SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $905.41 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_7prxr7pl1n7
Transfer
acht_sim_nort_7prxr7pl1n7 · $905.41 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An ACH outgoing debit transfer of $905.41 from entity Cedar Services 02 (program Northwind Payroll) was flagged by the skoor_review detector at a risk score of 40, placing it in the review band. The sole contributing signal is one prior unauthorized return associated with the counterparty. What the evidence shows. The transfer settled already (status SETTLED, return code none), so no funds are currently held. The triggering signal is a single prior unauthorized return on counterparty cpty_sim_nort_5a6oup6d8m; no other risk signals fired. The entity Cedar Services 02 is VERIFIED, not high risk, not PEP, with no review reasons and screening current as of 2026-06-30. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=212), ach_overall_return_rate at 0.94% (n=212, ok), and reserve_coverage_ratio at 3.38 (ok), indicating no broader unauthorized-return pattern at the program level. One KRI, manual_review_aging_hours, shows a breach (1434.67 hours, n=3), which reflects review queue timing rather than this specific alert's substance. Confidence on the evidence record is 1, and n=583 for the skoor model. What was checked. Transfer status and return code, entity verification and risk flags, program declared volume and rails, program KRI panel for related return-rate and concentration metrics, and prior dispositions on this alert (none found). What is recommended. Since the transfer has already settled and no hold is in place, a release recommendation does not apply. The single unauthorized-return signal on the counterparty warrants a person's review of the counterparty relationship and this entity's transaction history before any further transfers to this counterparty are processed, but does not by itself indicate a pattern beyond this alert given program-level return rates are at 0-0.94% and otherwise normal. Recommend hold status for review is not applicable to a settled transfer; instead this should go to a reviewer to determine whether to restrict future transfers to this counterparty or require additional verification, rather than being closed outright given the unauthorized-return history is unresolved.
Recommendation
hold
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer already settled, so 'hold' here refers to reviewer attention before any further transfers to this counterparty, not a fund freeze on this specific completed transaction.
  • The only signal present is one prior unauthorized return on the counterparty; this is a specific counterparty-level concern, not evidence of a broader entity or program pattern.
  • Entity-level checks (verification, PEP, high-risk, review reasons) are all clean, reducing concern about the paying entity itself.
  • Program KRIs (ach_unauthorized_return_rate=0, ach_overall_return_rate=0.94%, reserve_coverage_ratio=3.38) show no elevated program-wide return risk, which weighs against escalation.
  • A single prior unauthorized return, even if resolved, is a factual item that has not been reviewed by a person and could affect the counterparty relationship, which weighs against outright closure.
  • Evidence is otherwise thin (counterparty country unknown, no detail on the nature or resolution of the prior unauthorized return), which lowers confidence in either closing or escalating decisively.

Evidence

{
  "n": 583,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.