, and frozen_accounts are all at 'ok'. One KRI, manual_review_aging_hours, shows a breach (1434.7 hours, n=3), but this reflects program-wide review backlog, not evidence tied to this specific entity or transfer.
What was checked. Entity verification status, PEP review reasons, last screening date, transfer status and return code, alert score and band, hard signal flag, and program KRIs for related risk indicators (sanctioned country exposure, return rates, frozen accounts, concentration).
What is recommended. No evidence in this alert indicates unresolved PEP concerns, transfer irregularities, or sanctions exposure. The entity is verified with no open review reasons, the transfer settled cleanly, and the score sits in the clear band with no hard signal. This can be closed. The manual_review_aging_hours breach is a program-level operational metric unrelated to this specific alert's evidence and should be tracked separately, not as grounds to hold this transfer.
- Recommendation
- close
- Confidence
- 0.78
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Score 15, band clear, hard_signal false.
- Entity status VERIFIED, high_risk false, review reasons none.
- Last screened 2026-06-25, recent prior to alert open.
- Transfer SETTLED, no return code, single transaction of $1,108.94 against declared monthly volume of $2,500,000.00.
- Program KRIs mostly 'ok'; PEP-related KRIs are 'watch' but based on small sample (n=33) and not specific to this entity's review reasons.
- Manual_review_aging_hours breach is a program-level metric (n=3) not tied to this transfer or entity, noted but not a basis for holding this alert.
Evidence
{
"n": 604,
"band": "clear",
"skoor": 15,
"signals": [
{
"code": "entity.pep_potential",
"detail": "potential PEP match",
"weight": 15
}
],
"routeReason": "detector always reviewed"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.pep_potential | +15 | potential PEP match |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.