SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Activity on an entity flagged by screening (PEP status no, high risk).

Detector
sanctions_or_pep
Severity
high
Program
Northwind Payroll (simulated)
Subject
entity enti_sim_nort_4ndrgqqi3r
Transfer
acht_sim_nort_9d0fdqbr3s3 · $2,400.00 · ach outgoing
Skoor at alert
100 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. A high-severity sanctions/PEP detector alert fired on entity enti_sim_nort_4ndrgqqi3r, part of the Northwind Payroll program, following a settled outgoing ACH transfer of $2,400.00 (acht_sim_nort_9d0fdqbr3s3) dated 2026-09-10. The alert scored 100 (band hold, autoHold true) and was routed to review because the detector type is always reviewed. What the evidence shows. The entity record shows verification status DENIED, high risk true, pep no, and review reason sanctions_match, last screened 2026-06-24. The alert-level evidence lists only entity.high_risk (+20) with hard signal false, but the underlying transfer record carries a separate score of 100 with three signals: entity.denied (+60, hard), entity.high_risk (+20), and returns.counterparty_prior_unauthorized (+40). The counterparty (cpty_sim_nort_25c8izfo4a) has an unknown country and a prior unauthorized return history. The transfer itself is already SETTLED with no return code, meaning funds have already moved. Program KRIs show pep_flagged_entities and high_risk_entity_share both at 'watch' (1/33 and 0.0606 respectively), and manual_review_aging_hours is in breach (1434.69 hours, n=13), indicating slower-than-expected review turnaround across the program. Other KRIs (frozen_accounts, overdraft_events, sanctioned_country_transfers, return rates) are at ok. What was checked. Reviewed alert evidence, transfer-level signals, entity verification record, program KRIs, and prior dispositions. Prior dispositions: none on file. No sanctioned-country transfer signal on the program KRI (sanctioned_country_transfers=0), but the entity-level sanctions_match reason and DENIED verification status are independent of that KRI. What is recommended. This alert involves a DENIED-verification entity with a sanctions_match review reason, a hard signal at the transfer level (entity.denied), and a counterparty with prior unauthorized returns and unknown country, on a transfer that has already settled. This combination — hard sanctions-related signal plus prior unauthorized-return history on the counterparty — indicates a pattern that a single alert disposition cannot resolve. The transfer cannot be held or released since it is already settled; there are no funds in a held state to act on for this transfer specifically. Given the entity's denied verification status and sanctions_match flag, this should be escalated for a person to review the entity relationship, prior transfers, and whether related transfers or entities need holding.
Recommendation
escalate
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Entity verification status is DENIED with review reason sanctions_match, a fact independent of the alert-level hard-signal flag of false.
  • The transfer-level evidence shows a hard signal (entity.denied, +60) not reflected in the alert-level summary, indicating the alert evidence undersells the transfer risk.
  • Counterparty has a prior unauthorized return signal (+40) and unknown country, raising counterparty risk beyond the entity alone.
  • The transfer is already SETTLED, so hold/release actions do not apply to this specific transfer; the appropriate action is escalation for broader review of the entity and related activity.
  • Program KRI manual_review_aging_hours is in breach (1434.69 hours), suggesting review backlogs that support escalating rather than closing without further look.
  • No prior dispositions exist for this entity or transfer, so there is no established handling pattern to rely on.

Evidence

{
  "n": 1322,
  "band": "hold",
  "skoor": 100,
  "signals": [
    {
      "code": "entity.high_risk",
      "detail": "entity marked high risk by screening",
      "weight": 20
    }
  ],
  "autoHold": true,
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.denied+60yesentity verification DENIED
entity.high_risk+20entity marked high risk by screening
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.