SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $917.57 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_344te6gf8s6
Transfer
acht_sim_harb_344te6gf8s6 · $917.57 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 437ad0d1 fired on outgoing ACH transfer acht_sim_harb_344te6gf8s6 for $917.57, opened 2026-09-17. The detector skoor_review scored the transfer 40 (review band, hard_signal false) on the single signal returns.counterparty_prior_unauthorized, meaning the counterparty cpty_sim_harb_39i9ftby3xi has one prior unauthorized return on record. What the evidence shows. The transfer itself is already SETTLED with return code none, so it did not itself return unauthorized. The entity behind the transfer, enti_sim_harb_ax0fq0ns3w8 (Fern Studio 117), is VERIFIED, not high risk, not PEP, with no review reasons and screening current as of 2026-08-29. The signal weight (40) accounts for the entire skoor and reflects one prior unauthorized return event on the counterparty, not a pattern on this entity. Program-level KRIs show ach_unauthorized_return_rate at 0.78% (n=767) flagged as breach, and manual_review_aging_hours at 1438 hours (n=14) also flagged as breach. Other KRIs (frozen_accounts, overdraft_events, velocity_vs_declared, reserve_coverage_ratio, sanctioned_country_transfers) are ok. No prior dispositions exist on this alert. What was checked. Transfer status and return code, entity verification/PEP/high-risk status and screening recency, program KRI panel, and prior disposition history. No counterparty-level KRI or history beyond the one prior unauthorized return cited in the signal is present in this context. What is recommended. The transfer is already settled, so there is no held transfer to release and no funds movement to stop. The single-signal basis (one prior unauthorized return) combined with a verified, non-high-risk entity is thin grounds to treat this alert alone as needing a hold. However, the program's ach_unauthorized_return_rate is independently flagged as breach at the portfolio level, which is the same risk category this alert's signal draws from, and manual_review_aging_hours is also in breach. This combination suggests the unauthorized-return pattern may be broader than this one alert and warrants a person looking at the counterparty and program-level trend rather than a routine close.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer acht_sim_harb_344te6gf8s6 is SETTLED with return code none; hold/release does not apply to a completed transfer.
  • Alert rests on a single signal (one prior unauthorized return on the counterparty) with hard_signal false and skoor 40 in the review band, not an auto-closable severity per routeReason.
  • Entity is VERIFIED, not high risk, not PEP, screening current, which weighs against escalation on entity grounds alone.
  • Program KRI ach_unauthorized_return_rate is flagged breach (0.78%, n=767), the same category as this alert's signal, indicating this may not be an isolated event.
  • manual_review_aging_hours is also flagged breach (1438 hours, n=14), suggesting review backlog that could delay follow-up if not escalated now.
  • No prior dispositions exist to indicate this counterparty pattern has already been reviewed and cleared.

Evidence

{
  "n": 1915,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+403 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.