Alert · reviewed · open
Transaction Risk Skoor 55 (review band) on a $670.63 ach transfer: returns.counterparty_prior_unauthorized, geo.outside_declared_countries.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_zgwfavk9gm
- Transfer
- acht_sim_harb_zgwfavk9gm · $670.63 · ach outgoing
- Skoor at alert
- 55 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 4bb0bc17-f620-479a-b1e2-49e32977f743 fired on outgoing ACH credit acht_sim_harb_zgwfavk9gm for $670.63, flagged by the skoor_review detector at a Transaction Risk Skoor of 55 (review band). The transfer settled on 2026-09-16 with no return code.
What the evidence shows. Two signals drove the score: returns.counterparty_prior_unauthorized (weight 40, detail: 5 prior unauthorized return(s) on this counterparty) and geo.outside_declared_countries (weight 15, counterparty country TR, program Harbor Marketplace Payouts declares only US). The originating entity, Payout Agent (Harbor), is VERIFIED, not high risk, no PEP flags, last screened 2026-09-02. Program-level KRIs show ach_unauthorized_return_rate at 0.0091 (n=877) flagged breach, and manual_review_aging_hours at 1438 hours flagged breach; other KRIs (frozen_accounts, verification_denial_rate, sanctioned_country_transfers, counterparty_concentration_top1) are within ok range.
What was checked. Alert evidence, transfer record, program declared countries and volume, entity verification status, and program KRI panel. No prior dispositions exist for this alert. The transfer status is SETTLED, so there are no funds currently held against this transaction.
What is recommended. The transfer itself cannot be held or released since it has already settled. However, the counterparty has 5 prior unauthorized returns and operates outside the program's declared countries, and the program's ach_unauthorized_return_rate KRI is independently in breach. This combination points to a counterparty-level pattern rather than an isolated transaction issue. A person should review the counterparty relationship (cpty_sim_harb_7nn77rms57g) and the program's declared-country scope, rather than closing this as a one-off.
- Recommendation
- escalate
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer acht_sim_harb_zgwfavk9gm is SETTLED with no return code, so hold/release do not apply to this transaction.
- Counterparty signal shows 5 prior unauthorized returns (weight 40 of the 55 score), which is a repeat pattern, not a single-instance flag.
- Counterparty country TR is outside the program's sole declared country (US), an unresolved scope mismatch.
- Program KRI ach_unauthorized_return_rate is flagged breach (0.0091, n=877), corroborating a pattern beyond this single alert.
- Originating entity is verified and not high risk, which limits scope to the counterparty side rather than the payout agent.
- Confidence is moderate because the entity file is clean and evidence for the counterparty's return history is a count only, without transaction-level detail on those 5 priors.
Evidence
{
"n": 2220,
"band": "review",
"skoor": 55,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "5 prior unauthorized return(s)",
"weight": 40
},
{
"code": "geo.outside_declared_countries",
"detail": "counterparty country TR not declared by the program",
"weight": 15
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 5 prior unauthorized return(s) | |
| geo.outside_declared_countries | +15 | counterparty country TR not declared by the program |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.