SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $507.36 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_9qyu4ytt9bb
Transfer
acht_sim_harb_9qyu4ytt9bb · $507.36 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 0b806e1c-3a64-48f6-be62-fe32d685d493 fired on transfer acht_sim_harb_9qyu4ytt9bb, an outgoing ACH credit of $507.36 under the Harbor Marketplace Payouts program. The detector skoor_review scored the transaction 40 (review band) because the counterparty cpty_sim_harb_bmqeuc7o3xi has one prior unauthorized return on record. The transfer itself has no return code and is already in SETTLED status. What the evidence shows. The single scoring signal is returns.counterparty_prior_unauthorized, weight 40, based on one prior unauthorized return for this counterparty. There is no current return code on this transfer, and hard_signal is false. The originating entity, Harbor Marketplace Payouts, is VERIFIED, not high risk, not PEP, with no open review reasons and a recent screening date (2026-07-15). Program-level KRIs show two items in breach status: manual_review_aging_hours (1438.05 hours, n=16) and ach_unauthorized_return_rate (0.00816, n=858). Several other KRIs are at watch level (hold_aging_hours, overdraft_events, card_fraud_declines, pep_flagged_entities, high_risk_entity_share) but within stated thresholds. Prior dispositions: none on record for this alert. What was checked. Reviewed the alert evidence block, the transfer record and its status, the originating entity's verification and screening status, the program's declared volume and KRI panel, and the prior disposition history. No counterparty-specific KRI or history beyond the single prior unauthorized return was available in the context. What is recommended. The transfer is already settled, so there are no funds to hold or release on this alert. The scoring basis is a single prior unauthorized return with no current return code, and the entity is verified with a clean review history. However, two program-level KRIs are in breach (manual_review_aging_hours and ach_unauthorized_return_rate), which is evidence of a broader pattern beyond this individual alert and warrants review by a person to determine whether the counterparty or program requires closer attention.
Recommendation
escalate
Confidence
0.52
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer is SETTLED with no return code; there is no pending movement to hold or release on this alert.
  • The alert's own signal is limited to one prior unauthorized return for the counterparty, with hard_signal false and skoor in the review (not high) band.
  • Originating entity is VERIFIED, not high risk, no PEP flag, no open review reasons, and recently screened, which does not support a hold on entity-level grounds.
  • Program KRI panel shows two items in breach (manual_review_aging_hours=1438.05h; ach_unauthorized_return_rate=0.00816), indicating a pattern at the program level that this single alert does not fully explain.
  • No prior dispositions exist for this alert or counterparty in the provided context, limiting confidence in whether this is an isolated event or part of a recurring issue.
  • Given the breach-level KRIs, a person should assess whether this counterparty's unauthorized-return history is part of the broader program trend rather than closing on this alert's narrow evidence alone.

Evidence

{
  "n": 2146,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.