SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status potential).

Detector
sanctions_or_pep
Severity
high
Program
Harbor Marketplace Payouts (simulated)
Subject
entity enti_sim_harb_azbiyidj3x2
Transfer
acht_sim_harb_bzr5mnaa535 · $259.05 · ach outgoing
Skoor at alert
15 clear
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 7395fd14-d912-4344-a0c2-39380fdf615d fired on entity enti_sim_harb_azbiyidj3x2 under the sanctions_or_pep detector after a potential PEP match was flagged by screening. The alert is tied to one settled ACH outgoing credit transfer (acht_sim_harb_bzr5mnaa535) for $259.05 USD, created 2026-07-23. Route reason is 'detector always reviewed', meaning this detector routes to review regardless of score. What the evidence shows. The alert score is 15, band clear, with hard_signal false. The only contributing signal is entity.pep_potential (+15). The entity record shows verification status VERIFIED, high_risk false, review reasons none, and last screened 2026-06-25, about four weeks before the transfer. The transfer itself is settled with no return code and no other signals attached (transfer skoor also 15, band clear). Program KRIs are mostly ok: ach return rates 0, sanctioned_country_transfers 0, reserve_coverage_ratio 16.5, counterparty_concentration_top1 0.118. Two KRIs sit in watch: pep_flagged_entities=1 (n=30) and high_risk_entity_share=0.067 (n=30), both low-magnitude given small n. One KRI shows breach: manual_review_aging_hours=1438 hours (n=2), which reflects program-level review backlog rather than anything specific to this entity or transfer. What was checked. Checked the entity record for verification status, high-risk flag, review reasons, and screening recency. Checked the transfer for settlement status, return code, and counterparty country. Checked the transfer-level score and signals, which match the alert-level score with no additional hard signals. Checked program KRIs for related sanctions, PEP, and concentration indicators. Checked prior dispositions, of which there are none. What is recommended. Close this alert. The entity is verified, not high-risk, has no open review reasons, and was screened within the last month. The associated transfer is small, settled, and carries no return or sanctioned-country signal. The score is in the clear band with no hard signal. The manual_review_aging_hours breach is a program-level KRI issue, not specific to this alert, and should be tracked separately by the program owner rather than held against this transfer, which has already settled.
Recommendation
close
Confidence
0.82
Model
claude-sonnet-5
Drafted
2026-09-17 19:30Z
Rationale
  • Alert score 15, band clear, hard_signal false, single contributing signal entity.pep_potential.
  • Entity verification VERIFIED, high_risk false, review reasons none, last screened 2026-06-25.
  • Transfer acht_sim_harb_bzr5mnaa535 is SETTLED with no return code; transfer-level score matches alert score with no added signals.
  • Program KRIs for sanctions and returns are clean (sanctioned_country_transfers=0, ach_overall_return_rate=0); PEP-related KRIs are in watch but based on small n (30) and do not indicate a pattern tied to this specific entity.
  • manual_review_aging_hours breach is a separate program-level metric (n=2) unrelated to this transfer's settlement status, and the transfer cannot be held or released since it already settled.

Evidence

{
  "n": 402,
  "band": "clear",
  "skoor": 15,
  "signals": [
    {
      "code": "entity.pep_potential",
      "detail": "potential PEP match",
      "weight": 15
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.pep_potential+15potential PEP match

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.