SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Counterparty Receiver 20 entered the hold band (Skoor 90, n=14): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.review_share, counterparty.new.

Detector
counterparty_hold
Severity
high
Program
Meridian Remit (simulated)
Subject
counterparty cpty_sim_meri_bts0zmjm9td
Transfer
Skoor at alert
90 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Counterparty cpty_sim_meri_bts0zmjm9td entered the hold band under detector counterparty_hold with a Skoor of 90 (band: hold, n=14). The alert was opened 2026-09-17T19:31:26.178Z and routed to review because the detector is not auto-closable. What the evidence shows. Of 14 observed transactions, 2 were unauthorized returns, driving an unauthorized rate and return rate of 2/14, both flagged as above the network threshold (weights 40 and 15). 58% of this counterparty's activity falls in the review band (weight 10), and the counterparty is new, first seen 0 days ago (weight 10). The detector's own confidence in this composite score is low (0.296) and hard_signal is false, meaning no single deterministic signal drove the hold; the score is built from a small sample (n=14). autoHold is true, indicating the system has already placed a hold on this counterparty pending review. What was checked. Program-level KRIs for Meridian Remit (simulated) show reserve_coverage_ratio in breach (0.896, n=249), manual_review_aging_hours in breach (1146.9 hours, n=2), and ach_unauthorized_return_rate in breach (0.008, n=249), alongside watch-level hold_aging_hours (1364.96 hours, n=4) and pep_flagged_entities (1 of 30). No prior dispositions exist for this alert or counterparty. These program breaches are not directly tied to this specific counterparty in the evidence provided; they describe the program as a whole, not a confirmed link to cpty_sim_meri_bts0zmjm9td. What is recommended. This is a new counterparty with a small transaction sample (n=14) that has already drawn 2 unauthorized returns, and the detector has placed an automatic hold. The sample size is thin and detector confidence is low, so no unilateral pattern determination beyond this alert can be made from the evidence given. A person should review the underlying transactions and returns before any funds move. Given the program-level breaches in reserve coverage, manual review aging, and unauthorized return rate, the reviewer may also want to check whether this counterparty is a contributor to those program metrics, but that connection is not established in the evidence provided and does not on its own justify escalation.
Recommendation
hold
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • autoHold is true and route is reviewed, indicating funds/activity tied to this counterparty are already held pending human review.
  • 2 of 14 transactions were unauthorized returns, a rate the detector flags as above the network threshold; this is a substantive finding even though the sample is small.
  • Detector confidence is low (0.296) and hard_signal is false, so the composite score alone should not drive a close decision without human review.
  • Counterparty is new (0 days), which increases the value of manual review before further activity is authorized.
  • Program KRI breaches (reserve_coverage_ratio, manual_review_aging_hours, ach_unauthorized_return_rate) are noted for context but are not evidenced as directly caused by or connected to this specific counterparty, so escalation to a program-wide pattern is not supported by this alert alone.
  • No prior dispositions exist, so this is a first review with no history to indicate the hold is stale or resolved.

Evidence

{
  "n": 14,
  "band": "hold",
  "skoor": 90,
  "signals": [
    {
      "code": "counterparty.unauthorized_returns",
      "detail": "drew 2 unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "counterparty.unauthorized_rate",
      "detail": "unauthorized rate 2/14 above the network threshold",
      "weight": 15
    },
    {
      "code": "counterparty.return_rate",
      "detail": "return rate 2/14",
      "weight": 15
    },
    {
      "code": "counterparty.review_share",
      "detail": "58% in the review band",
      "weight": 10
    },
    {
      "code": "counterparty.new",
      "detail": "first seen 0d ago",
      "weight": 10
    }
  ],
  "version": "crs-v1",
  "autoHold": true,
  "confidence": 0.296,
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.