SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Counterparty Receiver 44 entered the hold band (Skoor 90, n=9): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.review_share, counterparty.new.

Detector
counterparty_hold
Severity
high
Program
Meridian Remit (simulated)
Subject
counterparty cpty_sim_meri_4t9h3oztaja
Transfer
Skoor at alert
90 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Counterparty cpty_sim_meri_4t9h3oztaja was scored by the counterparty_hold detector and entered the hold band. Skoor reached 90 on a sample of 9 transactions, and severity is recorded as high. The alert routed to review because the detector is not auto-closable, and autoHold is set to true. What the evidence shows. Of 9 observed transactions with this counterparty, 1 was an unauthorized return. This single return drove three of the five signals: unauthorized_returns (weight 40), unauthorized_rate at 1/9 which is above the network threshold (weight 15), and return_rate at 1/9 (weight 15). Review_share shows 75% of this counterparty's transactions fall in the review band (weight 10), and the counterparty is newly seen, first observed 0 days ago (weight 10). The detector's own confidence in this score is low at 0.226, and hard_signal is false, meaning no deterministic rule (e.g., sanctions match) fired. The sample size of 9 is small, so a single unauthorized return has an outsized effect on the rate-based signals. What was checked. Program-level KRIs for Meridian Remit (simulated) were reviewed for context. ach_unauthorized_return_rate is 0.013 (n=307) and flagged as a breach, reserve_coverage_ratio is 0.737 (n=307) and flagged as a breach, and manual_review_aging_hours is 1146.86 (n=2) and flagged as a breach. hold_aging_hours (1364.97, n=4) and pep_flagged_entities (1, n=30) are flagged watch. Other KRIs, including sanctioned_country_transfers, stale_screening_share, and counterparty_concentration_top1, are within normal range. No prior dispositions exist for this alert or counterparty. The program-level breaches are not specific to this counterparty and cannot be attributed to it from the evidence given. What is recommended. Given the hold band, autoHold flag, and the fact that this counterparty is new with a small transaction sample driven by a single unauthorized return, a person should review before any further transactions with this counterparty are processed. The low detector confidence (0.226) and small n (9) mean the score could shift quickly with more data, so this should not be closed without review. The program-level breaches (reserve_coverage_ratio, ach_unauthorized_return_rate, manual_review_aging_hours) are noted for awareness but the evidence here does not establish a link between those breaches and this specific counterparty, so escalation to a program-wide pattern is not supported by this alert alone.
Recommendation
hold
Confidence
0.40
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Skoor is 90 in the hold band with autoHold true, indicating the system default is to not release pending review.
  • The unauthorized return and elevated rates are based on only 9 transactions, so the statistical basis is thin and detector confidence is low (0.226).
  • The counterparty is newly seen (0 days), which independently contributes to the score and warrants a person's judgment before further activity.
  • Hard_signal is false, so no deterministic rule triggered; this is a scored/heuristic alert, not a confirmed violation.
  • Program KRIs show separate breaches (reserve_coverage_ratio, ach_unauthorized_return_rate, manual_review_aging_hours) but the evidence does not tie these to this counterparty, so escalation beyond this alert is not supported.
  • No prior dispositions exist to inform pattern history for this counterparty.

Evidence

{
  "n": 9,
  "band": "hold",
  "skoor": 90,
  "signals": [
    {
      "code": "counterparty.unauthorized_returns",
      "detail": "drew 1 unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "counterparty.unauthorized_rate",
      "detail": "unauthorized rate 1/9 above the network threshold",
      "weight": 15
    },
    {
      "code": "counterparty.return_rate",
      "detail": "return rate 1/9",
      "weight": 15
    },
    {
      "code": "counterparty.review_share",
      "detail": "75% in the review band",
      "weight": 10
    },
    {
      "code": "counterparty.new",
      "detail": "first seen 0d ago",
      "weight": 10
    }
  ],
  "version": "crs-v1",
  "autoHold": true,
  "confidence": 0.226,
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.