Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $1,366.37 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Northwind Payroll (simulated)
- Subject
- transfer acht_sim_nort_66nc4rr927x
- Transfer
- acht_sim_nort_66nc4rr927x · $1,366.37 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. A $1,366.37 outgoing ACH debit from Northwind Payroll (simulated) to counterparty cpty_sim_nort_25c8izfo4a settled on 2026-08-18. The transaction risk score of 40 placed it in the review band due to a single flagged signal: the counterparty has one prior unauthorized return on record. The transfer itself carries no return code.
What the evidence shows. The only signal driving the score is returns.counterparty_prior_unauthorized, weighted at 40, based on one prior unauthorized return for this counterparty (n=817 population). The transfer in question shows status SETTLED with return code none, meaning it did not itself return unauthorized or otherwise. The originating entity, Alder Co 024, is VERIFIED, not high risk, not PEP, has no review reasons, and was screened on 2026-08-17, one day before the transfer. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=302, ok) and ach_overall_return_rate at 0.99% (ok), indicating no broader pattern of unauthorized returns tied to this program at present.
What was checked. Reviewed the alert signal and weight, the transfer record (status, return code, amount, dates), the originating entity's verification and screening status, and the program KRI panel for related indicators (unauthorized return rate, high-risk entity share, sanctioned country transfers, stale screening). No prior dispositions exist for this alert or entity. The program KRI panel shows a manual_review_aging_hours breach (1434.7 hours, n=7) and watch-level PEP/high-risk entity shares, but these are program-wide figures not specific to this transfer or counterparty.
What is recommended. Because the transfer has already settled and carries no return code, there are no funds to hold on this transaction. The single signal is historical (one prior unauthorized return by the counterparty) and is not corroborated by any return, screening, or KRI anomaly on this transfer or the originating entity. Recommend closing this alert. A person should note the counterparty's prior unauthorized return for reference on any future transfers to the same counterparty.
- Recommendation
- close
- Confidence
- 0.68
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer status is SETTLED with return code none; nothing about this specific transaction failed or is in dispute.
- The alert's sole signal (counterparty_prior_unauthorized) reflects one historical event on the counterparty, not a signal on this transfer's outcome.
- Originating entity is VERIFIED, not high risk, not PEP, with current screening (2026-08-17) predating the transfer.
- Program-level ach_unauthorized_return_rate is 0 (n=302), showing no active pattern of unauthorized returns to escalate.
- Evidence is thin on the counterparty itself (no entity profile, no country, no detail on when/why the prior unauthorized return occurred), which limits confidence but does not by itself justify a hold on an already-settled transfer.
- No prior dispositions exist to indicate repeat alerting on this counterparty or entity.
Evidence
{
"n": 817,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.