SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $1,366.37 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_66nc4rr927x
Transfer
acht_sim_nort_66nc4rr927x · $1,366.37 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. A $1,366.37 outgoing ACH debit from Northwind Payroll (simulated) to counterparty cpty_sim_nort_25c8izfo4a settled on 2026-08-18. The transaction risk score of 40 placed it in the review band due to a single flagged signal: the counterparty has one prior unauthorized return on record. The transfer itself carries no return code. What the evidence shows. The only signal driving the score is returns.counterparty_prior_unauthorized, weighted at 40, based on one prior unauthorized return for this counterparty (n=817 population). The transfer in question shows status SETTLED with return code none, meaning it did not itself return unauthorized or otherwise. The originating entity, Alder Co 024, is VERIFIED, not high risk, not PEP, has no review reasons, and was screened on 2026-08-17, one day before the transfer. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=302, ok) and ach_overall_return_rate at 0.99% (ok), indicating no broader pattern of unauthorized returns tied to this program at present. What was checked. Reviewed the alert signal and weight, the transfer record (status, return code, amount, dates), the originating entity's verification and screening status, and the program KRI panel for related indicators (unauthorized return rate, high-risk entity share, sanctioned country transfers, stale screening). No prior dispositions exist for this alert or entity. The program KRI panel shows a manual_review_aging_hours breach (1434.7 hours, n=7) and watch-level PEP/high-risk entity shares, but these are program-wide figures not specific to this transfer or counterparty. What is recommended. Because the transfer has already settled and carries no return code, there are no funds to hold on this transaction. The single signal is historical (one prior unauthorized return by the counterparty) and is not corroborated by any return, screening, or KRI anomaly on this transfer or the originating entity. Recommend closing this alert. A person should note the counterparty's prior unauthorized return for reference on any future transfers to the same counterparty.
Recommendation
close
Confidence
0.68
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer status is SETTLED with return code none; nothing about this specific transaction failed or is in dispute.
  • The alert's sole signal (counterparty_prior_unauthorized) reflects one historical event on the counterparty, not a signal on this transfer's outcome.
  • Originating entity is VERIFIED, not high risk, not PEP, with current screening (2026-08-17) predating the transfer.
  • Program-level ach_unauthorized_return_rate is 0 (n=302), showing no active pattern of unauthorized returns to escalate.
  • Evidence is thin on the counterparty itself (no entity profile, no country, no detail on when/why the prior unauthorized return occurred), which limits confidence but does not by itself justify a hold on an already-settled transfer.
  • No prior dispositions exist to indicate repeat alerting on this counterparty or entity.

Evidence

{
  "n": 817,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.