Hoist AI
HomeGlossaryRisk Flag

What is a risk flag?

A discrepancy or anomaly surfaced during source checks. It signals that a data point warrants attention, not that a transaction should be blocked.

Verification response fieldLast updated 2026-07-20

A risk flag is a structured indicator in a tool-specific verification response that identifies a discrepancy, anomaly, or data point requiring attention. Risk flags from supported workflows are surfaced from source checks. Risk flags in the separate Evidence Pack export are fixture-derived samples and are not source findings.

What triggers a risk flag

Risk flags are raised when source data contains something that does not match an expected pattern, contradicts another source, or falls outside normal parameters. Examples include:

  • An ABN that is registered but the GST registration has lapsed
  • A trading name on an invoice that does not match the ABN holder on the ABR
  • A supported professional-register record whose status needs human review
  • A supported source that is unavailable or returns an incomplete response

What a risk flag contains

  • Flag type: the category of discrepancy (for example, encumbrance, identity mismatch, status change)
  • Severity: an indication of how significant the flag is, from informational to critical
  • Source: which source check raised the flag
  • Description: a plain-language explanation of what was found
  • Timestamp: when the underlying source check ran

Why agents need this

Agents need structured risk indicators to decide what to do next. An agent that receives an unstructured narrative description of a source result has to parse it to extract actionable information. A structured risk flag tells the agent exactly what was found, how significant it is, and which source it came from, so the agent can route appropriately: continue, escalate to a human reviewer, or block the workflow.

Risk flags also give agents a way to explain their decisions. An agent escalating a transaction to a human reviewer can reference specific risk flags rather than summarising a narrative. Cited, not inferred.

How Hoist uses this

Risk flags appear in the documented field of a tool-specific verification response, such as risk_flags in an Evidence Card. Flags are structured so agents can filter, sort, and route on them without parsing free text. The separate Evidence Pack export includes fixture-derived sample flags for workflow testing. Available source-backed workflows generate flags only from checks that actually ran or explicit unavailability. Hoist PPSR preview and paid search are currently unavailable, so PPSR-shaped sample flags are fixture data, not a live result.

What Hoist does not infer

A risk flag is not a verdict. It does not mean a transaction is unsafe, fraudulent, or should be declined. An ABN with a lapsed GST registration may be operating a GST-exempt activity. Hoist surfaces the flag; the agent, the operator, and the human reviewer determine what it means for a given transaction. For flags that cannot be resolved from source data alone, the verification response may include a human review item.

Related terms

  • Evidence Pack: the current owner-bound prelaunch sample export; its risk flags are fixture-derived workflow examples.
  • Source check: the individual verification step that generates a source-backed risk flag.
  • Human review item: an action required when a risk flag cannot be resolved from source data alone.
  • PPSR: future Hoist contract whose preview and paid-search calls are currently unavailable; any current PPSR-shaped flag is sample/fixture data.
  • NPII: AFSA's National Personal Insolvency Index, a separate person-insolvency register that is not currently enabled as a Hoist source.
  • ABN: business identifier whose status can generate risk flags on mismatch or lapse.
  • AFSA: the authority that would issue a certificate for a direct AFSA PPSR search.