SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status no, high risk).

Detector
sanctions_or_pep
Severity
high
Program
Meridian Remit (simulated)
Subject
entity enti_sim_meri_5if3mzfr9pn
Transfer
acht_sim_meri_6jto1nx7c08 · $447.29 · ach outgoing
Skoor at alert
20 clear
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert bb7df757-c991-46a1-bb33-5358c74fe4ff fired on entity enti_sim_meri_5if3mzfr9pn under the sanctions_or_pep detector because screening marked the entity high risk. The detector always routes to review regardless of score. The associated activity is a single outgoing ACH credit transfer (acht_sim_meri_6jto1nx7c08) for $447.29, already settled, with no return code. What the evidence shows. The entity-level skoor is 20, banded clear, with hard_signal false, driven solely by the entity.high_risk signal (+20). The entity record shows PEP status no, verification VERIFIED, no review reasons listed, last screened 2026-08-27, business type, US country. The transfer itself carries the same skoor of 20, clear band, based on n=914 with confidence 1, and no return or unauthorized flags. Program-level KRIs show several breaches (reserve_coverage_ratio 0.53, ach_unauthorized_return_rate 0.0105, sanctioned_country_transfers=2, manual_review_aging_hours 1146.9) but these are aggregate program metrics, not specific to this entity or transfer. There are no prior dispositions on this alert. What was checked. Reviewed the alert signal composition, entity screening attributes (PEP, verification, review reasons, last screen date), the linked transfer's status and return code, the transfer-level skoor and band, and the program KRI panel for any entity-specific linkage. No sanctions match, no PEP flag, no adverse review reason, and no return/unauthorized activity were found tied to this specific entity or transfer. What is recommended. Close this alert. The only driver is a generic high-risk flag with no PEP, no unresolved review reason, recent screening, and a settled transfer with no return issues. The program-level KRI breaches (reserve coverage, unauthorized returns, sanctioned country transfers) are not connected in this evidence to this specific entity and should be tracked separately at the program level rather than through this alert.
Recommendation
close
Confidence
0.72
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Skoor 20, band clear, hard_signal false at both entity and transfer level.
  • Entity is verified, PEP no, has no review reasons, and was screened within the last month.
  • The single associated transfer is settled with no return code and no unauthorized or administrative return flags.
  • Program KRI breaches (reserve_coverage_ratio, ach_unauthorized_return_rate, sanctioned_country_transfers) exist but the evidence does not tie them to this specific entity or transfer, so they do not support escalating this particular alert.
  • No prior dispositions exist to indicate a recurring pattern for this entity.

Evidence

{
  "n": 914,
  "band": "clear",
  "skoor": 20,
  "signals": [
    {
      "code": "entity.high_risk",
      "detail": "entity marked high risk by screening",
      "weight": 20
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.high_risk+20entity marked high risk by screening

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.