SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status potential).

Detector
sanctions_or_pep
Severity
high
Program
Harbor Marketplace Payouts (simulated)
Subject
entity enti_sim_harb_azbiyidj3x2
Transfer
acht_sim_harb_calfj8fi5t2 · $261.66 · ach outgoing
Skoor at alert
15 clear
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert e9b7e54a fired from the sanctions_or_pep detector on entity enti_sim_harb_azbiyidj3x2 ("Potential Pep 1"), triggered by a single signal: entity.pep_potential (weight 15). This is a potential PEP match, not a confirmed one. The alert score is 15, placing it in the 'clear' band, and hard_signal is false. Route was 'reviewed' because this detector is always reviewed, per routeReason. What the evidence shows. The entity record shows verification status VERIFIED, high_risk false, review reasons none, and last screened 2026-08-16T23:44:46.000Z, roughly one month before this alert opened. Country is US. The transfer tied to this alert (acht_sim_harb_calfj8fi5t2) is an outgoing ACH CREDIT of $261.66 with status RETURNED and return code R10 (customer advises unauthorized). This return code relates to authorization dispute, not to sanctions or PEP status, and is a separate matter from the detector's basis. The transfer's own skoor is also 15/clear. Program KRIs show pep_flagged_entities at 1 of 30 entities (watch) and high_risk_entity_share at 6.7% (watch), both program-level and not specific to this entity beyond the existing flag. Manual_review_aging_hours (breach) and ach_unauthorized_return_rate (breach) are also program-level metrics, not attributed to this entity or transfer in the evidence provided. What was checked. Checked the alert's detector, score, and band; the entity's verification status, high-risk flag, review reasons, and last screening date; the associated transfer's status, return code, and skoor; program KRIs for related watch/breach conditions; and prior dispositions, of which there are none for this alert. What is recommended. Close this alert. The entity is already verified, screened within the past month, carries no open review reasons, and the alert score sits in the clear band with no hard signal. The R10 return on the linked transfer concerns transaction authorization, not PEP/sanctions status, and is not evidence of a sanctions or PEP concern on this entity. The transfer is already RETURNED, not held, so no release action applies. Program-level KRI watches and breaches (pep_flagged_entities, manual_review_aging_hours, ach_unauthorized_return_rate) are noted for program-level review but do not by themselves indicate this specific alert requires escalation, since none are tied in the evidence to this entity or transfer.
Recommendation
close
Confidence
0.72
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Detector fired on a single potential PEP signal, weight 15, alert score 15, band clear, hard_signal false.
  • Entity is VERIFIED, high_risk false, review reasons none, last screened within the past month.
  • Transfer is already RETURNED (R10, unauthorized), not held, so no funds-movement action is pending on this alert.
  • R10 return code reflects an authorization dispute unrelated to the PEP/sanctions basis of this alert.
  • Program KRI watches/breaches are entity/transfer-agnostic in the evidence given and do not establish a pattern specific to this subject.
  • No prior dispositions exist to indicate recurring concern for this entity.

Evidence

{
  "n": 706,
  "band": "clear",
  "skoor": 15,
  "signals": [
    {
      "code": "entity.pep_potential",
      "detail": "potential PEP match",
      "weight": 15
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.pep_potential+15potential PEP match

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.