Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $3,472.73 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Northwind Payroll (simulated)
- Subject
- transfer acht_sim_nort_867fmkn534n
- Transfer
- acht_sim_nort_867fmkn534n · $3,472.73 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 536ff290-1319-41e0-bf6e-fcae2dd942a4 was raised by the skoor_review detector on outgoing ACH transfer acht_sim_nort_867fmkn534n for $3,472.73, opened 2026-09-17T19:31:48.707Z. The transfer risk skoor was 40, placing it in the review band, driven by a single signal: one prior unauthorized return associated with the counterparty (weight 40).
What the evidence shows. The transfer itself is SETTLED with no return code recorded, so no funds are currently held or reversible on this instance. The hard_signal flag is false and the model confidence is 1 (n=1188). The originating entity, Kestrel Partners 022, is VERIFIED, not high risk, not PEP, with no open review reasons and screening current as of 2026-09-02. Program-level KRIs show ach_unauthorized_return_rate at 0.0019 (ok) and ach_overall_return_rate at 0.0135 (ok), both well within normal range, and counterparty_concentration_top1 at 0.099 (ok). manual_review_aging_hours shows a breach (1434.7 hours, n=10), but this is a program-wide KRI and is not tied specifically to this transfer or counterparty. No prior dispositions exist for this alert.
What was checked. Reviewed the alert evidence block, the transfer record (status, return code, amount, counterparty), the entity verification and risk profile, and the full set of program KRIs for corroborating signals of a broader unauthorized-return or fraud pattern. Checked whether the transfer was in a held state (it is not; it is SETTLED), which rules out a release recommendation.
What is recommended. Close the alert. The single review-band signal reflects one historical unauthorized return on the counterparty, the transfer has already settled with no return code, the originating entity is verified and clean, and program-wide unauthorized/overall return rates remain low. The manual_review_aging_hours breach is a separate program-level condition and does not indicate this specific alert requires a hold or escalation; it should be tracked independently outside this disposition.
- Recommendation
- close
- Confidence
- 0.68
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is SETTLED with return code none; there is no held transfer to act on, so hold/release do not apply.
- The only signal driving the review band is one prior unauthorized return for the counterparty; hard_signal is false.
- Entity is VERIFIED, not high risk, not PEP, no open review reasons, screening current.
- Program KRIs ach_unauthorized_return_rate (0.0019) and ach_overall_return_rate (0.0135) are both in the ok range, showing no broader pattern.
- manual_review_aging_hours is in breach at the program level (n=10) but is unrelated to this specific transfer or counterparty and should be handled as a separate operational item.
- Confidence is moderate rather than high because counterparty country is listed as unknown and only one prior return event underlies the signal, limiting the evidence base.
Evidence
{
"n": 1188,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.