SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status no, high risk).

Detector
sanctions_or_pep
Severity
high
Program
Northwind Payroll (simulated)
Subject
entity enti_sim_nort_91eod4q93y
Transfer
acht_sim_nort_8tm41mj86m · $1,097.82 · ach outgoing
Skoor at alert
null unscored
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. A ach outgoing credit transfer of $1097.82 (acht_sim_nort_8tm41mj86m) on program Northwind Payroll (simulated) was flagged by detector sanctions_or_pep: Activity on an entity flagged by screening (PEP status no, high risk).. What the evidence shows. The transaction was unscored: too little history for a Skoor. Signals: entity.high_risk (+20), counterparty.first_time (+10). Entity High Risk Trading 0: verification VERIFIED, PEP no, high risk yes. What was checked. No program KRI snapshot was available. No prior dispositions on this entity or counterparty. What is recommended. Recommended: escalate. A person decides; this draft was assembled from the evidence without a model (model call failed).
Recommendation
escalate
Confidence
null (template, no model)
Model
none (template)
Drafted
2026-09-17 19:30Z
Rationale
  • Template draft: recommendation follows the band and the hard-signal rule only.

Evidence

{
  "n": 15,
  "band": "unscored",
  "skoor": null,
  "signals": [
    {
      "code": "entity.high_risk",
      "detail": "entity marked high risk by screening",
      "weight": 20
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.high_risk+20entity marked high risk by screening
counterparty.first_time+10first transfer with this counterparty

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.