SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

The entity's first transfer, $2,943.37, above the program median, came 0.0 hours after verification.

Detector
rapid_onboarding
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_2s8mc65w4m
Transfer
acht_sim_nort_2s8mc65w4m · $2,943.37 · ach outgoing
Skoor at alert
null unscored
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. A rapid_onboarding alert fired on the entity's first transfer (acht_sim_nort_2s8mc65w4m), a $2,943.37 outgoing ACH debit that posted 0.0 hours after verification, above the program median of $1,471.75 (147175 cents). The detector routed to review because it is not auto-closable; severity is medium and the transfer risk band is unscored (skoor null, n=1). What the evidence shows. The transfer status is COMPLETED with no return code, so funds have already moved and there is no held position to act on. The entity (Reconciliation Agent, Northwind) is VERIFIED, not high risk, not PEP, has no review reasons, and was screened on 2026-08-25. The two triggered signals are counterparty.first_time and counterparty.first_time_and_large, both expected outcomes of a first transfer and not independently indicative of fraud. Counterparty country is unknown, which is a gap but not flagged as high-risk or sanctioned. Program-level KRIs are mostly in the ok/watch range (velocity_vs_declared 0.48, reserve_coverage_ratio 1.19, ach return rates under 1.5%); the one breach is manual_review_aging_hours (1434.7 hours, n=11), which is a program-wide backlog metric and not specific to this entity or transfer. What was checked. Transfer status and return code, entity verification and PEP/high-risk status, transfer-level skoor/band, program declared volume versus transfer amount, and program KRI panel for corroborating stress signals (sanctioned_country_transfers=0, pep_flagged_entities watch at 1/33, high_risk_entity_share watch at 6%). No prior dispositions exist for this alert or entity. What is recommended. Close the alert. The transfer is completed with no return, the entity is verified with no adverse history, and the triggered signals are inherent to any first-time transfer rather than evidence of risk. The unscored band and n=1 mean confidence in this assessment is limited, and a reviewer may want to confirm counterparty country before final sign-off, but nothing in the evidence requires holding funds (already settled) or points to a broader pattern warranting escalation.
Recommendation
close
Confidence
0.60
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is COMPLETED with no return code; funds have already settled, so hold/release are not applicable.
  • Entity is VERIFIED, not high risk, no PEP, no review reasons, screened within the last month.
  • Both triggered signals (first_time, first_time_and_large) are structural to any new entity's first transfer, not standalone fraud indicators.
  • Program KRIs show no sanctioned-country exposure and return rates well within normal range; the one breach (manual_review_aging_hours) is a program backlog metric unrelated to this specific alert.
  • Evidence is thin: transfer risk band is unscored with n=1 and skoor null, and counterparty country is unknown, which limits confidence and should be noted for the record.

Evidence

{
  "n": 1,
  "band": "unscored",
  "skoor": null,
  "typology": "rapid_onboarding",
  "confidence": null,
  "thresholds": {
    "hours": 24
  },
  "medianCents": "147175",
  "routeReason": "detector not auto-closable",
  "hoursSinceVerification": 0
}

Skoor signals

SignalWeightHardDetail
counterparty.first_time+10first transfer with this counterparty
counterparty.first_time_and_large+15amount above the program p95 (147175)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.