SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status potential).

Detector
sanctions_or_pep
Severity
high
Program
Meridian Remit (simulated)
Subject
entity enti_sim_meri_28dfpclz9pj
Transfer
acht_sim_meri_ajulyz7hc2y · $319.65 · ach outgoing
Skoor at alert
30 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 9eb22d7e-9077-4d4d-9497-ec608fbe98f4 was opened on 2026-09-17 by the sanctions_or_pep detector for entity enti_sim_meri_28dfpclz9pj (Potential Pep 2) under the Meridian Remit program. The detector always routes to review, so the route itself carries no additional weight. The triggering activity is one settled ACH debit transfer, acht_sim_meri_ajulyz7hc2y, for $319.65 dated 2026-09-09, with return code none. What the evidence shows. The alert score is 30 (review band), and hard_signal is false, meaning no confirmed match. The entity record shows verification status VERIFIED, high_risk false, review reasons none, and a last screening date of 2026-08-22, which is recent relative to the alert open date. The transfer-level score is also 30 with two contributing signals: entity.pep_potential (+15) and returns.counterparty_prior_any (+15). The prior-returns signal reflects counterparty history on other transfers, not this transfer, which settled cleanly with no return code. Program-level KRIs show several breaches (reserve_coverage_ratio, manual_review_aging_hours, ach_unauthorized_return_rate, sanctioned_country_transfers), but these are aggregate program metrics with no field tying them to this specific entity or transfer. There are no prior dispositions on this alert. What was checked. Reviewed the alert evidence block, the entity record (verification, risk flag, review reasons, screening date), the single associated transfer (amount, status, return code), and program-level KRIs for context on whether a broader pattern is indicated. What is recommended. Close the alert. The entity is verified, not flagged high risk, has no open review reasons, and was screened within the last month. The transfer that triggered the alert settled without a return. The PEP flag is potential only and does not, on its own, indicate a confirmed match requiring hold. The program KRI breaches are aggregate figures unconnected to this entity or transfer in the evidence provided and do not by themselves justify escalating this specific alert.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Hard_signal is false and score sits in the review band, not a confirmed-match band.
  • Entity verification is VERIFIED, high_risk is false, and review reasons field is empty.
  • Last screening date (2026-08-22) is recent relative to alert open date (2026-09-17), so stale screening is not a concern here.
  • The transfer tied to this alert settled with return code none; the counterparty-prior-return signal references other activity, not this transfer.
  • Program KRI breaches (reserve coverage, unauthorized returns, sanctioned-country transfers) are aggregate metrics with no evidence field linking them to this entity or transfer, so they do not support escalation of this specific alert.
  • Evidence set is limited to one transfer and summary entity/program fields; confidence is capped at moderate given this thinness.

Evidence

{
  "n": 943,
  "band": "review",
  "skoor": 30,
  "signals": [
    {
      "code": "entity.pep_potential",
      "detail": "potential PEP match",
      "weight": 15
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.pep_potential+15potential PEP match
returns.counterparty_prior_any+151 prior return(s) other than NSF

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.