SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Entity velocity spiked: 1 transfers and $3,973.82 in 24 hours.

Detector
velocity_spike
Severity
medium
Program
Northwind Payroll (simulated)
Subject
entity enti_sim_nort_b408fp2t37
Transfer
acht_sim_nort_8hoy1h4x7q · $3,632.11 · ach outgoing
Skoor at alert
null unscored
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. A velocity_spike alert (medium severity) fired for entity Kestrel Partners 022 after the system detected 1 transfer totaling $3,973.82 in a 24-hour window against program Northwind Payroll, exceeding 2x the program daily average. The alert routed to review because the detector is not auto-closable. What the evidence shows. The only transfer tied to the entity in this record is acht_sim_nort_8hoy1h4x7q, an ACH outgoing credit for $3,632.11, status SETTLED, with no return code. The transfer carries a first-time-counterparty flag and a first-time-and-large flag, but its risk band is unscored (skoor null, n=2, confidence null), so the scoring model has not evaluated it against enough history to render a band. The entity itself is a VERIFIED business, not flagged high risk, not PEP, with no open review reasons, last screened 2026-06-28. Program-level KRIs show frozen_accounts, overdraft_events, and stale_screening_share at ok levels; pep_flagged_entities and high_risk_entity_share are at watch but reflect the full 33-entity program population, not a signal specific to this entity. Several KRIs (hold_aging_hours, manual_review_rate, velocity_vs_declared, reserve_coverage_ratio, ach return rates) are unmeasured (n=0), limiting broader context. There are no prior dispositions on this alert. What was checked. Reviewed the alert evidence and signal weights, the linked transfer's status and scoring, the entity's verification, risk, and PEP status, and the program KRI panel for corroborating patterns. Confirmed no hard signal was triggered and no prior disposition history exists for this alert or entity. What is recommended. The transfer is already SETTLED, so there are no funds to hold. The triggering entity is verified, not high risk, not PEP, with no open review reasons, and the flagged transfer shows no return or dispute. The unscored band reflects thin transaction history rather than an identified risk pattern. Close the alert; no further action is needed unless additional velocity or counterparty signals accumulate for this entity.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:30Z
Rationale
  • Transfer status is SETTLED with no return code, so a hold or release action does not apply.
  • Entity is VERIFIED, not high risk, not PEP, with no open review reasons and recent screening (2026-06-28).
  • Transfer risk band is unscored (skoor null, n=2), reflecting insufficient history rather than a confirmed risk finding.
  • Program KRIs relevant to fraud/velocity control (frozen_accounts, overdraft_events, stale_screening_share) are at ok levels; watch-level KRIs (pep_flagged_entities, high_risk_entity_share) are program-wide, not entity-specific.
  • No prior dispositions exist for this entity or alert, so no established pattern of repeat velocity spikes is documented.
  • Confidence is moderated because several program KRIs (velocity_vs_declared, ach return rates) are unmeasured, limiting ability to confirm this is an isolated event.

Evidence

{
  "n": 2,
  "band": "unscored",
  "skoor": null,
  "signals": [
    {
      "code": "velocity.sum_24h_gt_2x_daily_avg",
      "detail": "24h sum above 2× the program daily average",
      "weight": 10
    }
  ],
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
counterparty.first_time+10first transfer with this counterparty
velocity.sum_24h_gt_2x_daily_avg+1024h sum above 2× the program daily average

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.