SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status no, high risk).

Detector
sanctions_or_pep
Severity
high
Program
Northwind Payroll (simulated)
Subject
entity enti_sim_nort_91eod4q93y
Transfer
acht_sim_nort_8vmdxl1k1mp · $2,072.52 · ach outgoing
Skoor at alert
20 clear
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 8688b89e-de29-4ffd-8c20-b5f14eab2f0f fired on entity enti_sim_nort_91eod4q93y under the sanctions_or_pep detector because screening marked the entity high risk. The linked transaction is an ACH outgoing credit acht_sim_nort_8vmdxl1k1mp for $2,072.52 USD, status SETTLED, with no return code. What the evidence shows. The alert score is 20, band clear, hard_signal false, driven solely by the entity.high_risk signal (weight 20). The entity record shows verification VERIFIED, pep no, review reasons none, and last screened 2026-06-26T12:01:30.000Z. The transfer itself carries the same clear-band score (20, n=552, confidence 1) with no additional signals. The counterparty country is listed as unknown, which is a gap in the evidence but is not flagged by any signal or KRI. Program-level KRIs are mostly ok: sanctioned_country_transfers=0, ach_unauthorized_return_rate=0, verification_denial_rate=0.030 (33 entities), reserve_coverage_ratio=3.86. Two KRIs sit at watch (pep_flagged_entities=1/33, high_risk_entity_share=0.061/33) and one is in breach (manual_review_aging_hours=1434.7 hours, n=3), but none of these are specific to this entity or this transfer. What was checked. Reviewed the alert signals and score, the entity's verification and screening status, the transfer's status and return code, the counterparty record, and the program KRI panel for corroborating patterns (sanctioned-country activity, return rates, concentration, PEP/high-risk shares). What is recommended. No hold is warranted: the transfer has already settled, carries no return code, and the alert band is clear with no hard signal. The entity is verified with no open review reasons. The program-level manual_review_aging_hours breach is a separate operational issue (backlog of reviews) and does not implicate this specific entity or transfer; it should be tracked independently rather than attached to this alert. Close this alert.
Recommendation
close
Confidence
0.72
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Alert score 20 falls in the clear band with hard_signal false, and the only contributing signal is entity.high_risk at its base weight.
  • Entity is VERIFIED, not PEP, with no review reasons and a screening date within the last three months.
  • Transfer is SETTLED with no return code, so no funds-in-transit decision is needed and release is not applicable.
  • Program KRIs directly relevant to sanctions/high-risk exposure (sanctioned_country_transfers, verification_denial_rate, stale_screening_share) are all in the ok range.
  • Counterparty country is unknown, which limits certainty; this is noted as a residual gap rather than a basis for holding, given the otherwise clear evidence.
  • The manual_review_aging_hours breach and the two watch-level KRIs (pep_flagged_entities, high_risk_entity_share) point to a program-wide condition, not to this alert specifically, so escalation of this individual alert is not supported.

Evidence

{
  "n": 552,
  "band": "clear",
  "skoor": 20,
  "signals": [
    {
      "code": "entity.high_risk",
      "detail": "entity marked high risk by screening",
      "weight": 20
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.high_risk+20entity marked high risk by screening
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.