SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Counterparty Receiver 61 entered the hold band (Skoor 90, n=9): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.review_share, counterparty.new.

Detector
counterparty_hold
Severity
high
Program
Meridian Remit (simulated)
Subject
counterparty cpty_sim_meri_3mv7euw3b1k
Transfer
Skoor at alert
90 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Counterparty cpty_sim_meri_3mv7euw3b1k (Counterparty Receiver 61) was flagged by the counterparty_hold detector on 2026-09-17T19:32:18.324Z. The counterparty entered the hold band with a Skoor of 90 based on a sample of 9 transactions. The route was set to reviewed because the detector is not auto-closable, and autoHold is true. What the evidence shows. The score of 90 is driven mainly by one unauthorized return out of 9 transactions (weight 40), which also produced an unauthorized rate of 1/9 above the network threshold (weight 15) and a return rate of 1/9 (weight 15). Additional weight comes from 44% of the counterparty's activity falling in the review band (weight 10) and the counterparty being new, first seen 0 days ago (weight 10). The detector's own confidence field is low at 0.226, and hard_signal is false, meaning no single deterministic rule fired independent of the composite score. The sample size (n=9) is small, so rates built on it (1/9) are sensitive to a single event. What was checked. Reviewed the alert evidence block for signal composition and sample size. Checked program-level KRIs for Meridian Remit: reserve_coverage_ratio is in breach (0.48), manual_review_aging_hours is in breach (1146.87 hours, n=3), ach_unauthorized_return_rate is in breach (0.0118, n=425), and sanctioned_country_transfers shows 2 occurrences (n=923, breach). These are program-wide metrics and are not tied in the evidence to this specific counterparty, so they cannot be used to confirm a counterparty-specific pattern here. No prior dispositions exist for this alert. What is recommended. Given the small sample size (n=9), the low detector confidence (0.226), and the fact that the score is largely driven by a single unauthorized return, a person should review the underlying transaction and counterparty onboarding details before any funds tied to this counterparty move further. The program-level breaches (unauthorized return rate, sanctioned country transfers, manual review aging) are not directly linked to this counterparty in the evidence provided, so escalation to a program-wide investigation is not supported by this alert alone, though the reviewer may want to check whether this counterparty appears in the broader breach populations.
Recommendation
hold
Confidence
0.40
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Skoor is in the hold band (90) with autoHold true, indicating the system itself withheld action pending review.
  • hard_signal is false and detector confidence is low (0.226), meaning the alert reflects a composite score rather than a definitive rule violation.
  • The unauthorized return and return rate signals are each based on 1 event out of 9, a small sample that a human should verify before any release decision.
  • The counterparty is newly seen (0 days), which independently limits the reliability of rate-based signals.
  • Program-level KRI breaches (unauthorized return rate, sanctioned country transfers, manual review aging, reserve coverage) are noted but not evidenced as connected to this specific counterparty, so escalation is not justified on this alert alone.
  • No prior dispositions exist to inform a faster resolution.

Evidence

{
  "n": 9,
  "band": "hold",
  "skoor": 90,
  "signals": [
    {
      "code": "counterparty.unauthorized_returns",
      "detail": "drew 1 unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "counterparty.unauthorized_rate",
      "detail": "unauthorized rate 1/9 above the network threshold",
      "weight": 15
    },
    {
      "code": "counterparty.return_rate",
      "detail": "return rate 1/9",
      "weight": 15
    },
    {
      "code": "counterparty.review_share",
      "detail": "44% in the review band",
      "weight": 10
    },
    {
      "code": "counterparty.new",
      "detail": "first seen 0d ago",
      "weight": 10
    }
  ],
  "version": "crs-v1",
  "autoHold": true,
  "confidence": 0.226,
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.