SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $1,055.30 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_5ntz9y102dx
Transfer
acht_sim_nort_5ntz9y102dx · $1,055.30 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An outgoing ACH payroll credit of $1,055.30 from Northwind Payroll to counterparty cpty_sim_nort_25c8izfo4a was flagged by the skoor_review detector at a risk score of 40 (review band) due to one prior unauthorized return associated with this counterparty. The transfer itself settled with no return code. What the evidence shows. The transfer status is SETTLED with return code none, meaning this specific transaction completed without incident. The single signal driving the score, returns.counterparty_prior_unauthorized, reflects one historical unauthorized return by this counterparty, not a return on this transfer. The originating entity, Kestrel Partners 022, is VERIFIED, not high risk, not PEP, has no open review reasons, and was screened 2026-06-28. Program-level KRIs are mostly ok: ach_unauthorized_return_rate is 0 across 338 transfers, ach_overall_return_rate is 1.18%, sanctioned_country_transfers is 0, and verification_denial_rate is 3.03%. Two KRIs are in watch status (pep_flagged_entities=1/33, high_risk_entity_share=6.06%) but neither ties to this entity or transfer. manual_review_aging_hours is in breach (1434.7 hours, n=7), which reflects review backlog, not a signal specific to this alert. What was checked. Transfer status and return code, the triggering signal detail and weight, entity verification and screening status, prior dispositions (none on file), and program KRIs for related patterns in returns, sanctions exposure, and entity risk concentration. What is recommended. Because the transfer already settled cleanly with no return, and the flagged entity is verified with no other risk indicators, no funds are at risk from this alert and no hold or release action applies. The prior unauthorized return is a single historical event tied to the counterparty rather than this transfer or entity. Recommend closing the alert. Separately, the manual_review_aging_hours breach should be routed to operations as a backlog issue unrelated to this specific alert's disposition.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is SETTLED with return code none; the flagged transaction itself carries no return.
  • The only signal (weight 40) is a single prior unauthorized return by the counterparty, not a pattern (n=1 implied, no count of total counterparty transfers given).
  • Entity Kestrel Partners 022 is VERIFIED, not high risk, not PEP, no review reasons, screened within the last 3 months.
  • Program-level ach_unauthorized_return_rate is 0 across 338 transfers, showing no broader unauthorized-return pattern.
  • No prior dispositions exist on this alert or subject to suggest recurrence.
  • Confidence is moderate rather than high because the evidence does not show the counterparty's total transfer history or return count, only that one unauthorized return occurred at some point.

Evidence

{
  "n": 883,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.