Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $334.76 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Meridian Remit (simulated)
- Subject
- transfer acht_sim_meri_7k4hczaqbqe
- Transfer
- acht_sim_meri_7k4hczaqbqe · $334.76 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 49f460af-c255-42b9-9020-ecad0077865f fired on ACH outgoing transfer acht_sim_meri_7k4hczaqbqe for $334.76, opened 2026-09-17T19:31:39.396Z under the skoor_review detector at severity medium. The transfer risk score was 40, placing it in the review band, driven by a single signal: one prior unauthorized return associated with the counterparty (weight 40, confidence 1).
What the evidence shows. The transfer itself settled with no return code recorded, meaning this specific transaction was not returned. The counterparty cpty_sim_meri_6hloyf56aa7 has a documented history of one prior unauthorized return, which is the sole basis for the score. The originating entity, Elm Partners 216, is a verified business, not high risk, not PEP, with no open review reasons and screening current as of 2026-07-06. At the program level (Meridian Remit), three KRIs are in breach: reserve_coverage_ratio (0.737, n=307), manual_review_aging_hours (1146.86, n=2), and ach_unauthorized_return_rate (0.0130, n=307). Two additional KRIs are at watch: hold_aging_hours and pep_flagged_entities. No prior dispositions exist for this alert.
What was checked. Reviewed the transfer record, the single risk signal driving the score, the counterparty's return history as described, the originating entity's verification and screening status, and the program-level KRI panel for corroborating patterns. No other signals, hard-signal flags, or sanctioned-country indicators were present on this transfer.
What is recommended. The transfer has already settled, so no funds are being held and release does not apply here. The alert's own evidence is limited to one prior counterparty return with no return on this transaction, which alone would not require holding funds. However, the program-level breaches in ach_unauthorized_return_rate, reserve_coverage_ratio, and manual_review_aging_hours, taken together with this counterparty's unauthorized-return history, indicate a pattern at the program level that exceeds the scope of this single alert. A person should review whether this counterparty and similar review-band alerts are contributing to the program's unauthorized-return and reserve-coverage breaches before this and related alerts are closed.
- Recommendation
- escalate
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer acht_sim_meri_7k4hczaqbqe settled with no return code; the review score rests entirely on the counterparty's single prior unauthorized return.
- Originating entity is verified, not high risk, not PEP, with current screening, which narrows the concern to the counterparty side.
- Program KRIs show three breaches (reserve_coverage_ratio, manual_review_aging_hours, ach_unauthorized_return_rate) and two watch conditions (hold_aging_hours, pep_flagged_entities), suggesting this alert may be part of a broader program-level pattern rather than an isolated event.
- No prior dispositions exist to indicate this counterparty or pattern has already been reviewed.
- Because the transfer already settled, hold and release do not apply; escalation is the appropriate path to have a person assess the broader pattern before similar alerts are closed.
Evidence
{
"n": 802,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 2 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.