SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $790.57 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_bqvthyet8rk
Transfer
acht_sim_harb_bqvthyet8rk · $790.57 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An ACH outgoing transfer of $790.57 from entity Iris Services 18 to counterparty cpty_sim_harb_b3trqxlu3zb generated a review-band Transaction Risk Skoor alert (40) because this counterparty has one prior unauthorized return on record. The transfer has already settled and its own return code is none. What the evidence shows. The alert is driven entirely by a single signal: returns.counterparty_prior_unauthorized, weight 40, detail '1 prior unauthorized return(s)'. Hard signal is false and confidence on the skoor computation is 1 (n=1915). The transfer itself settled with no return code, so this specific transaction did not fail. The subject entity is VERIFIED, not high risk, not PEP, with no open review reasons and screening current as of 2026-08-22. Program-level KRIs show ach_unauthorized_return_rate at 0.0078 flagged as a breach and manual_review_aging_hours at 1438 flagged as a breach, both program-wide conditions rather than specifics to this transfer. Other KRIs (frozen_accounts, overdraft_events, manual_review_rate, velocity_vs_declared, reserve_coverage_ratio, ach_overall_return_rate, sanctioned_country_transfers, counterparty_concentration_top1) are ok. There are no prior dispositions on this alert. What was checked. Reviewed the transfer record (status, return code, amount, dates), the entity verification status and screening date, the program KRI panel, and prior dispositions. No counterparty-level entity record or counterparty risk profile is included in the context, so the counterparty's overall history beyond 'one prior unauthorized return' cannot be assessed further from the evidence given. What is recommended. This transfer has already settled with no return code, so there are no funds to hold on this specific alert. The single-signal basis (one historical unauthorized return on the counterparty) combined with the settled, unreturned status of this transaction and a clean, verified subject entity does not by itself require blocking action. However, the program-level ach_unauthorized_return_rate breach and manual_review_aging_hours breach indicate broader conditions that a person should review to determine if this counterparty or pattern needs closer monitoring across the program. Recommend closing this individual alert given the settled status and lack of transaction-specific irregularity, while flagging the program-level KRI breaches for separate review.
Recommendation
close
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is SETTLED with return code none; there is no pending movement of funds to hold or release.
  • The only alert-driving signal is a single prior unauthorized return on the counterparty, weight 40, which placed the skoor in the review band but hard_signal is false.
  • Subject entity is VERIFIED, not high risk, not PEP, with no open review reasons and screening current.
  • Program KRIs show two breaches (ach_unauthorized_return_rate, manual_review_aging_hours) that are program-wide, not specific to this transfer, and do not clearly trace to this counterparty or entity.
  • No counterparty entity record is included in the evidence, limiting assessment of whether the prior unauthorized return reflects a broader pattern; confidence is lowered accordingly.
  • No prior dispositions exist for this alert, so this is a first-pass review with no escalation history to weigh.

Evidence

{
  "n": 1915,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.