SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $987.19 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_8osn43bj2fi
Transfer
acht_sim_nort_8osn43bj2fi · $987.19 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 7b383731-85e0-4a23-90f8-339ac31a0abe fired on a $987.19 outgoing ACH transfer (acht_sim_nort_8osn43bj2fi) under Northwind Payroll. The skoor_review detector scored the transfer 40 (review band) due to one signal: counterparty cpty_sim_nort_25c8izfo4a has a prior unauthorized return on record. What the evidence shows. The transfer itself settled with no return code, meaning it completed without an unauthorized-return event. The skoor of 40 is driven entirely by the single historical signal (returns.counterparty_prior_unauthorized, weight 40), with detector confidence 1 and n=896. The originating entity, Larch Studio 011, is VERIFIED, not high risk, not PEP, has no open review reasons, and was screened 2026-08-14. Program-level KRIs are mostly in range: ach_unauthorized_return_rate is 0, ach_overall_return_rate 1.07%, sanctioned_country_transfers 0, reserve_coverage_ratio 1.93. Two KRIs sit outside normal: manual_review_aging_hours is in breach (1434.7 hrs, n=7) and pep_flagged_entities and high_risk_entity_share are at watch, but none of these tie specifically to this counterparty or this transfer. What was checked. Reviewed the transfer status (SETTLED, no return code), the entity verification and risk flags, the program KRI panel, and prior dispositions (none exist for this subject). Counterparty country is listed as unknown, which is a gap in the evidence but does not itself generate a signal in this alert. What is recommended. The transfer already settled without incident and there is no live hold to act on, so release does not apply. The evidence is a single historical signal on the counterparty with no corroborating pattern (return rate metrics are normal, entity is verified and low risk). This does not meet the bar for escalation absent additional counterparty-level history. Recommend closing the alert; the aging and pep/high-risk-share KRI watches are program-level items that should be tracked separately, not through this alert.
Recommendation
close
Confidence
0.68
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer settled with no return code; the flagged unauthorized return is historical and attached to the counterparty, not this transaction.
  • Entity is VERIFIED, not high risk, not PEP, no open review reasons, screened within the past 5 weeks.
  • Program ach_unauthorized_return_rate is 0 and overall return rate is 1.07%, showing no active pattern of unauthorized returns.
  • No prior dispositions exist on this subject, so there is no repeat-alert pattern to escalate.
  • Counterparty country is unknown, a minor evidence gap, but it does not feed into the current signal or change the settled status of the transfer.
  • manual_review_aging_hours breach and pep/high-risk-share watches are program-wide KRI conditions unrelated to this specific counterparty or transfer.

Evidence

{
  "n": 896,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.