SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $350.51 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_7xyhf2fy93i
Transfer
acht_sim_harb_7xyhf2fy93i · $350.51 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. A $350.51 outgoing ACH transfer (acht_sim_harb_7xyhf2fy93i) under the Harbor Marketplace Payouts program was flagged by the skoor_review detector at a Transaction Risk Skoor of 40, placing it in the review band. The triggering signal is that the counterparty on this transfer has 2 prior unauthorized returns. What the evidence shows. The transfer itself settled with no return code recorded, so this specific transaction did not return as unauthorized. The alert is driven entirely by the counterparty's history: 2 prior unauthorized returns (weight 40, full contribution to the skoor). The hard_signal flag is false, and skoor confidence is 1 with a large reference population (n=2070). The originating entity, Iris Services 120, is VERIFIED, not high risk, not PEP, and has no review reasons, last screened 2026-09-06. At the program level, ach_unauthorized_return_rate (0.85%) is flagged as a breach against its threshold, and manual_review_aging_hours (1438 hours, ~60 days) is also in breach, indicating review backlog. Other KRIs (frozen_accounts, verification_denial_rate, sanctioned_country_transfers, counterparty_concentration) are ok or watch, showing no other acute program-wide stress. What was checked. Reviewed the transfer status and return code, the entity's verification and screening status, the skoor evidence and signal weighting, and the program KRI panel for corroborating or contradicting patterns. No prior dispositions exist for this alert or entity. What is recommended. The transfer has already settled, so there is no fund movement to hold or release. However, the counterparty's repeated unauthorized-return history combined with a program-level breach in ach_unauthorized_return_rate suggests this may not be an isolated case; a person should review the counterparty's transaction history across the program to determine if a broader pattern of unauthorized-return risk is developing.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is SETTLED with no return code, so no funds are pending movement; 'hold' or 'release' do not apply.
  • The sole driver of the skoor is the counterparty's 2 prior unauthorized returns, a signal specific to counterparty history rather than this transaction.
  • The originating entity is verified, not high risk, and has no review reasons, which weighs against escalation on the entity side alone.
  • The program-level ach_unauthorized_return_rate KRI is flagged as a breach, indicating the unauthorized-return issue may extend beyond this single alert.
  • Manual_review_aging_hours is also in breach, suggesting reviews are backing up, which supports surfacing this to a person rather than closing without review.
  • Evidence is limited to one transfer and one counterparty; there is no visibility into the counterparty's full transaction history within this alert, which lowers confidence in the exact scope of the pattern.

Evidence

{
  "n": 2070,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "2 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+403 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.