SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Activity on an entity flagged by screening (PEP status potential).

Detector
sanctions_or_pep
Severity
high
Program
Harbor Marketplace Payouts (simulated)
Subject
entity enti_sim_harb_azbiyidj3x2
Transfer
acht_sim_harb_cessogbi6j2 · $531.67 · ach outgoing
Skoor at alert
30 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert f0966338-132a-484f-8a27-a3e3fe067707 fired on entity enti_sim_harb_azbiyidj3x2 under the sanctions_or_pep detector for a potential PEP match. The alert is tied to one settled ACH outgoing credit transfer (acht_sim_harb_cessogbi6j2) for $531.67 USD, dated 2026-08-10, with no return code. What the evidence shows. The transfer score is 30 (band review, n=990, confidence=1), driven by two signals: entity.pep_potential (+15) and returns.counterparty_prior_any (+15). The entity record shows verification status VERIFIED, high_risk false, review reasons none, and a last screening date of 2026-06-25, which is after the program's screening cadence and shows no staleness (stale_screening_share=0). The transfer itself settled with no return code, so there is no failed or reversed payment tied to this alert. The counterparty's country is listed as unknown, which limits geographic risk assessment but is not itself a signal in the evidence. Program-level KRIs show pep_flagged_entities at 1 of 30 entities (watch) and high_risk_entity_share at 6.7% (watch), both within a small population and not flagged as breach. Two KRIs are in breach status (manual_review_aging_hours and ach_unauthorized_return_rate) but neither evidence field ties these breaches to this specific entity or transfer. What was checked. Reviewed the alert evidence, the transfer record and its settlement/return status, the entity's verification and screening history, and the program KRI panel for related patterns. No prior dispositions exist for this alert. No hard signal was present (hard_signal false), and the entity's own review reasons field is empty, indicating the screening system did not escalate this as a confirmed match. What is recommended. Close the alert. The entity is verified, has no open review reasons, and was screened within the program's normal cadence. The transfer settled without a return code, so no funds are in a state requiring a hold. The PEP signal is marked 'potential' rather than confirmed, and the counterparty-prior-return signal does not correspond to any return on this transfer. The two KRI breaches (manual_review_aging_hours, ach_unauthorized_return_rate) are program-wide and not directly linked to this entity or transfer in the evidence provided; they may warrant separate monitoring but do not change the disposition of this specific alert.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Entity verification status is VERIFIED with high_risk false and review reasons none.
  • PEP signal is marked as 'potential' only, with no confirmed match noted in entity or alert evidence.
  • Transfer settled with no return code; no funds are pending or held.
  • Score is 30, at the low end of the review band, with hard_signal false.
  • Counterparty country is listed as unknown, which is a data gap but not itself a triggering signal.
  • Program KRI breaches (manual_review_aging_hours, ach_unauthorized_return_rate) are not tied in the evidence to this specific entity or transfer, limiting confidence that this alert reflects a broader pattern.

Evidence

{
  "n": 990,
  "band": "review",
  "skoor": 30,
  "signals": [
    {
      "code": "entity.pep_potential",
      "detail": "potential PEP match",
      "weight": 15
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.pep_potential+15potential PEP match
returns.counterparty_prior_any+151 prior return(s) other than NSF

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.