Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $917.57 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_344te6gf8s6
- Transfer
- acht_sim_harb_344te6gf8s6 · $917.57 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 437ad0d1 fired on outgoing ACH transfer acht_sim_harb_344te6gf8s6 for $917.57, opened 2026-09-17. The detector skoor_review scored the transfer 40 (review band, hard_signal false) on the single signal returns.counterparty_prior_unauthorized, meaning the counterparty cpty_sim_harb_39i9ftby3xi has one prior unauthorized return on record.
What the evidence shows. The transfer itself is already SETTLED with return code none, so it did not itself return unauthorized. The entity behind the transfer, enti_sim_harb_ax0fq0ns3w8 (Fern Studio 117), is VERIFIED, not high risk, not PEP, with no review reasons and screening current as of 2026-08-29. The signal weight (40) accounts for the entire skoor and reflects one prior unauthorized return event on the counterparty, not a pattern on this entity. Program-level KRIs show ach_unauthorized_return_rate at 0.78% (n=767) flagged as breach, and manual_review_aging_hours at 1438 hours (n=14) also flagged as breach. Other KRIs (frozen_accounts, overdraft_events, velocity_vs_declared, reserve_coverage_ratio, sanctioned_country_transfers) are ok. No prior dispositions exist on this alert.
What was checked. Transfer status and return code, entity verification/PEP/high-risk status and screening recency, program KRI panel, and prior disposition history. No counterparty-level KRI or history beyond the one prior unauthorized return cited in the signal is present in this context.
What is recommended. The transfer is already settled, so there is no held transfer to release and no funds movement to stop. The single-signal basis (one prior unauthorized return) combined with a verified, non-high-risk entity is thin grounds to treat this alert alone as needing a hold. However, the program's ach_unauthorized_return_rate is independently flagged as breach at the portfolio level, which is the same risk category this alert's signal draws from, and manual_review_aging_hours is also in breach. This combination suggests the unauthorized-return pattern may be broader than this one alert and warrants a person looking at the counterparty and program-level trend rather than a routine close.
- Recommendation
- escalate
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer acht_sim_harb_344te6gf8s6 is SETTLED with return code none; hold/release does not apply to a completed transfer.
- Alert rests on a single signal (one prior unauthorized return on the counterparty) with hard_signal false and skoor 40 in the review band, not an auto-closable severity per routeReason.
- Entity is VERIFIED, not high risk, not PEP, screening current, which weighs against escalation on entity grounds alone.
- Program KRI ach_unauthorized_return_rate is flagged breach (0.78%, n=767), the same category as this alert's signal, indicating this may not be an isolated event.
- manual_review_aging_hours is also flagged breach (1438 hours, n=14), suggesting review backlog that could delay follow-up if not escalated now.
- No prior dispositions exist to indicate this counterparty pattern has already been reviewed and cleared.
Evidence
{
"n": 1915,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 3 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.