Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $381.94 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_b3h7z5u49cq
- Transfer
- acht_sim_harb_b3h7z5u49cq · $381.94 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An ACH outgoing debit transfer of $381.94 (acht_sim_harb_b3h7z5u49cq) under the Harbor Marketplace Payouts program was flagged by the skoor_review detector at Skoor 40 (review band) due to the counterparty having 2 prior unauthorized ACH returns. The transfer itself has already settled with no return code recorded.
What the evidence shows. The transfer skoor model (n=2166, confidence 1) placed this transaction in the review band solely because of the counterparty's history: 2 prior unauthorized returns, contributing the full 40-point weight. The transfer's own return code is none, meaning it settled without incident. The subject entity (Elm Partners 14) is VERIFIED, not high risk, not PEP, with no open review reasons and a recent screening date. At the program level, however, the ach_unauthorized_return_rate KRI shows a breach (0.00816 against threshold), and manual_review_aging_hours is also in breach (1438 hours), while several other KRIs sit in watch status (hold_aging_hours, overdraft_events, card_fraud_declines, pep_flagged_entities, high_risk_entity_share). Hard signal is false, meaning this alert alone is not deterministic evidence of fraud.
What was checked. Reviewed the transfer record (status, amount, return code), the entity verification and risk flags, the program's declared volume and KRI panel, and prior dispositions. No prior dispositions exist for this alert or subject. No sanctioned country or frozen account issues are present. The counterparty's country is unknown, which limits full verification of counterparty risk.
What is recommended. Because the transfer has already settled, there is no fund movement to hold or release. The individual transaction shows no direct anomaly, but the counterparty's repeat unauthorized-return history combined with a program-level breach in ach_unauthorized_return_rate and manual_review_aging_hours suggests this alert may be part of a broader pattern affecting multiple transfers under this program rather than an isolated event. This warrants escalation for a person to review the counterparty history and program-level return trend together, rather than closing this single alert in isolation.
- Recommendation
- escalate
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is SETTLED with no return code, so hold/release actions do not apply to this alert.
- The alert's sole basis is counterparty history (2 prior unauthorized returns), not an anomaly in this specific transfer.
- Program-level ach_unauthorized_return_rate KRI is in breach status, and manual_review_aging_hours is also in breach, indicating a pattern beyond this single alert.
- Entity-level checks (VERIFIED, not high risk, not PEP, recent screening) do not indicate direct entity risk, tempering the confidence.
- Counterparty country is unknown, limiting full risk assessment and supporting escalation over closure.
- Hard signal is false and no prior dispositions exist, so confidence is moderate rather than high.
Evidence
{
"n": 2166,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "2 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 3 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.