SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status potential).

Detector
sanctions_or_pep
Severity
high
Program
Lantern Lending (simulated)
Subject
entity enti_sim_lant_866sn4vcjd
Transfer
acht_sim_lant_k4vimpld72 · $1,297.62 · ach outgoing
Skoor at alert
15 clear
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An automated sanctions/PEP screening alert was opened on entity enti_sim_lant_866sn4vcjd ("Potential Pep 3") after a potential PEP match was flagged during screening. The alert is tied to a single ACH outgoing credit transfer (acht_sim_lant_k4vimpld72) for $1,297.62 USD, which settled with no return code. What the evidence shows. The alert skoor is 15, placing it in the clear band, and hard_signal is false, meaning no hard sanctions or watchlist match was made. The only contributing signal is entity.pep_potential (+15), described as a potential PEP match, not a confirmed one. The entity record shows verification status VERIFIED, high_risk false, and review reasons listed as none. The entity was last screened 2026-06-25, roughly two months before this alert opened, which is within the program's stale_screening_share threshold (0.061, marked ok). The transfer itself settled normally with no return code, and program-level ACH return rates are all 0. Program KRIs are largely in the ok/watch range: pep_flagged_entities=1 (watch, n=33), manual_review_aging_hours=1433.5 (breach, n=2), but these are program-wide metrics not specific findings against this entity or transfer. What was checked. Reviewed the alert's skoor and band, the hard_signal flag, the entity's verification and risk status, review reasons, last screening date, the transfer's settlement status and return code, and the program-level KRI panel for corroborating signals of a broader pattern (sanctioned_country_transfers=0, verification_denial_rate=0.03, high_risk_entity_share=0.03, reserve_coverage_ratio=8.67). No prior dispositions exist for this alert. What is recommended. Close the alert. The entity is verified, not flagged high risk, has no listed review reasons, and the PEP match is potential rather than confirmed. The associated transfer settled without incident and program-level indicators do not show a pattern implicating this entity beyond the single watch-level KRI (pep_flagged_entities). The manual_review_aging_hours breach is a program-level metric with n=2 and is not evidenced as connected to this specific alert; if a person wants to confirm that separately, that is a distinct KRI review, not a reason to hold this transfer or entity.
Recommendation
close
Confidence
0.74
Model
claude-sonnet-5
Drafted
2026-09-17 19:30Z
Rationale
  • Skoor 15 in clear band; hard_signal false; only one weighted signal (entity.pep_potential, potential match, not confirmed).
  • Entity verification status is VERIFIED, high_risk false, review reasons none.
  • Transfer settled with no return code; ACH return rates across the program are 0.
  • Program KRIs show no sanctioned-country transfers, low verification denial rate, and stale_screening_share within ok range.
  • Manual_review_aging_hours breach is a separate program-level metric (n=2) not directly tied to this entity or transfer, so it does not by itself justify escalation of this specific alert.
  • No prior dispositions to indicate recurring concern for this entity.

Evidence

{
  "n": 226,
  "band": "clear",
  "skoor": 15,
  "signals": [
    {
      "code": "entity.pep_potential",
      "detail": "potential PEP match",
      "weight": 15
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.pep_potential+15potential PEP match

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.