SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status potential).

Detector
sanctions_or_pep
Severity
high
Program
Harbor Marketplace Payouts (simulated)
Subject
entity enti_sim_harb_azbiyidj3x2
Transfer
acht_sim_harb_44u5phds4yj · $315.39 · ach outgoing
Skoor at alert
15 clear
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 8f2e1126-fd32-402f-9b4e-a22aa90c79ce was generated by the sanctions_or_pep detector on entity enti_sim_harb_azbiyidj3x2, a US-based individual named 'Potential Pep 1', following an outgoing ACH debit of $315.39 on transfer acht_sim_harb_44u5phds4yj. The detector always routes to review regardless of score, per routeReason. What the evidence shows. The alert score is 15, placing it in the 'clear' band, with hard_signal false. The only contributing signal is entity.pep_potential (weight 15), indicating a potential PEP match rather than a confirmed one. The entity is marked VERIFIED, high_risk false, with no review reasons listed, and was last screened 2026-06-25. The transfer is ACH outgoing, status SETTLED, with return code none, so no funds are in a held state. Counterparty country is listed as unknown, but program-level KRI sanctioned_country_transfers is 0 (n=86, ok) and ach_overall_return_rate is 0 (n=37, ok). Program KRIs show pep_flagged_entities=1 (n=30, watch) and high_risk_entity_share=0.067 (n=30, watch), both flagged 'watch' but not 'breach'. manual_review_aging_hours shows a breach (1438 hours, n=1), which reflects program-wide review backlog, not a fact specific to this entity or transfer. No prior dispositions exist for this alert. What was checked. Reviewed the alert evidence block, transfer record, entity screening record, and program KRI snapshot. Confirmed the transfer has already settled with no return code, so there is no held transfer to release. Confirmed the entity's verification status and absence of listed review reasons. Confirmed the score/band classification and hard_signal flag. Noted that counterparty country and velocity_vs_declared are unmeasured or unknown fields, limiting full context on the counterparty side. What is recommended. Close the alert. The score is in the clear band, hard_signal is false, the entity is verified with no open review reasons, and the transfer has settled cleanly with no return code. The PEP match is described as potential only, with no corroborating high-risk or adverse signal in this record. The program-level watch indicators (pep_flagged_entities, high_risk_entity_share) and the manual_review_aging_hours breach are portfolio-level conditions that may warrant separate operational attention but do not, on the evidence here, indicate this specific alert requires further review before closing.
Recommendation
close
Confidence
0.72
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Score 15 in clear band with hard_signal false.
  • Entity is VERIFIED, high_risk false, no review reasons listed.
  • Transfer is SETTLED with return code none; nothing is on hold.
  • Only one contributing signal, a potential (not confirmed) PEP match.
  • Counterparty country unknown and velocity_vs_declared null limit full certainty, which caps confidence below high.
  • Program KRI breach (manual_review_aging_hours) and watch-level PEP/high-risk shares are portfolio conditions, not entity- or transfer-specific evidence requiring escalation of this alert.

Evidence

{
  "n": 335,
  "band": "clear",
  "skoor": 15,
  "signals": [
    {
      "code": "entity.pep_potential",
      "detail": "potential PEP match",
      "weight": 15
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.pep_potential+15potential PEP match

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.