SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Transaction Risk Skoor 45 (hold band) on a $9,700.00 ach transfer: amount.gt_3x_median, structuring.pattern.

Detector
skoor_hold
Severity
high
Program
Northwind Payroll (simulated)
Subject
transfer acht_sb_9f64fcb36bd51819
Transfer
acht_sb_9f64fcb36bd51819 · $9,700.00 · ach outgoing
Skoor at alert
45 hold
Hard signal
yes
Policy
policy-v1
Opened
2026-09-17 23:15Z
Closed
Decision clock
standard · due 2026-09-18 23:15Z due 2026-09-18 23:15Z
Escalated

Draft narrative

What happened. An ACH outgoing debit of $9,700.00 from Northwind Payroll to counterparty cpty_sb_b275b92613f08df9 triggered the skoor_hold detector with a risk score of 45, placing it in the hold band. The transfer was auto-held and routed for review because a hard signal fired. What the evidence shows. Two signals contributed to the score: the amount is more than 3x the program median (weight 10), and the transfer matches a structuring pattern of 3 debits just under $10,000 within 24 hours (weight 35, hard signal). The structuring signal is marked hard, which is why the alert routed to review regardless of score. The transfer status is INITIATED with no return code recorded. The subject entity, Sandbox Structurer, is verified, not flagged high risk, not PEP, has no open review reasons, and was screened two days before the transfer (2026-09-15). What was checked. Entity verification status, PEP and high-risk flags, and screening recency were checked and show no independent concerns. Program KRIs were checked: frozen_accounts, overdraft_events, manual_review_rate, reserve_coverage_ratio, and return rates are all in the ok range. hold_aging_hours, pep_flagged_entities, and high_risk_entity_share are in watch status, and manual_review_aging_hours is in breach (1438 hours), indicating existing review backlog at the program level rather than something specific to this transfer. Prior dispositions on this subject: none. What is recommended. Hold the transfer pending manual review. The structuring pattern is a hard signal describing behavior (three sub-$10,000 debits in 24 hours) that requires a person to examine the related debits before this transfer is released or allowed to settle. The entity's own verification and screening data do not resolve the structuring concern, since that concern is about transaction pattern, not identity.
Recommendation
hold
Confidence
0.70
Model
claude-sonnet-5
Drafted
2026-09-17 23:15Z
Rationale
  • Structuring pattern signal is hard and drove auto-hold and routing to review; this requires human examination of the three related sub-$10,000 debits, which are not detailed in this context.
  • Amount exceeding 3x program median is corroborating but not independently disqualifying.
  • Entity verification, PEP, and screening status are clean, so no identity-level escalation is indicated by this alert alone.
  • Program-level KRI breach in manual_review_aging_hours suggests review capacity strain but is not specific evidence about this transfer.
  • No prior dispositions exist on this subject, so there is no established pattern across cases to justify escalation beyond this single alert.
  • Transfer status is INITIATED with no return code, consistent with funds not yet settled, so holding is operationally appropriate rather than releasing.

Evidence

{
  "n": 1480,
  "band": "hold",
  "skoor": 45,
  "signals": [
    {
      "code": "amount.gt_3x_median",
      "detail": "amount > 3× program median (190635)",
      "weight": 10
    },
    {
      "code": "structuring.pattern",
      "hard": true,
      "detail": "3 debits just under $10,000 in 24h",
      "weight": 35
    }
  ],
  "autoHold": true,
  "confidence": 0.745,
  "routeReason": "hard signal"
}

Skoor signals

SignalWeightHardDetail
amount.gt_3x_median+10amount > 3× program median (190635)
structuring.pattern+35yes3 debits just under $10,000 in 24h

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.