SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 30 (review band) on a $491.00 ach transfer: returns.counterparty_prior_any, returns.entity_rate_gt_threshold.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_brerjepc799
Transfer
acht_sim_harb_brerjepc799 · $491.00 · ach outgoing
Skoor at alert
30 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Transaction Risk Skoor flagged an outgoing ACH debit of $491.00 (transfer acht_sim_harb_brerjepc799) under program Harbor Marketplace Payouts. The transfer settled on 2026-08-19 with no return code. The alert scored 30 (review band) on two signals: a prior non-NSF return for the counterparty and an entity-level unauthorized return rate exceeding threshold (1 of 27 originated ACH debits in 60 days). What the evidence shows. The transfer itself settled cleanly with no return. The two signals driving the score relate to history, not this transaction: one prior return (other than NSF) tied to the counterparty, and an entity-level unauthorized return rate of 1/27 (3.7%) over 60 days. The originating entity, Juniper LLC 19, is VERIFIED, not high risk, not PEP, with no open review reasons and screening current as of 2026-07-06. Counterparty country is unknown. At the program level, two KRIs are in breach: manual_review_aging_hours (1438.0, n=8) and ach_unauthorized_return_rate (0.0104, n=479), alongside three KRIs in watch status (hold_aging_hours, pep_flagged_entities, high_risk_entity_share). No prior dispositions exist for this alert. What was checked. Transfer status and return code, entity verification and screening status, signal detail and weights, program KRI panel, and prior disposition history. No additional transaction-level irregularity (e.g., sanctioned country, velocity breach) was found; velocity_vs_declared and sanctioned_country_transfers are both at ok/zero. What is recommended. The transfer already settled, so no funds are available to hold on this alert. However, the alert signals point to entity-level and counterparty-level return history rather than a one-off event, and this coincides with two program-wide KRI breaches (manual_review_aging_hours, ach_unauthorized_return_rate). This combination suggests a pattern extending beyond this single transfer that a person should review across the program, not just close at the alert level.
Recommendation
escalate
Confidence
0.58
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer acht_sim_harb_brerjepc799 settled with no return code; no funds are held at this alert.
  • Both alert signals (counterparty_prior_any, entity_rate_gt_threshold) reflect historical return patterns for the entity/counterparty, not a defect in this transaction itself.
  • Program KRIs show two breaches (manual_review_aging_hours=1438.0h, ach_unauthorized_return_rate=0.0104) concurrent with this alert, consistent with a broader pattern rather than an isolated event.
  • Entity Juniper LLC 19 is VERIFIED, not high risk, not PEP, with current screening, reducing concern about this specific entity's identity risk.
  • No prior dispositions exist to indicate this pattern was already reviewed or resolved.

Evidence

{
  "n": 1278,
  "band": "review",
  "skoor": 30,
  "signals": [
    {
      "code": "returns.counterparty_prior_any",
      "detail": "1 prior return(s) other than NSF",
      "weight": 15
    },
    {
      "code": "returns.entity_rate_gt_threshold",
      "detail": "entity unauthorized return rate 1/27 originated ACH debits in 60d",
      "weight": 15
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_any+151 prior return(s) other than NSF
returns.entity_rate_gt_threshold+15entity unauthorized return rate 1/27 originated ACH debits in 60d

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.