Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $750.43 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Meridian Remit (simulated)
- Subject
- transfer acht_sim_meri_2qpydu5hccb
- Transfer
- acht_sim_meri_2qpydu5hccb · $750.43 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. A medium-severity skoor_review alert fired on a settled outgoing ACH credit of $750.43 from program Meridian Remit, counterparty cpty_sim_meri_3mv7euw3b1k. The single signal is returns.counterparty_prior_unauthorized, weight 40, based on 1 prior unauthorized return by this counterparty. The transfer itself settled with no return code.
What the evidence shows. The transfer skoor is 40, review band, confidence 1, driven entirely by the one prior-unauthorized-return signal on the counterparty; this transfer itself shows no return code and status SETTLED, so it did not itself bounce. The originating entity, Meridian Remit, is VERIFIED, not high risk, no PEP flag, and was last screened 2026-07-29. Program-level KRIs show several breaches that are not specific to this transfer: reserve_coverage_ratio 0.466 (breach), manual_review_aging_hours 1146.9 (breach, n=3), ach_unauthorized_return_rate 0.0113 (breach, n=442), and sanctioned_country_transfers=2 (breach, n=971). hold_aging_hours and pep_flagged_entities are flagged watch. There are no prior dispositions on this alert.
What was checked. Alert evidence, transfer record, program KRI snapshot, entity verification record, and prior disposition history. No other transfers or entities were provided in this context, so no cross-transfer counterparty pattern beyond the single cited prior unauthorized return can be confirmed from this record alone.
What is recommended. This specific transfer is settled and shows no return; there is no fund movement to hold. However, the program carries concurrent KRI breaches in unauthorized return rate, reserve coverage, manual review aging, and sanctioned-country transfers, which together indicate a pattern broader than this single alert. This should be escalated for a person to review the program-level breach cluster alongside this counterparty's prior unauthorized return, rather than closed as an isolated event.
- Recommendation
- escalate
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer is SETTLED with no return code, so no hold or release action applies to this transfer.
- The alert's sole basis is one prior unauthorized return by the counterparty, which is a real but single-instance signal at review band (skoor 40).
- Program KRIs independently show multiple breaches (reserve_coverage_ratio, ach_unauthorized_return_rate, manual_review_aging_hours, sanctioned_country_transfers) concurrent with this alert, suggesting a program-level pattern that exceeds the scope of this single transfer alert.
- Entity is verified, not high risk, no PEP, recently screened, which weighs against closing this as a standalone low-risk event given the surrounding breach signals.
- Context does not include other transfers tied to this same counterparty, so the full extent of the pattern cannot be confirmed here, lowering confidence and supporting escalation for a person to pull that data.
Evidence
{
"n": 1064,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.