SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status no, high risk).

Detector
sanctions_or_pep
Severity
high
Program
Harbor Marketplace Payouts (simulated)
Subject
entity enti_sim_harb_skonrvy3x6
Transfer
acht_sim_harb_acdp689o8ki · $470.64 · ach outgoing
Skoor at alert
20 clear
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert d44246a4-5d54-4d82-aecf-7c1bde438dc9 fired on entity enti_sim_harb_skonrvy3x6 (High Risk Trading 1) under the sanctions_or_pep detector, following an outgoing ACH debit of $470.64 (transfer acht_sim_harb_acdp689o8ki) settled on 2026-09-05. The detector routed for review because its routing rule always sends these to review, not because of an elevated score. What the evidence shows. The transfer and entity skoor is 20, banded clear, with no hard signal. The single contributing signal is entity.high_risk (weight 20), reflecting that screening marked the entity high risk. The entity record shows PEP status no, verification VERIFIED, no review reasons listed, and last screened 2026-08-27, which is within the program's normal screening cadence (stale_screening_share=0). The transfer itself settled with no return code, is within the program's declared monthly volume ($4,000,000.00 declared vs. $470.64 single transaction), and the program's sanctioned_country_transfers KRI is 0. Counterparty country is unknown but no sanctioned-country signal fired. What was checked. Reviewed the alert evidence, transfer record, entity record, and program KRIs. Confirmed no hard signal was present, no PEP flag, no unresolved review reasons, and no return code on the settled transfer. Checked program KRIs for related patterns: pep_flagged_entities (1, watch), high_risk_entity_share (0.067, watch), manual_review_aging_hours (breach), and ach_unauthorized_return_rate (breach) are elevated at the program level but are not tied to this entity or transfer by any evidence in this alert. Prior dispositions for this entity: none. What is recommended. Close this alert. The transfer has already settled, so no hold or release action applies. The evidence is limited to a single low-weight, clear-band signal (entity marked high risk) with no PEP, no stale screening, and no adverse transfer outcome. The program-level KRI breaches (manual_review_aging_hours, ach_unauthorized_return_rate) are noted for separate program-level review but do not by themselves connect to this entity or transaction in the evidence provided.
Recommendation
close
Confidence
0.74
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Skoor 20, band clear, hard_signal false; single signal entity.high_risk with no corroborating PEP or review-reason flags.
  • Entity verification is VERIFIED, PEP no, last screened 2026-08-27, within normal cadence (stale_screening_share=0).
  • Transfer acht_sim_harb_acdp689o8ki is SETTLED with no return code; no hold exists to release.
  • Transaction amount ($470.64) is small relative to declared monthly volume ($4,000,000.00); no sanctioned-country or overdraft signals fired.
  • Program KRI watch/breach items (pep_flagged_entities, high_risk_entity_share, manual_review_aging_hours, ach_unauthorized_return_rate) are program-level and not linked by evidence to this specific entity or transfer, so they support program-level attention but not escalation of this alert.
  • No prior dispositions exist for this entity, so no pattern of repeat alerts is established.

Evidence

{
  "n": 1832,
  "band": "clear",
  "skoor": 20,
  "signals": [
    {
      "code": "entity.high_risk",
      "detail": "entity marked high risk by screening",
      "weight": 20
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.high_risk+20entity marked high risk by screening

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.