SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $1,114.96 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_aua49gsc2g3
Transfer
acht_sim_nort_aua49gsc2g3 · $1,114.96 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 729e15ac-2aaf-4135-9ada-bddbc6efb257 fired on a $1,114.96 outgoing ACH credit transfer (acht_sim_nort_aua49gsc2g3) under program Northwind Payroll. The detector (skoor_review) scored the transfer at 40, placing it in the review band, driven by a single signal: the counterparty (cpty_sim_nort_5a6oup6d8m) has one prior unauthorized return on record. What the evidence shows. The transfer itself has status SETTLED with return code none, meaning this specific transfer was not returned. The risk score of 40 comes entirely from the counterparty_prior_unauthorized signal (weight 40, n=896, confidence 1). The subject entity, Dune LLC 015 (enti_sim_nort_8t15w9uc2f), is VERIFIED, not high risk, not PEP, has no review reasons, and was screened as recently as 2026-07-07. Program-level KRIs show ach_unauthorized_return_rate at 0 across 374 transfers, ach_overall_return_rate at 1.07%, and sanctioned_country_transfers at 0, none of which corroborate an emerging pattern tied to this transfer. Manual_review_aging_hours shows a breach (1434.68 hours, n=7), but this is a portfolio-wide backlog metric, not evidence specific to this alert or counterparty. Counterparty country is listed as unknown, which limits full verification but is not itself a flagged signal. What was checked. Reviewed the transfer record (status, amount, return code), the triggering signal and its weight, the subject entity's verification and screening status, program declared volume and KRIs, and prior dispositions. Prior dispositions: none on file for this entity or counterparty. What is recommended. The transfer has already settled, so no funds are available to hold. The single signal reflects one historical unauthorized return by the counterparty, not a return on this transfer, and no other program-level indicator (unauthorized return rate, sanctioned country transfers, entity risk flags) supports a broader pattern. The subject entity is verified and unflagged. Absent additional signals or prior dispositions, this alert does not require further human review before closing, though the counterparty's return history should remain visible for future transfers.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is SETTLED with return code none; there is no pending fund movement to hold or release.
  • The sole signal driving the review-band score is one prior unauthorized return by the counterparty, not a defect in this transaction.
  • Subject entity is VERIFIED, not high-risk, not PEP, and was screened within the last two months.
  • Program-level ach_unauthorized_return_rate is 0 (n=374) and sanctioned_country_transfers is 0 (n=772), providing no corroborating pattern.
  • Manual_review_aging_hours breach is a portfolio backlog metric unrelated to this specific alert or counterparty.
  • No prior dispositions exist for this entity or counterparty to suggest recurrence.

Evidence

{
  "n": 896,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.