SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status potential).

Detector
sanctions_or_pep
Severity
high
Program
Meridian Remit (simulated)
Subject
entity enti_sim_meri_28dfpclz9pj
Transfer
acht_sim_meri_9ehts4bi9z7 · $721.28 · ach outgoing
Skoor at alert
15 clear
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. The alert fired because entity enti_sim_meri_28dfpclz9pj, a PERSON labeled "Potential Pep 2," carries a potential PEP match from screening. The sanctions_or_pep detector routes to review on any PEP flag regardless of score. The transfer under review is an ACH outgoing debit of $721.28 USD, settled, with no return code, dated 2026-07-15. What the evidence shows. The transfer score is 15, band clear, hard_signal false, confidence 0.435 on n=82. The only contributing signal is entity.pep_potential (+15). The entity record shows verification VERIFIED, high_risk false, review reasons none, and last screened 2026-06-25, about three weeks before the transfer. Counterparty country is unknown and there is no return code indicating a failed or reversed transfer. Program KRIs show pep_flagged_entities at 1 of 30 entities (watch status) but all other measured KRIs (stale_screening_share, high_risk_entity_share, verification_denial_rate, frozen_accounts, overdraft_events) are in the ok range. Several KRIs are unmeasured (n=0), including velocity_vs_declared, reserve_coverage_ratio, and sanctioned_country_transfers, which limits visibility into broader pattern risk. What was checked. Reviewed the detector output, transfer score and band, entity verification status and screening recency, transfer settlement status and return code, program KRI panel, and prior dispositions. No prior dispositions exist for this entity or transfer. Counterparty country field is present but unresolved (unknown), so no direct sanctioned-country or high-risk-corridor determination can be made from this alert alone. What is recommended. Nothing in the evidence indicates the transfer should be held; it has already settled and the score is in the clear band with no hard signal. The PEP flag is a potential match only, and the entity has been verified with no adverse review reasons and recent screening. A person should confirm the PEP disposition is documented per policy, but the transaction itself does not require intervention. Recommend closing this alert, noting the unresolved counterparty country as a minor gap for future screening completeness.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:30Z
Rationale
  • Transfer score 15 falls in the clear band with hard_signal false and no other contributing signals beyond the single PEP-potential flag.
  • Entity is VERIFIED, high_risk false, and has review reasons none, with screening dated 2026-06-25, recent relative to the transfer date.
  • Transfer is SETTLED with no return code, so there is no pending or reversible transaction to hold.
  • Program KRIs are largely in the ok range; pep_flagged_entities shows watch status but this is a program-level metric, not specific evidence of wrongdoing tied to this alert.
  • Counterparty country is unknown, which is a gap but not sufficient alone to justify escalation or hold given all other clear indicators.
  • No prior dispositions exist, so there is no pattern of repeat unresolved PEP alerts on this entity to escalate.

Evidence

{
  "n": 82,
  "band": "clear",
  "skoor": 15,
  "signals": [
    {
      "code": "entity.pep_potential",
      "detail": "potential PEP match",
      "weight": 15
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.pep_potential+15potential PEP match

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.