SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $536.03 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Meridian Remit (simulated)
Subject
transfer acht_sim_meri_1lytfkhacce
Transfer
acht_sim_meri_1lytfkhacce · $536.03 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 61d05a03-8ca9-4505-a2f5-6f215a578139 was opened by the skoor_review detector on 2026-09-17 for an outgoing ACH transfer of $536.03 (acht_sim_meri_1lytfkhacce) under program Meridian Remit. The transfer risk score was 40, placing it in the review band, driven by a single signal: the counterparty has 2 prior unauthorized returns. The transfer itself settled with no return code. Hard signal is false. What the evidence shows. The score is based entirely on the counterparty's return history (returns.counterparty_prior_unauthorized, weight 40, confidence 1). This transfer did not itself return; status is SETTLED, return code none. The originating entity, Payout Agent (Meridian), is VERIFIED, not high risk, not PEP, last screened 2026-08-26, with no review reasons on file. The counterparty's country is unknown. At the program level, several KRIs are in breach: ach_unauthorized_return_rate (0.0118, n=425, breach), sanctioned_country_transfers (2, n=923, breach), reserve_coverage_ratio (0.48, n=425, breach), and manual_review_aging_hours (1146.9, n=3, breach). These are program-wide figures, not specific to this counterparty or transfer, but they indicate elevated unauthorized-return activity and sanctioned-country exposure are active concerns across the program at the same time this alert fired. What was checked. Transfer status and return code, entity verification and screening status, program declared volume and rails, transfer-level skoor and signal detail, and program KRI panel. No prior dispositions exist for this alert. Counterparty entity record beyond the return-history signal was not present in the evidence provided. What is recommended. This transfer has already settled, so there is no fund movement to hold or release. Given the counterparty's repeat unauthorized-return history combined with program-level breaches in unauthorized-return rate and sanctioned-country transfers occurring in the same period, this looks like it could be part of a broader pattern rather than an isolated review-band score. A person should review the counterparty's full transaction and return history across the program before this or related alerts are closed.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Score driver is counterparty prior unauthorized returns (2), weight 40, confidence 1 — a repeat-pattern signal, not a one-off.
  • Transfer itself settled with no return code, so no immediate funds-movement action applies; release/hold on this transfer is not applicable.
  • Originating entity is verified and low risk, which narrows concern to the counterparty side, whose country is unknown.
  • Program KRIs show concurrent breaches in ach_unauthorized_return_rate and sanctioned_country_transfers, suggesting the pattern may extend beyond this single alert.
  • Evidence on the counterparty itself (beyond return count) is thin — no entity verification status, no country confirmed — which limits certainty and caps confidence at moderate.

Evidence

{
  "n": 1053,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "2 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+402 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.