Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $1,706.86 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Northwind Payroll (simulated)
- Subject
- transfer acht_sim_nort_4d4po26v3ig
- Transfer
- acht_sim_nort_4d4po26v3ig · $1,706.86 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 6d024b8b-57f5-413a-b131-5c2d2eefb86a fired on transfer acht_sim_nort_4d4po26v3ig, an outgoing ACH credit of $1,706.86 under program Northwind Payroll, opened 2026-09-17T19:32:09.678Z. The detector skoor_review scored the transfer 40 (review band) based on one signal: returns.counterparty_prior_unauthorized, reflecting one prior unauthorized return associated with counterparty cpty_sim_nort_2vu2cgc34a.
What the evidence shows. The transfer itself is SETTLED with return code none, meaning it completed without an unauthorized or administrative return. The single contributing signal carries the full skoor weight of 40 and is drawn from n=1356 with confidence 1, but it reflects a prior return history on the counterparty, not an issue with this transaction. The associated entity, Larch Studio 011, is VERIFIED, not high risk, not PEP, has no open review reasons, and was screened as recently as 2026-08-14. Program-level KRIs show ach_unauthorized_return_rate at 0.17% (ok) and ach_overall_return_rate at 1.34% (ok), both within normal range, indicating no broader unauthorized-return pattern at the program level. manual_review_aging_hours is in breach (1434.7 hours, n=11) and hold_aging_hours is at watch (518.3 hours, n=1), but these are program-wide queue metrics, not specific to this transfer, and no prior dispositions exist on this alert.
What was checked. Reviewed the alert evidence block, the transfer record (status, return code, amount, dates), the linked entity's verification and risk flags, and the program KRI panel for corroborating patterns. Confirmed no prior dispositions exist for this alert. Confirmed the transfer is settled, not held, so no funds-movement decision is pending.
What is recommended. Close the alert. The transfer settled cleanly with no return, the entity is verified with no open risk flags, and program-level return-rate KRIs are within normal bounds. The single signal driving the score is historical counterparty information, not evidence of a problem with this transaction. Separately, the manual_review_aging_hours breach (1434.7 hours) warrants attention by the queue owner, but it is a program-wide condition and not a basis to hold or escalate this specific settled transfer.
- Recommendation
- close
- Confidence
- 0.68
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is SETTLED with return code none, so there is no unauthorized return on this specific transaction.
- Only one signal drove the score: a prior unauthorized return on the counterparty, which is historical context rather than current-transaction evidence.
- Entity is VERIFIED, not high risk, not PEP, no open review reasons, screened within the last five weeks.
- Program KRIs for unauthorized and overall ACH return rates are both in the 'ok' band, showing no wider pattern tied to this program or counterparty type.
- manual_review_aging_hours is in breach and hold_aging_hours is at watch, but these are aggregate program metrics (n=11 and n=1) not specific to this alert, so they inform operational follow-up rather than this disposition.
- No prior dispositions exist on this alert, and since the transfer already settled, 'hold' or 'release' do not apply.
Evidence
{
"n": 1356,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.