SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status potential).

Detector
sanctions_or_pep
Severity
high
Program
Meridian Remit (simulated)
Subject
entity enti_sim_meri_28dfpclz9pj
Transfer
acht_sim_meri_220tqwjnaue · $1,146.61 · ach outgoing
Skoor at alert
15 clear
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 1b1e24db-132b-412b-a28f-e528ecd81a90 fired on entity enti_sim_meri_28dfpclz9pj under the sanctions_or_pep detector due to a potential PEP match. The entity is linked to a single ACH outgoing debit of $1,146.61 USD (acht_sim_meri_220tqwjnaue) that settled on 2026-08-05 with no return code. What the evidence shows. The alert skoor is 15, banded clear, with hard_signal false. The only contributing signal is entity.pep_potential (weight 15). The entity record shows verification status VERIFIED, high_risk false, review_reasons none, and a last screening date of 2026-06-25, which is after the alert's transfer creation date. The transfer itself settled normally with no return code and no adverse status. Counterparty country is listed as unknown, which is a data gap but not itself a signal in the evidence provided. Program KRIs show pep_flagged_entities=1 (n=30, watch), consistent with this single entity, and high_risk_entity_share and stale_screening_share are both at 0 (ok), indicating this entity's screening is current and it is not separately marked high risk. What was checked. Reviewed the alert score, band, and hard_signal flag. Reviewed the entity's verification status, high-risk flag, review reasons, and last screening date. Reviewed the associated transfer for amount, status, and return code. Reviewed program-level KRIs for sanctioned_country_transfers (0, ok), high_risk_entity_share (0.033, ok), stale_screening_share (0, ok), and pep_flagged_entities (1, watch). Noted manual_review_aging_hours is in breach (n=1) at the program level, but this metric is not tied to this specific alert or entity in the evidence provided. No prior dispositions exist for this alert. What is recommended. Close the alert. The score is in the clear band, hard_signal is false, the entity is verified with no open review reasons, screening is current, and the associated transfer settled without incident. No evidence in this alert points to an unresolved sanctions or PEP concern requiring a person to intervene before further action. The unrelated program-level manual_review_aging_hours breach should be tracked separately and is not a basis to hold this alert.
Recommendation
close
Confidence
0.72
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Skoor 15, band clear, hard_signal false — no elevated risk signal beyond the single PEP-potential flag.
  • Entity verification status is VERIFIED with review_reasons none and last_screened after the transfer date, indicating the potential PEP match was already reviewed and cleared.
  • Transfer settled with no return code, amount ($1,146.61) is small relative to declared monthly program volume of $1,200,000.00.
  • Program KRIs show no sanctioned_country_transfers, stale_screening_share at 0, and high_risk_entity_share low (0.033), none of which support escalation.
  • Counterparty country is unknown, which is a data gap worth noting but not evidenced as a risk signal in this alert.
  • No prior dispositions exist to indicate a recurring or worsening pattern for this entity.

Evidence

{
  "n": 414,
  "band": "clear",
  "skoor": 15,
  "signals": [
    {
      "code": "entity.pep_potential",
      "detail": "potential PEP match",
      "weight": 15
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.pep_potential+15potential PEP match

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.