SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $750.43 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Meridian Remit (simulated)
Subject
transfer acht_sim_meri_2qpydu5hccb
Transfer
acht_sim_meri_2qpydu5hccb · $750.43 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. A medium-severity skoor_review alert fired on a settled outgoing ACH credit of $750.43 from program Meridian Remit, counterparty cpty_sim_meri_3mv7euw3b1k. The single signal is returns.counterparty_prior_unauthorized, weight 40, based on 1 prior unauthorized return by this counterparty. The transfer itself settled with no return code. What the evidence shows. The transfer skoor is 40, review band, confidence 1, driven entirely by the one prior-unauthorized-return signal on the counterparty; this transfer itself shows no return code and status SETTLED, so it did not itself bounce. The originating entity, Meridian Remit, is VERIFIED, not high risk, no PEP flag, and was last screened 2026-07-29. Program-level KRIs show several breaches that are not specific to this transfer: reserve_coverage_ratio 0.466 (breach), manual_review_aging_hours 1146.9 (breach, n=3), ach_unauthorized_return_rate 0.0113 (breach, n=442), and sanctioned_country_transfers=2 (breach, n=971). hold_aging_hours and pep_flagged_entities are flagged watch. There are no prior dispositions on this alert. What was checked. Alert evidence, transfer record, program KRI snapshot, entity verification record, and prior disposition history. No other transfers or entities were provided in this context, so no cross-transfer counterparty pattern beyond the single cited prior unauthorized return can be confirmed from this record alone. What is recommended. This specific transfer is settled and shows no return; there is no fund movement to hold. However, the program carries concurrent KRI breaches in unauthorized return rate, reserve coverage, manual review aging, and sanctioned-country transfers, which together indicate a pattern broader than this single alert. This should be escalated for a person to review the program-level breach cluster alongside this counterparty's prior unauthorized return, rather than closed as an isolated event.
Recommendation
escalate
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer is SETTLED with no return code, so no hold or release action applies to this transfer.
  • The alert's sole basis is one prior unauthorized return by the counterparty, which is a real but single-instance signal at review band (skoor 40).
  • Program KRIs independently show multiple breaches (reserve_coverage_ratio, ach_unauthorized_return_rate, manual_review_aging_hours, sanctioned_country_transfers) concurrent with this alert, suggesting a program-level pattern that exceeds the scope of this single transfer alert.
  • Entity is verified, not high risk, no PEP, recently screened, which weighs against closing this as a standalone low-risk event given the surrounding breach signals.
  • Context does not include other transfers tied to this same counterparty, so the full extent of the pattern cannot be confirmed here, lowering confidence and supporting escalation for a person to pull that data.

Evidence

{
  "n": 1064,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.