SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $847.57 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_4mdmdoi639e
Transfer
acht_sim_nort_4mdmdoi639e · $847.57 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 53f7c3ac-900c-41a2-acfa-8575208bdbf0 fired on transfer acht_sim_nort_4mdmdoi639e, an outgoing ACH credit of $847.57 under program Northwind Payroll. The detector (skoor_review) scored the transfer 40, placing it in the review band, driven by a single signal: the counterparty has 1 prior unauthorized return. What the evidence shows. The transfer itself settled with return code none, so no return occurred on this transaction. The counterparty's history shows one prior unauthorized return, which is the sole basis for the score (weight 40, n=1256, confidence 1). The associated entity, Kestrel Partners 010, is VERIFIED, not high risk, not PEP, has no open review reasons, and was screened on 2026-09-09, eight days before the alert opened. Counterparty country is listed as unknown, which is a gap in the record but not flagged as a risk signal by the detector. Program-level KRIs are mostly in the 'ok' range: ach_unauthorized_return_rate is 0.18%, ach_overall_return_rate is 1.27%, sanctioned_country_transfers is 0, and reserve_coverage_ratio is 1.29. Three KRIs sit at 'watch' (hold_aging_hours, pep_flagged_entities, high_risk_entity_share) and one at 'breach' (manual_review_aging_hours, 1434.7 hours, n=10), but none of these are tied to this specific transfer or entity, and this entity is not among the pep or high-risk counts. What was checked. Transfer status and return code, entity verification and screening status, program declared volume and rails, and program-level KRI panel for corroborating patterns. There are no prior dispositions on file for this alert or subject. What is recommended. The transfer has already settled with no return recorded, so there are no funds to hold and release does not apply. The single risk signal is a historical prior unauthorized return on the counterparty, not a current unauthorized return, and the receiving entity is verified with no other review flags. The program-level breach in manual_review_aging_hours is a separate operational metric affecting review queue timing generally, not evidence of a pattern specific to this counterparty or entity. Nothing in the record requires a person to act on this specific transfer. Recommend closing the alert. A person should separately track the manual_review_aging_hours breach as a program-level operational item outside this alert.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer settled with return code none; no current unauthorized return occurred.
  • Single signal (prior unauthorized return, weight 40) is historical, not tied to this transaction's outcome.
  • Entity is VERIFIED, not high risk, not PEP, no open review reasons, screened 8 days before alert.
  • Program KRIs for unauthorized/overall return rates and sanctioned transfers are in the ok range, showing no broader pattern tied to this alert.
  • Counterparty country listed as unknown, a data gap that slightly lowers confidence but is not itself a flagged signal.
  • Manual_review_aging_hours breach is a program-level KRI unrelated to this specific transfer or entity and does not on its own justify escalation of this alert.

Evidence

{
  "n": 1256,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.