Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $766.95 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_283jcx2q6tm
- Transfer
- acht_sim_harb_283jcx2q6tm · $766.95 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 59db0d7a fired on outgoing ACH transfer acht_sim_harb_283jcx2q6tm for $766.95 to counterparty cpty_sim_harb_gzii64r41f under the Harbor Marketplace Payouts program. The detector skoor_review scored the transaction 40 (review band, hard_signal false) due to signal returns.counterparty_prior_unauthorized, noting 2 prior unauthorized returns for this counterparty. The transfer itself has status RETURNED with return code R07 (authorization revoked), created 2026-08-14.
What the evidence shows. The transfer already returned before this alert was reviewed; no funds are currently in motion or held. The sending entity, Heath Holdings 119, is VERIFIED, not high risk, not PEP, with no review reasons and screening current as of 2026-09-01. The risk signal attaches to the counterparty, which has 2 prior unauthorized returns and an unknown country. At the program level, ach_unauthorized_return_rate is flagged breach (0.00846 over n=709) and manual_review_aging_hours is also breach (1438 hours over n=11), while other KRIs (frozen_accounts, overdraft_events, sanctioned_country_transfers, verification_denial_rate) are ok. No prior dispositions exist for this alert.
What was checked. Transfer status and return code, entity verification and screening status, program KRI panel, and prior disposition history. Confirmed the transfer is already returned (not pending or held), so no funds are at risk of further movement from this specific transaction.
What is recommended. Because the underlying transfer has already returned and no funds are held or pending, there is nothing to hold or release on this transaction. However, the counterparty's repeat unauthorized-return history combined with a program-level breach in ach_unauthorized_return_rate indicates a pattern beyond this single alert that warrants review of the counterparty relationship and whether other transfers to cpty_sim_harb_gzii64r41f should be restricted going forward.
- Recommendation
- escalate
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is RETURNED (R07); no funds are currently movable or held, so close/hold/release on this transaction alone would not address the underlying risk.
- Signal returns.counterparty_prior_unauthorized indicates 2 prior unauthorized returns tied to the counterparty, not the sending entity, suggesting a recurring counterparty-level issue.
- Sending entity Heath Holdings 119 is verified, non-PEP, not high risk, with no review reasons, which limits concern about the originating party itself.
- Program KRI ach_unauthorized_return_rate is marked breach (0.00846, n=709), aligning with the alert's underlying concern and suggesting this is not an isolated case.
- manual_review_aging_hours is also in breach, indicating review backlogs that support escalation over closing without further look.
- No prior dispositions exist, so there is no established precedent to close this alert type without review.
Evidence
{
"n": 1123,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "2 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 4 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.