SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status potential).

Detector
sanctions_or_pep
Severity
high
Program
Harbor Marketplace Payouts (simulated)
Subject
entity enti_sim_harb_azbiyidj3x2
Transfer
acht_sim_harb_6x5hhfmp6jw · $279.19 · ach outgoing
Skoor at alert
30 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 2c14ca34-8758-46f2-a416-2bbf16b43b6f was opened on 2026-09-17 by the sanctions_or_pep detector against entity enti_sim_harb_azbiyidj3x2, a person flagged as a potential PEP match. The alert is tied to one settled ACH outgoing credit transfer of $279.19 USD (acht_sim_harb_6x5hhfmp6jw), created 2026-08-11, to counterparty cpty_sim_harb_1fd2i6t54k3 in AE. Route reason states this detector is always reviewed regardless of score. What the evidence shows. The alert score is 30 (band review) with hard_signal false. The only weighted signal on the entity itself is entity.pep_potential (+15). The transfer carries an additional geo.outside_declared_countries signal (+15) because the counterparty country (AE) falls outside the program's declared countries (US only), which the program-level ACH rail data confirms (declared countries: US). The entity record shows verification VERIFIED, high_risk false, review reasons none, and last screened 2026-06-25, prior to this alert's transfer date. The transfer itself settled with no return code. Program KRIs show ach_unauthorized_return_rate and manual_review_aging_hours in breach, and pep_flagged_entities and high_risk_entity_share at watch, but these are program-wide metrics not specific to this entity or transfer, and the entity's own high_risk flag is false. What was checked. Entity screening status and verification state, transfer status and return code, geo signal against declared program countries, transfer score band and hard-signal flag, program KRIs for related patterns (PEP concentration, high-risk share), and prior dispositions (none on file). What is recommended. The transfer already settled with no return code, so no hold or release action applies to funds. The entity is verified, carries no confirmed high-risk designation, and has no review reasons attached to its screening record. The PEP flag is potential, not confirmed, and screening is current relative to onboarding but predates this transfer by roughly seven weeks, which a person may want to refresh given the flag. Absent further evidence of a confirmed PEP match or a broader pattern, this alert does not on its own require escalation. Recommend closing the alert, with a note that the entity's screening should be refreshed given the elapsed time since last screening and the outside-declared-country signal on this transfer.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Score is 30, band review, hard_signal false.
  • Entity verification is VERIFIED, high_risk false, review reasons none.
  • Transfer is SETTLED with no return code; no funds are held, so hold/release does not apply.
  • PEP status is potential, not confirmed, and no prior dispositions exist to suggest escalation.
  • Program KRI breaches (ach_unauthorized_return_rate, manual_review_aging_hours) and watch-level PEP metrics are program-wide and not specifically tied to this entity or transfer.
  • Last screening date (2026-06-25) predates the transfer (2026-08-11) by about seven weeks, which supports a note for refreshed screening rather than escalation.

Evidence

{
  "n": 1009,
  "band": "review",
  "skoor": 30,
  "signals": [
    {
      "code": "entity.pep_potential",
      "detail": "potential PEP match",
      "weight": 15
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.pep_potential+15potential PEP match
geo.outside_declared_countries+15counterparty country AE not declared by the program

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.