SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 30 (review band) on a $233.39 ach transfer: returns.counterparty_prior_any, returns.entity_rate_gt_threshold.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_98ndmih9778
Transfer
acht_sim_harb_98ndmih9778 · $233.39 · ach outgoing
Skoor at alert
30 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 5195517e-3092-4114-a2d6-b179de4b3ffa fired on outgoing ACH credit acht_sim_harb_98ndmih9778 for $233.39, originated under the Harbor Marketplace Payouts program. The transfer skoor was 30 (review band, hard signal false), driven by two signals: one prior non-NSF return on the counterparty (weight 15) and an entity-level unauthorized ACH return rate above threshold, 1 of 27 originated debits in 60 days (weight 15). What the evidence shows. The transfer settled on 2026-08-19 with no return code, meaning this specific transfer was not itself returned. The counterparty has one prior return on record. The originating entity, Juniper LLC 19 (enti_sim_harb_yhmcztb3vc), is VERIFIED, not high risk, not PEP, with no open review reasons and last screened 2026-07-06. Program-level KRIs show ach_unauthorized_return_rate at 1.04% (n=479, flagged breach) and manual_review_aging_hours at 1438 hours (n=8, flagged breach); both are program-wide metrics, not specific to this transfer or entity. No prior dispositions exist for this alert. What was checked. Transfer status and return code, entity verification and screening status, program KRI panel, and prior disposition history. The transfer is settled with no return code attached, so there is no pending movement of funds to hold or release. What is recommended. Close the alert. The transfer has settled without a return, the entity is verified with no open risk flags, and the two signals driving the skoor (a single prior counterparty return and an entity return-rate threshold breach) are informational risk indicators rather than evidence of a problem with this specific transfer. The program-level KRI breaches (ach_unauthorized_return_rate, manual_review_aging_hours) warrant separate program-level monitoring but do not by themselves implicate this transfer or entity, and no prior dispositions link this entity to a broader pattern.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer status is SETTLED with return code none; no funds are pending or held, so release/hold do not apply.
  • Entity is VERIFIED, not high risk, not PEP, with no open review reasons, reducing concern about this specific counterparty.
  • Both alert signals are threshold-based risk indicators (prior return count, entity return rate) rather than direct evidence of an unauthorized or erroneous transaction on this transfer.
  • Program KRI breaches for ach_unauthorized_return_rate and manual_review_aging_hours are program-wide (n=479 and n=8 respectively) and not tied to this entity or transfer in the evidence provided, so they support monitoring rather than escalation of this single alert.
  • No prior dispositions exist for this alert or entity, so there is no established pattern history to justify escalation at this time.
  • Confidence is moderate because entity-level return history beyond the stated 1/27 rate and counterparty country are not fully detailed in the evidence.

Evidence

{
  "n": 1262,
  "band": "review",
  "skoor": 30,
  "signals": [
    {
      "code": "returns.counterparty_prior_any",
      "detail": "1 prior return(s) other than NSF",
      "weight": 15
    },
    {
      "code": "returns.entity_rate_gt_threshold",
      "detail": "entity unauthorized return rate 1/27 originated ACH debits in 60d",
      "weight": 15
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_any+151 prior return(s) other than NSF
returns.entity_rate_gt_threshold+15entity unauthorized return rate 1/27 originated ACH debits in 60d

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.