Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $567.47 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_46as69326zx
- Transfer
- acht_sim_harb_46as69326zx · $567.47 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An ACH outgoing debit transfer of $567.47 from Harbor Marketplace Payouts to counterparty cpty_sim_harb_5p4yfvh5vq was flagged by the skoor_review detector at a skoor of 40 (review band), driven by a single signal: the counterparty has one prior unauthorized return on record.
What the evidence shows. The transfer itself settled with no return code, meaning this specific transaction completed without incident. The skoor is 40, placing it in the review band, and hard_signal is false, indicating the detector did not treat this as a high-confidence stop signal. The only contributing signal is 'returns.counterparty_prior_unauthorized' with a weight of 40, reflecting one prior unauthorized return for this counterparty, not a pattern of repeated unauthorized returns. The debiting entity, Elm Partners 14, is VERIFIED, not high risk, not PEP, has no open review reasons, and was screened as recently as 2026-07-08. The counterparty's country is unknown, but no sanctioned-country or high-risk-entity signal fired for this alert. At the program level, ach_unauthorized_return_rate is flagged as a breach (0.0097 against n=411) and manual_review_aging_hours is also a breach (1438 hours against n=7), but these are aggregate KRIs not specific to this counterparty or transfer, and no prior dispositions exist tying this alert to a broader case.
What was checked. Transfer status and return code, skoor and signal detail, entity verification status and screening recency, program KRI panel, and prior disposition history. No other signals fired on this transfer (n=1182/1201 population, confidence 0.985). No hard signal was present, and the transfer already settled, so no funds are pending or held.
What is recommended. Close this alert. The evidence is limited to a single prior unauthorized return on the counterparty with no corroborating signal, the current transfer settled cleanly, and the debiting entity is verified with no risk flags. The transfer is already settled, so there is no held transfer to release. The program-level KRI breaches (unauthorized return rate, manual review aging) are noted for separate program-level monitoring but do not, on the evidence in this alert, indicate a pattern specific to this counterparty or transfer that would warrant escalation.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Single low-weight signal (prior unauthorized return, weight 40) with hard_signal false and no other corroborating signals in the alert.
- Transfer already SETTLED with no return code; nothing to hold or release.
- Entity VERIFIED, not high risk, not PEP, no open review reasons, screening recent.
- Program KRI breaches (ach_unauthorized_return_rate, manual_review_aging_hours) are aggregate and not directly linked to this counterparty or transfer in the evidence provided, so they support noting but not escalating this specific alert.
- No prior dispositions exist to suggest a recurring pattern for this counterparty.
Evidence
{
"n": 1182,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 0.985,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.