Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $987.19 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Northwind Payroll (simulated)
- Subject
- transfer acht_sim_nort_8osn43bj2fi
- Transfer
- acht_sim_nort_8osn43bj2fi · $987.19 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 7b383731-85e0-4a23-90f8-339ac31a0abe fired on a $987.19 outgoing ACH transfer (acht_sim_nort_8osn43bj2fi) under Northwind Payroll. The skoor_review detector scored the transfer 40 (review band) due to one signal: counterparty cpty_sim_nort_25c8izfo4a has a prior unauthorized return on record.
What the evidence shows. The transfer itself settled with no return code, meaning it completed without an unauthorized-return event. The skoor of 40 is driven entirely by the single historical signal (returns.counterparty_prior_unauthorized, weight 40), with detector confidence 1 and n=896. The originating entity, Larch Studio 011, is VERIFIED, not high risk, not PEP, has no open review reasons, and was screened 2026-08-14. Program-level KRIs are mostly in range: ach_unauthorized_return_rate is 0, ach_overall_return_rate 1.07%, sanctioned_country_transfers 0, reserve_coverage_ratio 1.93. Two KRIs sit outside normal: manual_review_aging_hours is in breach (1434.7 hrs, n=7) and pep_flagged_entities and high_risk_entity_share are at watch, but none of these tie specifically to this counterparty or this transfer.
What was checked. Reviewed the transfer status (SETTLED, no return code), the entity verification and risk flags, the program KRI panel, and prior dispositions (none exist for this subject). Counterparty country is listed as unknown, which is a gap in the evidence but does not itself generate a signal in this alert.
What is recommended. The transfer already settled without incident and there is no live hold to act on, so release does not apply. The evidence is a single historical signal on the counterparty with no corroborating pattern (return rate metrics are normal, entity is verified and low risk). This does not meet the bar for escalation absent additional counterparty-level history. Recommend closing the alert; the aging and pep/high-risk-share KRI watches are program-level items that should be tracked separately, not through this alert.
- Recommendation
- close
- Confidence
- 0.68
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer settled with no return code; the flagged unauthorized return is historical and attached to the counterparty, not this transaction.
- Entity is VERIFIED, not high risk, not PEP, no open review reasons, screened within the past 5 weeks.
- Program ach_unauthorized_return_rate is 0 and overall return rate is 1.07%, showing no active pattern of unauthorized returns.
- No prior dispositions exist on this subject, so there is no repeat-alert pattern to escalate.
- Counterparty country is unknown, a minor evidence gap, but it does not feed into the current signal or change the settled status of the transfer.
- manual_review_aging_hours breach and pep/high-risk-share watches are program-wide KRI conditions unrelated to this specific counterparty or transfer.
Evidence
{
"n": 896,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.