SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $866.60 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_6qqfz33g50n
Transfer
acht_sim_harb_6qqfz33g50n · $866.60 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 411b96a4-83f9-4e1d-b1b0-0552c5df9667 flagged an $866.60 outgoing ACH credit transfer (acht_sim_harb_6qqfz33g50n) under program Harbor Marketplace Payouts. The transaction risk skoor engine scored the transfer at 40, placing it in the review band, based on a single signal: the counterparty has 1 prior unauthorized ACH return. What the evidence shows. The transfer itself is SETTLED with return code none, meaning this specific transaction completed without any return or dispute. The only signal driving the score is a historical count (1 prior unauthorized return) tied to counterparty cpty_sim_harb_gzii64r41f, whose country is unknown. Hard_signal is false and the detector notes routeReason as 'detector not auto-closable' rather than any confirmed fraud finding. The originating entity, Reconciliation Agent (Harbor), is VERIFIED, not high risk, not PEP, has no review reasons, and was screened 2026-06-28. Program-level KRIs are mostly OK: ach_unauthorized_return_rate is 0 across n=72, ach_overall_return_rate is 0, sanctioned_country_transfers is 0, and reserve_coverage_ratio is well above target. Two KRIs sit at watch (pep_flagged_entities=1/30, high_risk_entity_share=6.7%) and manual_review_aging_hours shows a breach (1438 hours, n=2), but none of these tie directly to this transfer or this counterparty. What was checked. Reviewed the transfer status and return code, the entity verification and screening record, the full KRI panel for the program, and prior dispositions on this alert (none exist). Confirmed the skoor evidence contains only one signal and no hard signal flag. What is recommended. The transfer is already settled, so there are no funds to hold or release. The evidence does not show a return, dispute, or confirmed loss on this transaction, and the originating entity is verified with no other risk indicators. The single counterparty-history signal is thin on its own and does not point to a broader pattern in this alert's evidence. Recommend closing the alert. The manual_review_aging_hours breach is a separate operational matter for the review queue and does not change the disposition of this specific alert.
Recommendation
close
Confidence
0.68
Model
claude-sonnet-5
Drafted
2026-09-17 19:30Z
Rationale
  • Transfer status is SETTLED with return code none; no adverse outcome occurred on this transaction.
  • Only one signal (returns.counterparty_prior_unauthorized, weight 40) drove the review-band score; hard_signal is false.
  • Originating entity is VERIFIED, not high risk, not PEP, with no review reasons and recent screening (2026-06-28).
  • Program-level unauthorized and overall ACH return rates are 0 across n=72, showing no systemic return pattern.
  • No prior dispositions exist on this alert, so there is no escalating history for this specific counterparty or transfer.
  • Confidence is moderated because the counterparty's country is unknown and the underlying prior unauthorized return is not detailed beyond a count of 1.

Evidence

{
  "n": 376,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 0.94,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+402 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.