Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $699.98 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_6lqehads8at
- Transfer
- acht_sim_harb_6lqehads8at · $699.98 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 207ae8b1-3790-4ac3-bbfd-d4d507b2772f flagged an outgoing ACH transfer of $699.98 (acht_sim_harb_6lqehads8at) under the skoor_review detector at severity medium. The transaction risk score was 40, landing in the review band, driven by a single signal: the counterparty has 2 prior unauthorized returns. Hard signal is false. The transfer itself settled with no return code.
What the evidence shows. The transfer status is SETTLED with return code none, meaning the funds have already moved and this specific transaction did not itself return or fail. The associated entity, Heath Holdings 119, is VERIFIED, not high risk, not PEP, with no review reasons and screening current as of 2026-09-01. The skoor of 40 rests entirely on one signal, weight 40, reflecting the counterparty's history of 2 prior unauthorized returns, not anything about this transaction's execution. At the program level, ach_unauthorized_return_rate is in breach (0.00885) and manual_review_aging_hours is in breach (1438 hours), while counterparty_concentration_top1 (0.076) and velocity_vs_declared (0.065) remain in the ok range. No prior dispositions exist for this alert.
What was checked. Transfer status and return code, entity verification and risk flags, the specific signal driving the skoor, program KRI panel for related breach conditions, and prior disposition history.
What is recommended. Because the transfer is already SETTLED and the review-band score stems solely from the counterparty's prior unauthorized-return history rather than a failure on this transaction, there is nothing to hold or release here. However, the counterparty carries 2 prior unauthorized returns, and the program shows a breach-level ach_unauthorized_return_rate alongside a breach in manual_review_aging_hours. This combination suggests the counterparty's return history may be part of a broader pattern that a single alert review will not capture. Recommend escalating for a person to review the counterparty's full transaction and return history across the program, and to assess whether the aging-hours breach reflects a backlog affecting review quality on similar alerts.
- Recommendation
- escalate
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer is SETTLED with no return code; this specific transaction did not fail, so hold/release do not apply.
- Skoor of 40 is driven entirely by counterparty's 2 prior unauthorized returns (weight 40), a pattern signal rather than a transaction-execution issue.
- Entity is VERIFIED, not high risk, not PEP, with no review reasons, reducing concern about this specific entity.
- Program KRI ach_unauthorized_return_rate is in breach, consistent with the counterparty-level signal and suggesting a broader pattern worth a person's review.
- manual_review_aging_hours is also in breach, indicating review capacity concerns that could affect handling of similar counterparty-risk alerts.
- No prior dispositions exist to indicate this pattern has already been reviewed and cleared.
Evidence
{
"n": 1737,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "2 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 2 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.