Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $1,114.96 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Northwind Payroll (simulated)
- Subject
- transfer acht_sim_nort_aua49gsc2g3
- Transfer
- acht_sim_nort_aua49gsc2g3 · $1,114.96 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 729e15ac-2aaf-4135-9ada-bddbc6efb257 fired on a $1,114.96 outgoing ACH credit transfer (acht_sim_nort_aua49gsc2g3) under program Northwind Payroll. The detector (skoor_review) scored the transfer at 40, placing it in the review band, driven by a single signal: the counterparty (cpty_sim_nort_5a6oup6d8m) has one prior unauthorized return on record.
What the evidence shows. The transfer itself has status SETTLED with return code none, meaning this specific transfer was not returned. The risk score of 40 comes entirely from the counterparty_prior_unauthorized signal (weight 40, n=896, confidence 1). The subject entity, Dune LLC 015 (enti_sim_nort_8t15w9uc2f), is VERIFIED, not high risk, not PEP, has no review reasons, and was screened as recently as 2026-07-07. Program-level KRIs show ach_unauthorized_return_rate at 0 across 374 transfers, ach_overall_return_rate at 1.07%, and sanctioned_country_transfers at 0, none of which corroborate an emerging pattern tied to this transfer. Manual_review_aging_hours shows a breach (1434.68 hours, n=7), but this is a portfolio-wide backlog metric, not evidence specific to this alert or counterparty. Counterparty country is listed as unknown, which limits full verification but is not itself a flagged signal.
What was checked. Reviewed the transfer record (status, amount, return code), the triggering signal and its weight, the subject entity's verification and screening status, program declared volume and KRIs, and prior dispositions. Prior dispositions: none on file for this entity or counterparty.
What is recommended. The transfer has already settled, so no funds are available to hold. The single signal reflects one historical unauthorized return by the counterparty, not a return on this transfer, and no other program-level indicator (unauthorized return rate, sanctioned country transfers, entity risk flags) supports a broader pattern. The subject entity is verified and unflagged. Absent additional signals or prior dispositions, this alert does not require further human review before closing, though the counterparty's return history should remain visible for future transfers.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is SETTLED with return code none; there is no pending fund movement to hold or release.
- The sole signal driving the review-band score is one prior unauthorized return by the counterparty, not a defect in this transaction.
- Subject entity is VERIFIED, not high-risk, not PEP, and was screened within the last two months.
- Program-level ach_unauthorized_return_rate is 0 (n=374) and sanctioned_country_transfers is 0 (n=772), providing no corroborating pattern.
- Manual_review_aging_hours breach is a portfolio backlog metric unrelated to this specific alert or counterparty.
- No prior dispositions exist for this entity or counterparty to suggest recurrence.
Evidence
{
"n": 896,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.