SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $202.24 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_9rir1wnf8wt
Transfer
acht_sim_harb_9rir1wnf8wt · $202.24 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An ACH outgoing credit transfer of $202.24 from program Harbor Marketplace Payouts to counterparty cpty_sim_harb_39i9ftby3xi was flagged by the skoor_review detector at a Transaction Risk Skoor of 40 (review band). The triggering signal is returns.counterparty_prior_unauthorized, noting 2 prior unauthorized returns tied to this counterparty, weighted at +40 of the total skoor. What the evidence shows. The transfer itself settled with return code none, so no return occurred on this transaction. The originating entity, Fern Studio 15, is VERIFIED, not high risk, not PEP, has no review reasons, and was screened recently (2026-09-05). Velocity vs declared volume is normal (0.106), and program-level indicators are mostly ok or watch, except two flagged as breach: manual_review_aging_hours (1438.05 hours) and ach_unauthorized_return_rate (0.00757). The latter is the same risk category as the alert's triggering signal (unauthorized returns), which ties this individual alert to a program-level metric currently in breach status. What was checked. Transfer status and return code, entity verification and screening recency, program KRIs across return rates, aging, concentration, and risk-share metrics, and prior dispositions for this alert (none exist). What is recommended. Given the transfer already settled with no return and the entity shows no independent risk findings, this specific transaction does not need funds action. However, the ach_unauthorized_return_rate KRI is in breach and matches the alert's own triggering signal category, and manual_review_aging_hours is also in breach. This combination suggests the counterparty-level unauthorized-return pattern may extend beyond this single alert at the program level. This should be escalated for a person to review whether other alerts or transfers share the same counterparty or pattern before closing.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is SETTLED with return code none, so no hold or release action applies to this transaction.
  • Entity verification, screening recency, and PEP/high-risk flags show no additional concerns at the entity level.
  • The triggering signal (counterparty_prior_unauthorized) matches the category of a program KRI currently in breach (ach_unauthorized_return_rate), suggesting a possible pattern beyond this single alert.
  • manual_review_aging_hours is also in breach, indicating review backlogs that may affect timely handling of related alerts.
  • Evidence for this single transfer is otherwise clean, so confidence in the escalate call is moderate rather than high; a person should confirm whether other transfers to this counterparty show the same signal.

Evidence

{
  "n": 2010,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "2 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+403 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.