SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $214.37 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_31maepxd6pt
Transfer
acht_sim_harb_31maepxd6pt · $214.37 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An outgoing ACH transfer of $214.37 from program Harbor Marketplace Payouts was returned under code R29. The transfer triggered a Transaction Risk Skoor of 40 (review band, hard signal false) due to a single signal: the counterparty has 2 prior unauthorized returns. What the evidence shows. The transfer status is RETURNED, so no funds are currently held or in transit for this alert. The originating entity, Fern Studio 15, is verified, not high risk, not PEP, and was screened as recently as 2026-09-05. The counterparty's country is unknown and it has a documented history of 2 prior unauthorized returns, now a 3rd occurrence (R29) tied to this transfer. Program-level KRIs show ach_unauthorized_return_rate in breach (0.0085 against n=709) and manual_review_aging_hours in breach (1438 hours, n=11), alongside watch-level readings on hold_aging_hours, pep_flagged_entities, and high_risk_entity_share. Other program metrics (overall return rate, administrative return rate, reserve coverage, velocity vs declared) are within normal range. What was checked. Transfer status and return code, entity verification and risk flags, program KRI panel, and prior dispositions (none on file). No indication in the evidence of a hold currently in place on this or related transfers. What is recommended. Because there is no held transfer to release and no funds currently at risk in this specific alert, hold and release do not apply. The repeat unauthorized-return pattern on this specific counterparty (3 occurrences) combined with the program-wide breach on ach_unauthorized_return_rate suggests this alert is not isolated and may reflect a broader counterparty or program-level issue that a single-alert closure would miss. This warrants escalation for a person to review the counterparty's transfer history and the program's unauthorized-return trend together, rather than closing this alert on its own.
Recommendation
escalate
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is RETURNED; no funds are pending, so hold/release do not apply.
  • Counterparty has 2 prior unauthorized returns and this transfer, returned R29, is a 3rd instance of the same category, indicating a recurring counterparty-level pattern rather than a one-off.
  • Program KRI ach_unauthorized_return_rate is flagged breach (0.0085, n=709), consistent with a signal that this is not isolated to one transfer.
  • Manual_review_aging_hours is also in breach, suggesting review capacity strain that could delay pattern detection if not escalated.
  • Originating entity itself (Fern Studio 15) shows no risk flags, verified status, and recent screening, so the concern centers on the counterparty, not the originator.
  • Evidence on the counterparty is thin (country unknown, no further detail on the 2 prior returns), which limits certainty and lowers confidence in a specific root cause, but does not remove the case for escalation given the pattern and KRI breach.

Evidence

{
  "n": 1094,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "2 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+403 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.