SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $3,472.73 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_867fmkn534n
Transfer
acht_sim_nort_867fmkn534n · $3,472.73 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 536ff290-1319-41e0-bf6e-fcae2dd942a4 was raised by the skoor_review detector on outgoing ACH transfer acht_sim_nort_867fmkn534n for $3,472.73, opened 2026-09-17T19:31:48.707Z. The transfer risk skoor was 40, placing it in the review band, driven by a single signal: one prior unauthorized return associated with the counterparty (weight 40). What the evidence shows. The transfer itself is SETTLED with no return code recorded, so no funds are currently held or reversible on this instance. The hard_signal flag is false and the model confidence is 1 (n=1188). The originating entity, Kestrel Partners 022, is VERIFIED, not high risk, not PEP, with no open review reasons and screening current as of 2026-09-02. Program-level KRIs show ach_unauthorized_return_rate at 0.0019 (ok) and ach_overall_return_rate at 0.0135 (ok), both well within normal range, and counterparty_concentration_top1 at 0.099 (ok). manual_review_aging_hours shows a breach (1434.7 hours, n=10), but this is a program-wide KRI and is not tied specifically to this transfer or counterparty. No prior dispositions exist for this alert. What was checked. Reviewed the alert evidence block, the transfer record (status, return code, amount, counterparty), the entity verification and risk profile, and the full set of program KRIs for corroborating signals of a broader unauthorized-return or fraud pattern. Checked whether the transfer was in a held state (it is not; it is SETTLED), which rules out a release recommendation. What is recommended. Close the alert. The single review-band signal reflects one historical unauthorized return on the counterparty, the transfer has already settled with no return code, the originating entity is verified and clean, and program-wide unauthorized/overall return rates remain low. The manual_review_aging_hours breach is a separate program-level condition and does not indicate this specific alert requires a hold or escalation; it should be tracked independently outside this disposition.
Recommendation
close
Confidence
0.68
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is SETTLED with return code none; there is no held transfer to act on, so hold/release do not apply.
  • The only signal driving the review band is one prior unauthorized return for the counterparty; hard_signal is false.
  • Entity is VERIFIED, not high risk, not PEP, no open review reasons, screening current.
  • Program KRIs ach_unauthorized_return_rate (0.0019) and ach_overall_return_rate (0.0135) are both in the ok range, showing no broader pattern.
  • manual_review_aging_hours is in breach at the program level (n=10) but is unrelated to this specific transfer or counterparty and should be handled as a separate operational item.
  • Confidence is moderate rather than high because counterparty country is listed as unknown and only one prior return event underlies the signal, limiting the evidence base.

Evidence

{
  "n": 1188,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.