SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status potential).

Detector
sanctions_or_pep
Severity
high
Program
Meridian Remit (simulated)
Subject
entity enti_sim_meri_28dfpclz9pj
Transfer
acht_sim_meri_61w0u5p1bcd · $1,037.01 · ach outgoing
Skoor at alert
15 clear
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 316bdc10-78e9-4604-b48c-69c866298e64 fired on entity enti_sim_meri_28dfpclz9pj under the sanctions_or_pep detector due to a potential PEP match. The alert cites a single ACH outgoing debit transfer of $1,037.01 (acht_sim_meri_61w0u5p1bcd), which settled on 2026-08-20. The alert was opened 2026-09-17. What the evidence shows. The skoor at both the alert and transfer level is 15, placing it in the 'clear' band, and the hard_signal flag is false. The only contributing signal is entity.pep_potential (+15). The entity record shows verification status VERIFIED, high_risk=false, review reasons listed as none, and a last-screened date of 2026-08-22, which postdates the transfer. Counterparty country is listed as unknown, and the transfer return code is none, with status SETTLED. Program-level KRIs show most metrics in the 'ok' range (ach return rates, sanctioned_country_transfers=0, reserve_coverage_ratio>1). Two KRIs are flagged: manual_review_aging_hours is in breach (1146.86 hours, n=2) and pep_flagged_entities is in watch status (1 of 30 entities, n=30). hold_aging_hours is also in watch status. What was checked. Reviewed the alert's skoor and band, the hard_signal flag, the transfer status and return code, the entity's verification and high-risk flags, review reasons, last screening date relative to transfer date, counterparty country field, program declared volume and rails, and the full set of program KRIs for corroborating or contradicting signals. Prior dispositions on this alert: none. What is recommended. Close this alert. The transfer has already settled, so a hold or release is not applicable to it. The score is in the clear band with no hard signal, the entity is verified with no PEP-related review reasons, and screening postdates the transfer with no stale-screening issue. The manual_review_aging_hours breach and pep_flagged_entities watch status are program-level metrics that a person should track separately, but they do not point to a pattern specific to this entity or transfer that would warrant escalation of this alert.
Recommendation
close
Confidence
0.72
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • skoor=15 in clear band with hard_signal=false and only one contributing signal (entity.pep_potential, weight 15)
  • Entity is VERIFIED, high_risk=false, and review reasons are listed as none
  • Last screening (2026-08-22) postdates the transfer (2026-08-20), so screening was current relative to the flagged activity
  • Transfer status is SETTLED with return code none, so no funds are currently held pending action on this alert
  • Program KRIs are largely 'ok'; the two flagged KRIs (manual_review_aging_hours breach, pep_flagged_entities watch) are program-wide metrics not tied specifically to this entity's transaction pattern
  • Counterparty country is unknown, which is a gap in the evidence and slightly lowers confidence but does not itself indicate sanctions or high-risk geography exposure given sanctioned_country_transfers=0 program-wide

Evidence

{
  "n": 620,
  "band": "clear",
  "skoor": 15,
  "signals": [
    {
      "code": "entity.pep_potential",
      "detail": "potential PEP match",
      "weight": 15
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.pep_potential+15potential PEP match

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.