Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $536.03 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Meridian Remit (simulated)
- Subject
- transfer acht_sim_meri_1lytfkhacce
- Transfer
- acht_sim_meri_1lytfkhacce · $536.03 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 61d05a03-8ca9-4505-a2f5-6f215a578139 was opened by the skoor_review detector on 2026-09-17 for an outgoing ACH transfer of $536.03 (acht_sim_meri_1lytfkhacce) under program Meridian Remit. The transfer risk score was 40, placing it in the review band, driven by a single signal: the counterparty has 2 prior unauthorized returns. The transfer itself settled with no return code. Hard signal is false.
What the evidence shows. The score is based entirely on the counterparty's return history (returns.counterparty_prior_unauthorized, weight 40, confidence 1). This transfer did not itself return; status is SETTLED, return code none. The originating entity, Payout Agent (Meridian), is VERIFIED, not high risk, not PEP, last screened 2026-08-26, with no review reasons on file. The counterparty's country is unknown. At the program level, several KRIs are in breach: ach_unauthorized_return_rate (0.0118, n=425, breach), sanctioned_country_transfers (2, n=923, breach), reserve_coverage_ratio (0.48, n=425, breach), and manual_review_aging_hours (1146.9, n=3, breach). These are program-wide figures, not specific to this counterparty or transfer, but they indicate elevated unauthorized-return activity and sanctioned-country exposure are active concerns across the program at the same time this alert fired.
What was checked. Transfer status and return code, entity verification and screening status, program declared volume and rails, transfer-level skoor and signal detail, and program KRI panel. No prior dispositions exist for this alert. Counterparty entity record beyond the return-history signal was not present in the evidence provided.
What is recommended. This transfer has already settled, so there is no fund movement to hold or release. Given the counterparty's repeat unauthorized-return history combined with program-level breaches in unauthorized-return rate and sanctioned-country transfers occurring in the same period, this looks like it could be part of a broader pattern rather than an isolated review-band score. A person should review the counterparty's full transaction and return history across the program before this or related alerts are closed.
- Recommendation
- escalate
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Score driver is counterparty prior unauthorized returns (2), weight 40, confidence 1 — a repeat-pattern signal, not a one-off.
- Transfer itself settled with no return code, so no immediate funds-movement action applies; release/hold on this transfer is not applicable.
- Originating entity is verified and low risk, which narrows concern to the counterparty side, whose country is unknown.
- Program KRIs show concurrent breaches in ach_unauthorized_return_rate and sanctioned_country_transfers, suggesting the pattern may extend beyond this single alert.
- Evidence on the counterparty itself (beyond return count) is thin — no entity verification status, no country confirmed — which limits certainty and caps confidence at moderate.
Evidence
{
"n": 1053,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "2 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 2 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.