Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $1,054.86 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Northwind Payroll (simulated)
- Subject
- transfer acht_sim_nort_ahvf3f2z17y
- Transfer
- acht_sim_nort_ahvf3f2z17y · $1,054.86 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. A $1,054.86 outgoing ACH credit transfer (acht_sim_nort_ahvf3f2z17y) under the Northwind Payroll program was flagged by the skoor_review detector at a Transaction Risk Skoor of 40, placing it in the review band. The triggering signal is one prior unauthorized return associated with the counterparty (cpty_sim_nort_5a6oup6d8m), weighted at 40 points. The alert was routed to review because the detector is not auto-closable.
What the evidence shows. The transfer itself is SETTLED with return code none, meaning it completed without any return or dispute on this transaction. The skoor evidence shows a single contributing signal (returns.counterparty_prior_unauthorized) with a sample size of 387 and confidence 0.88; hard_signal is false. The receiving entity, Alder Co 012 (enti_sim_nort_co4ak19h24), is VERIFIED, not high risk, not PEP, has no open review reasons, and was screened recently (2026-06-29). Program-level KRIs show ach_unauthorized_return_rate at 0 (n=121) and ach_overall_return_rate at 1.65% (n=121), both within normal range, indicating no broader unauthorized-return pattern across the program. Counterparty concentration (top1) is 13.7%, within the ok range implied by other KRIs. Manual_review_aging_hours shows a breach (1434.7 hours, n=3), but this reflects program-wide review queue processing time, not evidence specific to this transfer or counterparty.
What was checked. Transfer status and return code, skoor signal detail and weight, entity verification status and screening date, program declared volume and rails, and program KRIs for unauthorized/overall/administrative ACH return rates, concentration, and review aging. Prior dispositions on this alert: none.
What is recommended. The transfer has already settled with no return and no dispute. The single signal driving the review band is a historical unauthorized return tied to the counterparty, not an outcome of this transaction, and program-wide unauthorized return metrics show no pattern. The receiving entity is verified and low risk. No funds are pending or held, so there is nothing to release or freeze. This alert can be closed without further action, though the counterparty's prior unauthorized return history may warrant continued monitoring on future transfers.
- Recommendation
- close
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:30Z
- Rationale
- Transfer status is SETTLED with return code none; no adverse outcome occurred on this specific transaction.
- The only signal (returns.counterparty_prior_unauthorized) reflects one historical event on the counterparty, not a current pattern; hard_signal is false.
- Entity is VERIFIED, not high risk, not PEP, screened within the last three months, with no open review reasons.
- Program KRIs ach_unauthorized_return_rate (0, n=121) and ach_overall_return_rate (1.65%, n=121) show no broader unauthorized-return pattern that would justify escalation.
- Manual_review_aging_hours breach is a program-level queue metric unrelated to this specific counterparty or transfer, so it does not change the disposition of this alert.
- No held funds exist on this transfer, so release is not applicable.
Evidence
{
"n": 387,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 0.88,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.