SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 55 (review band) on a $670.63 ach transfer: returns.counterparty_prior_unauthorized, geo.outside_declared_countries.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_zgwfavk9gm
Transfer
acht_sim_harb_zgwfavk9gm · $670.63 · ach outgoing
Skoor at alert
55 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 4bb0bc17-f620-479a-b1e2-49e32977f743 fired on outgoing ACH credit acht_sim_harb_zgwfavk9gm for $670.63, flagged by the skoor_review detector at a Transaction Risk Skoor of 55 (review band). The transfer settled on 2026-09-16 with no return code. What the evidence shows. Two signals drove the score: returns.counterparty_prior_unauthorized (weight 40, detail: 5 prior unauthorized return(s) on this counterparty) and geo.outside_declared_countries (weight 15, counterparty country TR, program Harbor Marketplace Payouts declares only US). The originating entity, Payout Agent (Harbor), is VERIFIED, not high risk, no PEP flags, last screened 2026-09-02. Program-level KRIs show ach_unauthorized_return_rate at 0.0091 (n=877) flagged breach, and manual_review_aging_hours at 1438 hours flagged breach; other KRIs (frozen_accounts, verification_denial_rate, sanctioned_country_transfers, counterparty_concentration_top1) are within ok range. What was checked. Alert evidence, transfer record, program declared countries and volume, entity verification status, and program KRI panel. No prior dispositions exist for this alert. The transfer status is SETTLED, so there are no funds currently held against this transaction. What is recommended. The transfer itself cannot be held or released since it has already settled. However, the counterparty has 5 prior unauthorized returns and operates outside the program's declared countries, and the program's ach_unauthorized_return_rate KRI is independently in breach. This combination points to a counterparty-level pattern rather than an isolated transaction issue. A person should review the counterparty relationship (cpty_sim_harb_7nn77rms57g) and the program's declared-country scope, rather than closing this as a one-off.
Recommendation
escalate
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer acht_sim_harb_zgwfavk9gm is SETTLED with no return code, so hold/release do not apply to this transaction.
  • Counterparty signal shows 5 prior unauthorized returns (weight 40 of the 55 score), which is a repeat pattern, not a single-instance flag.
  • Counterparty country TR is outside the program's sole declared country (US), an unresolved scope mismatch.
  • Program KRI ach_unauthorized_return_rate is flagged breach (0.0091, n=877), corroborating a pattern beyond this single alert.
  • Originating entity is verified and not high risk, which limits scope to the counterparty side rather than the payout agent.
  • Confidence is moderate because the entity file is clean and evidence for the counterparty's return history is a count only, without transaction-level detail on those 5 priors.

Evidence

{
  "n": 2220,
  "band": "review",
  "skoor": 55,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "5 prior unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "geo.outside_declared_countries",
      "detail": "counterparty country TR not declared by the program",
      "weight": 15
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+405 prior unauthorized return(s)
geo.outside_declared_countries+15counterparty country TR not declared by the program

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.