Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $3,136.65 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Northwind Payroll (simulated)
- Subject
- transfer acht_sim_nort_5bfcaieg365
- Transfer
- acht_sim_nort_5bfcaieg365 · $3,136.65 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 5bf515a5-c102-4c2c-acd7-01b1244fc546 flagged a $3,136.65 outgoing ACH credit (acht_sim_nort_5bfcaieg365) under the skoor_review detector at a Transaction Risk Skoor of 40 (review band), triggered by one signal: a prior unauthorized return associated with the counterparty (weight 40). The transfer has already settled with no return code recorded.
What the evidence shows. The transfer is SETTLED with return code none, meaning no unauthorized return occurred on this specific transaction. The single signal driving the score is a historical flag ('1 prior unauthorized return(s)') on counterparty cpty_sim_nort_25c8izfo4a, with no further detail on when that return occurred or its amount. Hard signal is false, and detector confidence is 1 on a population of 1,206. The subject entity, Larch Studio 023, is VERIFIED, not high risk, not PEP, has no review reasons, and was screened on 2026-09-02, ahead of this transfer's 2026-09-06 creation date. Program-level KRIs show ach_unauthorized_return_rate at 0.0019 (ok) and counterparty_concentration_top1 at 0.099 (ok), indicating no broader pattern of unauthorized-return activity tied to this counterparty or program. Separately, manual_review_aging_hours is in breach (1434.7 hours, n=10) and hold_aging_hours, pep_flagged_entities, and high_risk_entity_share are in watch status, but none of these KRIs reference this counterparty or this alert's signal.
What was checked. Reviewed the transfer status and return code, the entity's verification and screening status, the program's declared volume and KRIs, and prior dispositions on this alert (none on file). Checked whether the unauthorized-return signal corresponds to elevated program-wide unauthorized return activity; it does not (0.19% rate, ok band).
What is recommended. Close the alert. The transfer already settled without a return, the entity is verified with no risk flags, and program-level unauthorized-return metrics are within normal range. There is no pending transfer to hold or release. The manual_review_aging_hours breach and watch-status KRIs are program-level conditions unrelated to this specific counterparty signal and should be tracked separately, not through this alert.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer is SETTLED with return code none; no unauthorized return occurred on this transaction.
- Single driving signal is a historical prior unauthorized return with no detail on recency or amount, and hard_signal is false.
- Entity is VERIFIED, not high risk, not PEP, no review reasons, screened before this transfer.
- Program ach_unauthorized_return_rate (0.0019) and counterparty_concentration_top1 (0.099) are both in ok band, showing no broader pattern tied to this counterparty.
- Manual_review_aging_hours breach and other watch KRIs are program-wide and not specific to this alert's subject, so they do not support escalation of this particular alert.
- Confidence held at moderate because the underlying detail of the prior unauthorized return (date, amount, counterparty history depth) is not provided in evidence.
Evidence
{
"n": 1206,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.