SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $476.02 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_4vxfbl727n3
Transfer
acht_sim_harb_4vxfbl727n3 · $476.02 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 29e5fbb5-6d89-4486-8891-ce46c82a1717 fired on an outgoing ACH transfer (acht_sim_harb_4vxfbl727n3) of $476.02 from the Harbor Marketplace Payouts program. The skoor_review detector scored the transfer 40, placing it in the review band, on the basis of a single signal: the counterparty has 2 prior unauthorized returns (weight 40). What the evidence shows. The transfer itself is settled with no return code, so this specific transaction did not fail. The signal is entirely counterparty-history based (2 prior unauthorized returns), and hard_signal is false, meaning the detector did not treat this as a confirmed fraud indicator. The paying entity, Cedar Services 12, is VERIFIED, not high risk, not PEP, has no open review reasons, and was screened 2026-07-03. At the program level, ach_unauthorized_return_rate is flagged as a breach (0.0113 against n=530), while overall ach_overall_return_rate (0.0245) and administrative return rate (0.0057) are within normal ranges. Manual_review_aging_hours is also flagged as a breach (1438 hours, n=9), suggesting reviews in this program are taking longer than expected to clear. What was checked. Reviewed the alert evidence, the transfer record, the entity verification status, and program-level KRIs. Confirmed the transfer is settled with no return code attached, confirmed the entity has no adverse screening findings, and confirmed there are no prior dispositions on this alert or entity. What is recommended. The transfer already settled, so there are no funds to hold, and release does not apply since it was never held. The counterparty-level unauthorized-return signal combined with the program-level ach_unauthorized_return_rate breach suggests this alert is not isolated to one transaction but may reflect a broader pattern in the counterparty base. This warrants escalation for a person to review counterparty-level history across the program rather than a single-alert close.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer is SETTLED with no return code; nothing in this alert requires funds movement, ruling out hold or release.
  • The triggering signal (2 prior unauthorized returns for this counterparty) is a repeat-pattern indicator, not a one-off event finding.
  • Program KRI ach_unauthorized_return_rate is in breach status, suggesting the counterparty-level signal may reflect a program-wide trend rather than an isolated case.
  • Manual_review_aging_hours is also in breach, indicating review backlogs that support routing this to a person rather than auto-closing.
  • Entity itself is verified, not high risk, not PEP, and has no adverse screening findings, so entity-level risk alone does not justify escalation; the escalation basis is the combination of the return-history signal with program-level breach metrics.
  • Confidence is moderate because the alert evidence is limited to one signal and one transfer; a full pattern assessment requires review of other transfers tied to this counterparty, which is outside this alert's evidence.

Evidence

{
  "n": 1450,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "2 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+402 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.