Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $316.36 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_1tjw5ydj7rg
- Transfer
- acht_sim_harb_1tjw5ydj7rg · $316.36 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An ACH outgoing debit of $316.36 from Harbor Marketplace Payouts to counterparty cpty_sim_harb_1iejz6444vr was flagged by the skoor_review detector at Transaction Risk Skoor 40 (review band), driven by a single signal: the counterparty has one prior unauthorized return on record. The transfer itself settled with no return code.
What the evidence shows. The transfer already settled cleanly (status SETTLED, return code none), so the funds have moved and there is nothing pending to hold. The skoor is driven entirely by one prior unauthorized return on this counterparty, weighted at 40, which alone places it in the review band (hard_signal false). The entity behind the program, Birch Holdings 11, is VERIFIED, not high risk, not PEP, and was screened 2026-07-02 with no review reasons. At the program level, the KRI panel shows ach_unauthorized_return_rate at 0.0108 flagged as a breach (n=556), and manual_review_aging_hours at 1438 hours also flagged as a breach (n=9). Several other KRIs (pep_flagged_entities, high_risk_entity_share, hold_aging_hours) sit in watch status. There are no prior dispositions on this alert.
What was checked. Reviewed the alert evidence block, the transfer record, the linked entity's verification and screening status, and the program-level KRI panel. Confirmed the transfer status (settled, no return), confirmed the entity has no high-risk or PEP flags, and confirmed there is no disposition history to draw on.
What is recommended. The individual transfer poses no immediate funds-movement risk since it has already settled and the associated entity is verified and clean. However, the program-level ach_unauthorized_return_rate is flagged as a breach, and this alert's sole trigger is a prior unauthorized return on the same rail. This alignment between a program-wide breach metric and the specific signal driving this alert suggests the single counterparty flag may be part of a broader pattern across the program rather than an isolated event. This should be escalated for a person to review whether the unauthorized-return breach reflects a systemic counterparty or program issue beyond this one transfer.
- Recommendation
- escalate
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is SETTLED with no return code, so there is no held transfer to release or hold.
- The alert's only signal (prior unauthorized return, weight 40) matches the program-level KRI ach_unauthorized_return_rate, which is independently flagged as a breach (0.0108, n=556).
- The entity is VERIFIED, not high risk, not PEP, with recent clean screening, which weighs against a straightforward close-as-routine escalation to a person versus indicating deeper program-level review is warranted given the KRI breach.
- No prior dispositions exist to indicate this pattern has already been reviewed or accepted.
- Confidence is moderate because the KRI breach is program-wide and not confirmed to trace specifically to this counterparty; a person should verify whether the two are linked before deciding on program-level action.
Evidence
{
"n": 1485,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.