Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $1,138.15 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Northwind Payroll (simulated)
- Subject
- transfer acht_sim_nort_c76h9vcx1zt
- Transfer
- acht_sim_nort_c76h9vcx1zt · $1,138.15 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An ACH outgoing debit transfer of $1,138.15 from acht_sim_nort_c76h9vcx1zt was flagged by the skoor_review detector at a Transaction Risk Skoor of 40 (review band) due to a single signal: the counterparty has one prior unauthorized ACH return on record. The transfer itself settled with no return code.
What the evidence shows. The only signal driving the score is returns.counterparty_prior_unauthorized, weighted 40, based on one prior unauthorized return for this counterparty (n=721 population baseline, confidence 0.91). The transfer under review settled with return code none, so no unauthorized return occurred on this specific transaction. The originating entity, Birch Holdings 01, is VERIFIED, not high risk, not PEP, and was screened as recently as 2026-06-23. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=274) and ach_overall_return_rate at 0.73% (n=274), both in the ok range, indicating no broader pattern of unauthorized returns across the program. manual_review_aging_hours shows a breach (1434.67 hours, n=6), but this reflects program-wide review backlog, not a fact specific to this transfer or counterparty.
What was checked. Reviewed the transfer record (status, amount, rail, return code), the entity verification status and screening date, the program KRI panel for related patterns (unauthorized return rate, administrative return rate, sanctioned country transfers, high risk entity share), and prior dispositions on this alert, subject, and entity. No prior dispositions exist for this alert.
What is recommended. The transfer has already settled; there are no funds in a held state, so a hold or release action does not apply. The triggering signal is a single historical unauthorized return tied to the counterparty, and program-level unauthorized return metrics show no pattern beyond this one alert. Given the entity is verified, not high risk, and the transfer itself cleared without incident, this alert can be closed. If the counterparty accrues additional unauthorized returns, a future alert should escalate rather than close.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer status is SETTLED with return code none; no funds are held, so hold/release does not apply.
- The single triggering signal (1 prior unauthorized return) is the only basis for the review-band score; no additional signals are present in evidence.
- Program KRI ach_unauthorized_return_rate is 0 (n=274) and ach_overall_return_rate is 0.73% (n=274), showing no broader pattern tied to this counterparty or program.
- Entity Birch Holdings 01 is VERIFIED, not high risk, not PEP, with a recent screening date of 2026-06-23, reducing concern about the originating party.
- manual_review_aging_hours breach (1434.67 hours, n=6) is a program-level backlog metric, not evidence specific to this transfer, so it does not change the disposition of this alert.
- Counterparty country is listed as unknown, which is a gap in the evidence; this lowers confidence somewhat but does not by itself indicate a pattern requiring escalation given the other program metrics are in range.
Evidence
{
"n": 721,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 0.91,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.