SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status potential).

Detector
sanctions_or_pep
Severity
high
Program
Lantern Lending (simulated)
Subject
entity enti_sim_lant_866sn4vcjd
Transfer
acht_sim_lant_8vcpu6ngd2m · $966.33 · ach outgoing
Skoor at alert
15 clear
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 4286d397-8e22-443a-b86a-84471d1d0dbf fired from the sanctions_or_pep detector on entity enti_sim_lant_866sn4vcjd, a person recorded as "Potential Pep 3" under program Lantern Lending. The triggering activity is an outgoing ACH credit transfer (acht_sim_lant_8vcpu6ngd2m) for $966.33 USD, settled, with counterparty cpty_sim_lant_c9qj5z42ckx whose country is unknown. The alert was opened 2026-09-17 and routed to review because this detector is always reviewed, not because of a strong signal. What the evidence shows. The alert score is 15, placing it in the 'clear' band, and hard_signal is false. The only contributing signal is entity.pep_potential at weight 15. The entity record shows verification status VERIFIED, high_risk false, review reasons none, and a last screening date of 2026-06-25, which is recent relative to the alert open date. The transfer itself settled with no return code, so there is no indication of a rejected or reversed payment. Counterparty country is unknown, which limits what can be confirmed about the receiving side, but no signal in the evidence flags the counterparty itself. Program-level KRIs show pep_flagged_entities at 1 of 33 (watch) and manual_review_aging_hours in breach (n=2), but these are program-wide metrics not specific to this entity or transfer, and no prior dispositions exist to indicate a pattern tied to this subject. What was checked. Reviewed the alert score and band, the single contributing signal and its weight, the transfer status and return code, the entity's verification and risk flags, the last screening date, and the program KRI panel for related stress indicators. Checked for prior dispositions on this subject; none exist. What is recommended. Nothing in the evidence indicates a confirmed PEP match, a high-risk flag, an open review reason, or a returned/failed transfer. The entity is verified, screening is current, and the score sits in the clear band with no hard signal. The unknown counterparty country and the program-level manual_review_aging_hours breach are noted but do not attach to this specific alert's evidence. This can be closed at the analyst level; if the program-wide aging breach warrants attention, that should be tracked separately from this alert.
Recommendation
close
Confidence
0.72
Model
claude-sonnet-5
Drafted
2026-09-17 19:30Z
Rationale
  • Score 15, band clear, hard_signal false — detector routed this only because sanctions_or_pep is always reviewed, not due to signal strength.
  • Only one signal present: entity.pep_potential at low weight (15), with review reasons listed as none.
  • Entity verification is VERIFIED, high_risk is false, and screening occurred 2026-06-25, prior to and not stale relative to alert open.
  • Transfer status is SETTLED with return code none, so no payment-level failure or reversal evidence exists.
  • Counterparty country unknown is a gap but is not flagged by any signal in the evidence provided.
  • Program KRIs (pep_flagged_entities watch, manual_review_aging_hours breach) are aggregate metrics, not alert-specific evidence, and no prior dispositions link this entity to a broader pattern.

Evidence

{
  "n": 193,
  "band": "clear",
  "skoor": 15,
  "signals": [
    {
      "code": "entity.pep_potential",
      "detail": "potential PEP match",
      "weight": 15
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.pep_potential+15potential PEP match

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.