SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Activity on an entity flagged by screening (PEP status no, high risk).

Detector
sanctions_or_pep
Severity
high
Program
Northwind Payroll (simulated)
Subject
entity enti_sim_nort_4ndrgqqi3r
Transfer
acht_sim_nort_1c6mqyec3s6 · $2,400.00 · ach outgoing
Skoor at alert
80 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert a53d63e5-01bd-42c4-a71e-ef1ac1d05224 fired on entity enti_sim_nort_4ndrgqqi3r under the sanctions_or_pep detector, high severity, routed to review because the detector always routes to review. The entity is linked to an ACH outgoing credit of $2,400.00 (acht_sim_nort_1c6mqyec3s6) under the Northwind Payroll program, which already settled on 2026-08-10. What the evidence shows. The alert-level evidence lists skoor 80 (hold band) with a single weighted signal, entity.high_risk (+20), and marks hard signal as false. The transfer-level scoring for the same transfer shows a different picture: skoor 80, hold band, with signals entity.denied (+60, hard) and entity.high_risk (+20). The entity record confirms PERSON "Denied Origin 0", verification status DENIED, high risk true, pep no, and review reasons sanctions_match, last screened 2026-06-24. This means a transaction moved through an entity carrying a DENIED verification status with a sanctions_match reason, and the transfer-level hard signal (entity.denied) does not match the alert-level hard-signal flag of false. The transfer has already settled with no return code, so funds have already moved. What was checked. Transfer status and settlement: confirmed SETTLED, no return code, amount $2,400.00 against a declared program monthly volume of $2,500,000.00. Entity verification and screening: DENIED status, sanctions_match reason, last screened over two months prior to the alert opening. Program KRIs: verification_denial_rate 0.0303 (ok band), high_risk_entity_share 0.0606 (watch), pep_flagged_entities 1 of 33 (watch), manual_review_aging_hours 1434.68 (breach), sanctioned_country_transfers 0 (ok), stale_screening_share 0 (ok). Prior dispositions: none on file for this entity or transfer. What is recommended. Escalate. The transfer already settled, so release does not apply. The evidence shows a sanctions_match review reason and a DENIED verification status tied to a settled outgoing payment, combined with a hard-signal discrepancy between the alert-level and transfer-level scoring that a person needs to reconcile. The program-level manual_review_aging_hours breach and watch-level high_risk_entity_share and pep_flagged_entities figures indicate this may not be an isolated case and warrant broader review beyond this single alert.
Recommendation
escalate
Confidence
0.72
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Entity verification status is DENIED with review reason sanctions_match, per the ENTITY record.
  • Transfer-level scoring shows a hard signal (entity.denied, +60) that is not reflected in the alert-level evidence, which reports hard signal false; this inconsistency needs human reconciliation.
  • The associated $2,400.00 ACH transfer has already SETTLED, so no funds are currently held; recommending release is not applicable.
  • Program KRIs show manual_review_aging_hours in breach (1434.68 hours, n=7) and high_risk_entity_share and pep_flagged_entities in watch status, suggesting a broader pattern warranting escalation rather than a single-alert close.
  • No prior dispositions exist for this entity or transfer, so there is no precedent indicating this was previously reviewed and cleared.

Evidence

{
  "n": 675,
  "band": "hold",
  "skoor": 80,
  "signals": [
    {
      "code": "entity.high_risk",
      "detail": "entity marked high risk by screening",
      "weight": 20
    }
  ],
  "autoHold": true,
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.denied+60yesentity verification DENIED
entity.high_risk+20entity marked high risk by screening

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.