SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $766.95 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_283jcx2q6tm
Transfer
acht_sim_harb_283jcx2q6tm · $766.95 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 59db0d7a fired on outgoing ACH transfer acht_sim_harb_283jcx2q6tm for $766.95 to counterparty cpty_sim_harb_gzii64r41f under the Harbor Marketplace Payouts program. The detector skoor_review scored the transaction 40 (review band, hard_signal false) due to signal returns.counterparty_prior_unauthorized, noting 2 prior unauthorized returns for this counterparty. The transfer itself has status RETURNED with return code R07 (authorization revoked), created 2026-08-14. What the evidence shows. The transfer already returned before this alert was reviewed; no funds are currently in motion or held. The sending entity, Heath Holdings 119, is VERIFIED, not high risk, not PEP, with no review reasons and screening current as of 2026-09-01. The risk signal attaches to the counterparty, which has 2 prior unauthorized returns and an unknown country. At the program level, ach_unauthorized_return_rate is flagged breach (0.00846 over n=709) and manual_review_aging_hours is also breach (1438 hours over n=11), while other KRIs (frozen_accounts, overdraft_events, sanctioned_country_transfers, verification_denial_rate) are ok. No prior dispositions exist for this alert. What was checked. Transfer status and return code, entity verification and screening status, program KRI panel, and prior disposition history. Confirmed the transfer is already returned (not pending or held), so no funds are at risk of further movement from this specific transaction. What is recommended. Because the underlying transfer has already returned and no funds are held or pending, there is nothing to hold or release on this transaction. However, the counterparty's repeat unauthorized-return history combined with a program-level breach in ach_unauthorized_return_rate indicates a pattern beyond this single alert that warrants review of the counterparty relationship and whether other transfers to cpty_sim_harb_gzii64r41f should be restricted going forward.
Recommendation
escalate
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is RETURNED (R07); no funds are currently movable or held, so close/hold/release on this transaction alone would not address the underlying risk.
  • Signal returns.counterparty_prior_unauthorized indicates 2 prior unauthorized returns tied to the counterparty, not the sending entity, suggesting a recurring counterparty-level issue.
  • Sending entity Heath Holdings 119 is verified, non-PEP, not high risk, with no review reasons, which limits concern about the originating party itself.
  • Program KRI ach_unauthorized_return_rate is marked breach (0.00846, n=709), aligning with the alert's underlying concern and suggesting this is not an isolated case.
  • manual_review_aging_hours is also in breach, indicating review backlogs that support escalation over closing without further look.
  • No prior dispositions exist, so there is no established precedent to close this alert type without review.

Evidence

{
  "n": 1123,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "2 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+404 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.