SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $1,217.36 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Meridian Remit (simulated)
Subject
transfer acht_sim_meri_2w3cni8dbkf
Transfer
acht_sim_meri_2w3cni8dbkf · $1,217.36 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 7eac6508-b2ef-4b65-ab4c-f1c4cfffe344 fired on a $1,217.36 outgoing ACH transfer (acht_sim_meri_2w3cni8dbkf) under the skoor_review detector. The transfer risk score was 40, placing it in the review band, driven by a single signal: the counterparty (cpty_sim_meri_bts0zmjm9td) has 2 prior unauthorized returns, weighted at 40 points. What the evidence shows. The transfer itself settled with no return code (return code: none), so this specific transaction did not fail or get returned. The hard_signal flag is false, meaning the score is based on soft historical signal rather than a confirmed event on this transfer. The entity behind the payout, Payout Agent (Meridian), is VERIFIED, not high risk, not PEP, with no review reasons and current screening (last screened 2026-08-26). At the program level, three KRIs show breach status: ach_unauthorized_return_rate (0.0143, n=280), reserve_coverage_ratio (0.80, n=280), and manual_review_aging_hours (1146.9 hours, n=2). Two more KRIs are at watch: hold_aging_hours and pep_flagged_entities. There are no prior dispositions on this alert. What was checked. Reviewed the transfer record, the underlying skoor signal detail, the counterparty verification status, and the program-level KRI panel. Confirmed the transfer is settled with no return code attached to it, confirmed the risk signal originates from the counterparty's historical return record rather than this transaction, and confirmed entity verification is current and clean. What is recommended. This transfer already settled and carries no return of its own, so there is no held transfer to release and no immediate transaction-level action available. However, the counterparty's prior unauthorized return history, combined with the program's concurrent breach on ach_unauthorized_return_rate and reserve_coverage_ratio, indicates a pattern extending beyond this single alert. This should be escalated for a person to review the counterparty relationship and the program's broader return-rate and reserve trends together, rather than closed as an isolated review-band alert.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is SETTLED with return code none: no return occurred on this specific transaction.
  • Risk signal is a soft historical flag (hard_signal false) based on 2 prior unauthorized returns tied to the counterparty, not this transfer.
  • Entity is VERIFIED, not high risk, not PEP, with no review reasons, reducing entity-level concern.
  • Program KRIs show concurrent breaches in ach_unauthorized_return_rate and reserve_coverage_ratio, plus a breach in manual_review_aging_hours, suggesting a pattern beyond this single alert.
  • No prior dispositions exist, so this pattern has not yet been assessed by a person.
  • Confidence is moderate because the evidence linking this specific counterparty's history to the program-level breaches is circumstantial, not directly quantified in the alert context.

Evidence

{
  "n": 719,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "2 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+402 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.