SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $316.36 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_1tjw5ydj7rg
Transfer
acht_sim_harb_1tjw5ydj7rg · $316.36 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An ACH outgoing debit of $316.36 from Harbor Marketplace Payouts to counterparty cpty_sim_harb_1iejz6444vr was flagged by the skoor_review detector at Transaction Risk Skoor 40 (review band), driven by a single signal: the counterparty has one prior unauthorized return on record. The transfer itself settled with no return code. What the evidence shows. The transfer already settled cleanly (status SETTLED, return code none), so the funds have moved and there is nothing pending to hold. The skoor is driven entirely by one prior unauthorized return on this counterparty, weighted at 40, which alone places it in the review band (hard_signal false). The entity behind the program, Birch Holdings 11, is VERIFIED, not high risk, not PEP, and was screened 2026-07-02 with no review reasons. At the program level, the KRI panel shows ach_unauthorized_return_rate at 0.0108 flagged as a breach (n=556), and manual_review_aging_hours at 1438 hours also flagged as a breach (n=9). Several other KRIs (pep_flagged_entities, high_risk_entity_share, hold_aging_hours) sit in watch status. There are no prior dispositions on this alert. What was checked. Reviewed the alert evidence block, the transfer record, the linked entity's verification and screening status, and the program-level KRI panel. Confirmed the transfer status (settled, no return), confirmed the entity has no high-risk or PEP flags, and confirmed there is no disposition history to draw on. What is recommended. The individual transfer poses no immediate funds-movement risk since it has already settled and the associated entity is verified and clean. However, the program-level ach_unauthorized_return_rate is flagged as a breach, and this alert's sole trigger is a prior unauthorized return on the same rail. This alignment between a program-wide breach metric and the specific signal driving this alert suggests the single counterparty flag may be part of a broader pattern across the program rather than an isolated event. This should be escalated for a person to review whether the unauthorized-return breach reflects a systemic counterparty or program issue beyond this one transfer.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is SETTLED with no return code, so there is no held transfer to release or hold.
  • The alert's only signal (prior unauthorized return, weight 40) matches the program-level KRI ach_unauthorized_return_rate, which is independently flagged as a breach (0.0108, n=556).
  • The entity is VERIFIED, not high risk, not PEP, with recent clean screening, which weighs against a straightforward close-as-routine escalation to a person versus indicating deeper program-level review is warranted given the KRI breach.
  • No prior dispositions exist to indicate this pattern has already been reviewed or accepted.
  • Confidence is moderate because the KRI breach is program-wide and not confirmed to trace specifically to this counterparty; a person should verify whether the two are linked before deciding on program-level action.

Evidence

{
  "n": 1485,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.