SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $575.40 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Meridian Remit (simulated)
Subject
transfer acht_sim_meri_a4xj689ecac
Transfer
acht_sim_meri_a4xj689ecac · $575.40 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 242e26ee-b19f-41aa-b609-7fd49f71df06 fired on a $575.40 outgoing ACH transfer (acht_sim_meri_a4xj689ecac) under the skoor_review detector, medium severity, because the counterparty on this transfer has 2 prior unauthorized returns. The transfer risk score was 40, placing it in the review band; hard_signal is false. What the evidence shows. The transfer itself settled with no return code, so this specific transaction was not returned or flagged as unauthorized. The single evidence signal is returns.counterparty_prior_unauthorized, weight 40, based on 2 prior unauthorized returns tied to counterparty cpty_sim_meri_6hloyf56aa7, whose country is unknown. The originating entity, Meridian Remit, is a verified US business with no high-risk flag, no PEP flag, no open review reasons, last screened 2026-07-29. Program-level KRIs show several breaches: reserve_coverage_ratio (0.48, breach), manual_review_aging_hours (1146.9h, breach), ach_unauthorized_return_rate (1.18%, breach), and sanctioned_country_transfers (2 of 923, breach). These are program-wide figures, not specific to this transfer or counterparty, but they indicate broader operational and return-handling issues at the program level. What was checked. Transfer status and return code, counterparty screening data (country unknown), entity verification and risk flags, transfer-level skoor evidence, and program KRI panel. No prior dispositions exist for this alert. The transfer is already SETTLED, so no funds are currently held pending action. What is recommended. Because the transfer has already settled, there is no held transfer to release or hold. The immediate transaction shows no return or unauthorized-activity outcome on its own. However, the counterparty's history of 2 prior unauthorized returns combined with unknown counterparty country and program-level breaches in unauthorized return rate and reserve coverage suggests a pattern that may extend beyond this single alert. A person should review the counterparty's transaction history and the program's return-handling and reserve metrics to determine if broader action is needed.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer acht_sim_meri_a4xj689ecac is SETTLED with no return code, so no funds are held and 'release' does not apply.
  • The sole risk signal (2 prior unauthorized returns on the counterparty) concerns counterparty history, not this transaction's outcome, and counterparty country is unknown, limiting full assessment.
  • Program KRIs show breaches in ach_unauthorized_return_rate, reserve_coverage_ratio, manual_review_aging_hours, and sanctioned_country_transfers, indicating this alert may sit within a larger pattern warranting review beyond a single-transfer disposition.
  • Entity Meridian Remit is verified, not high-risk, not PEP, with no open review reasons, which weighs against elevating entity-level risk absent more counterparty-specific data.
  • Given settlement status and the counterparty pattern plus program breaches, escalation for a person to review counterparty and program-level trends is more appropriate than closing outright.

Evidence

{
  "n": 1046,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "2 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+402 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.