SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Transaction Risk Skoor 80 (hold band) on a $2,400.00 ach transfer: entity.denied, entity.high_risk.

Detector
skoor_hold
Severity
high
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_1c6mqyec3s6
Transfer
acht_sim_nort_1c6mqyec3s6 · $2,400.00 · ach outgoing
Skoor at alert
80 hold
Hard signal
yes
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert a576dc60-c4b3-4d64-a8ef-a18df27c9b4f fired on ACH outgoing transfer acht_sim_nort_1c6mqyec3s6 for $2,400.00 under program Northwind Payroll (simulated). The transaction risk skoor was 80, placing it in the hold band, driven by a hard signal entity.denied (weight 60) and entity.high_risk (weight 20). What the evidence shows. The counterparty entity enti_sim_nort_4ndrgqqi3r is a PERSON record with verification status DENIED, high_risk true, and review reason sanctions_match, last screened 2026-06-24. The transfer status is SETTLED with no return code, meaning the $2,400.00 has already moved despite the denied verification and sanctions match flag. The hard signal flag is true and routeReason is 'hard signal,' confirming the system intended this for auto-hold, but the transfer record shows settlement already occurred. What was checked. Reviewed the alert evidence block (n=675, confidence 0.7, autoHold true), the transfer record (status SETTLED, no return code, counterparty country unknown), the entity record (DENIED verification, sanctions_match reason, pep no), and program-level KRIs. Verification_denial_rate is 0.030 (n=33, ok band), high_risk_entity_share is 0.061 (watch), pep_flagged_entities is 1 (watch), and manual_review_aging_hours is 1434.7 (n=8, breach). No prior dispositions exist for this alert. What is recommended. This transfer is already settled, so it cannot be held or released; funds have moved. The combination of a DENIED verification with a sanctions_match reason and settlement having occurred anyway indicates a possible control gap between screening/hold logic and settlement processing, not an isolated alert. Given the manual_review_aging_hours breach and watch-level high_risk_entity_share and pep_flagged_entities KRIs, this should be escalated for review of why a hard-signal, sanctions-flagged transfer settled rather than being held, and whether other transfers from this entity or program followed the same path.
Recommendation
escalate
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Hard signal entity.denied with sanctions_match reason present on a settled transfer indicates the auto-hold control may not have prevented settlement.
  • Transfer status is SETTLED with no return code, so 'hold' or 'release' actions do not apply to funds already moved.
  • Program KRIs show manual_review_aging_hours in breach and high_risk_entity_share/pep_flagged_entities in watch band, suggesting broader review backlog and risk concentration beyond this single alert.
  • Evidence confidence on the skoor evaluation is 0.7 (not maximal), and counterparty country is unknown, limiting full certainty on entity risk classification.
  • No prior dispositions exist to indicate this pattern has already been reviewed or explained.

Evidence

{
  "n": 675,
  "band": "hold",
  "skoor": 80,
  "signals": [
    {
      "code": "entity.denied",
      "hard": true,
      "detail": "entity verification DENIED",
      "weight": 60
    },
    {
      "code": "entity.high_risk",
      "detail": "entity marked high risk by screening",
      "weight": 20
    }
  ],
  "autoHold": true,
  "confidence": 0.7,
  "routeReason": "hard signal"
}

Skoor signals

SignalWeightHardDetail
entity.denied+60yesentity verification DENIED
entity.high_risk+20entity marked high risk by screening

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.