SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status potential).

Detector
sanctions_or_pep
Severity
high
Program
Lantern Lending (simulated)
Subject
entity enti_sim_lant_866sn4vcjd
Transfer
acht_sim_lant_9lzs4e1adhq · $2,551.70 · ach outgoing
Skoor at alert
15 clear
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 402d9fbd-70ba-4e5d-aa0d-7cf013b6e9c7 fired from the sanctions_or_pep detector on entity enti_sim_lant_866sn4vcjd, a PERSON record carrying a potential PEP flag. The entity's associated ACH outgoing transfer acht_sim_lant_9lzs4e1adhq for $2,551.70 USD settled on 2026-08-10 with no return code. What the evidence shows. The alert skoor is 15, band clear, with a single signal (entity.pep_potential, weight 15) and hard_signal false. The route reason states this detector is always routed to review regardless of score, which explains why a clear-band, low-weight signal reached review. The entity record shows verification VERIFIED, high_risk false, review reasons none, and last screened 2026-06-25T12:01:30.000Z, roughly three months before this alert opened. The transfer itself carries the same skoor (15, clear, confidence 0.925) and settled without a return code, meaning no rail-level rejection occurred. Program KRIs show pep_flagged_entities at 1 of 33 (watch) and stale_screening_share at 0.061 (ok), so this entity's screening is not stale relative to the program, and the PEP-flagged count is not elevated in a way that ties multiple entities together. Manual_review_aging_hours shows a breach (n=3), but this is a program-wide operational metric with no field linking it to this specific entity or transfer. What was checked. Reviewed the alert's skoor and band, the hard_signal flag, the entity's verification and screening timestamp, the transfer's status and return code, prior dispositions (none on file), and program KRIs for related patterns (pep_flagged_entities, stale_screening_share, high_risk_entity_share, sanctioned_country_transfers). No review reasons are populated on the entity, and no other alerts or dispositions reference this entity or counterparty. What is recommended. Close this alert. The entity is verified, carries no active review reasons, and was screened within the program's normal cadence. The flagged signal (potential PEP) is present but produced a clear-band score with no hard signal. The associated transfer already settled with no return code, so there is no pending transfer to hold or release. No KRI directly ties this entity to a broader pattern warranting escalation.
Recommendation
close
Confidence
0.74
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Skoor 15 sits in the clear band with hard_signal false, and the only signal present is entity.pep_potential at weight 15.
  • Entity verification status is VERIFIED, high_risk is false, and review reasons field is empty.
  • Last screening (2026-06-25) is not flagged as stale under the program's stale_screening_share KRI (0.061, ok).
  • Transfer acht_sim_lant_9lzs4e1adhq is already SETTLED with return code none, so there is no transfer available to hold or release.
  • Program KRI pep_flagged_entities is at watch (1/33) but this single data point does not establish a pattern connecting other entities to this alert.
  • No prior dispositions exist on this entity, and manual_review_aging_hours breach is a program-level metric with no direct link to this alert's evidence.

Evidence

{
  "n": 355,
  "band": "clear",
  "skoor": 15,
  "signals": [
    {
      "code": "entity.pep_potential",
      "detail": "potential PEP match",
      "weight": 15
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.pep_potential+15potential PEP match

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.