SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $334.76 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Meridian Remit (simulated)
Subject
transfer acht_sim_meri_7k4hczaqbqe
Transfer
acht_sim_meri_7k4hczaqbqe · $334.76 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 49f460af-c255-42b9-9020-ecad0077865f fired on ACH outgoing transfer acht_sim_meri_7k4hczaqbqe for $334.76, opened 2026-09-17T19:31:39.396Z under the skoor_review detector at severity medium. The transfer risk score was 40, placing it in the review band, driven by a single signal: one prior unauthorized return associated with the counterparty (weight 40, confidence 1). What the evidence shows. The transfer itself settled with no return code recorded, meaning this specific transaction was not returned. The counterparty cpty_sim_meri_6hloyf56aa7 has a documented history of one prior unauthorized return, which is the sole basis for the score. The originating entity, Elm Partners 216, is a verified business, not high risk, not PEP, with no open review reasons and screening current as of 2026-07-06. At the program level (Meridian Remit), three KRIs are in breach: reserve_coverage_ratio (0.737, n=307), manual_review_aging_hours (1146.86, n=2), and ach_unauthorized_return_rate (0.0130, n=307). Two additional KRIs are at watch: hold_aging_hours and pep_flagged_entities. No prior dispositions exist for this alert. What was checked. Reviewed the transfer record, the single risk signal driving the score, the counterparty's return history as described, the originating entity's verification and screening status, and the program-level KRI panel for corroborating patterns. No other signals, hard-signal flags, or sanctioned-country indicators were present on this transfer. What is recommended. The transfer has already settled, so no funds are being held and release does not apply here. The alert's own evidence is limited to one prior counterparty return with no return on this transaction, which alone would not require holding funds. However, the program-level breaches in ach_unauthorized_return_rate, reserve_coverage_ratio, and manual_review_aging_hours, taken together with this counterparty's unauthorized-return history, indicate a pattern at the program level that exceeds the scope of this single alert. A person should review whether this counterparty and similar review-band alerts are contributing to the program's unauthorized-return and reserve-coverage breaches before this and related alerts are closed.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer acht_sim_meri_7k4hczaqbqe settled with no return code; the review score rests entirely on the counterparty's single prior unauthorized return.
  • Originating entity is verified, not high risk, not PEP, with current screening, which narrows the concern to the counterparty side.
  • Program KRIs show three breaches (reserve_coverage_ratio, manual_review_aging_hours, ach_unauthorized_return_rate) and two watch conditions (hold_aging_hours, pep_flagged_entities), suggesting this alert may be part of a broader program-level pattern rather than an isolated event.
  • No prior dispositions exist to indicate this counterparty or pattern has already been reviewed.
  • Because the transfer already settled, hold and release do not apply; escalation is the appropriate path to have a person assess the broader pattern before similar alerts are closed.

Evidence

{
  "n": 802,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+402 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.