SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Entity velocity spiked: 1 transfers and $2,305.92 in 24 hours.

Detector
velocity_spike
Severity
medium
Program
Northwind Payroll (simulated)
Subject
entity enti_sim_nort_70vkcofa2z
Transfer
acht_sim_nort_bksf6jct62 · $1,201.71 · ach outgoing
Skoor at alert
null unscored
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. A ach outgoing credit transfer of $1201.71 (acht_sim_nort_bksf6jct62) on program Northwind Payroll (simulated) was flagged by detector velocity_spike: Entity velocity spiked: 1 transfers and $2,305.92 in 24 hours.. What the evidence shows. The transaction was unscored: too little history for a Skoor. Signals: counterparty.first_time (+10), velocity.sum_24h_gt_2x_daily_avg (+10). Entity Iris Services 020: verification VERIFIED, PEP no, high risk no. What was checked. No program KRI snapshot was available. No prior dispositions on this entity or counterparty. What is recommended. Recommended: escalate. A person decides; this draft was assembled from the evidence without a model (model call failed).
Recommendation
escalate
Confidence
null (template, no model)
Model
none (template)
Drafted
2026-09-17 19:30Z
Rationale
  • Template draft: recommendation follows the band and the hard-signal rule only.

Evidence

{
  "n": 0,
  "band": "unscored",
  "skoor": null,
  "signals": [
    {
      "code": "velocity.sum_24h_gt_2x_daily_avg",
      "detail": "24h sum above 2× the program daily average",
      "weight": 10
    }
  ],
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
counterparty.first_time+10first transfer with this counterparty
velocity.sum_24h_gt_2x_daily_avg+1024h sum above 2× the program daily average

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.