SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Counterparty Receiver 45 entered the hold band (Skoor 90, n=5): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.review_share, counterparty.new.

Detector
counterparty_hold
Severity
high
Program
Meridian Remit (simulated)
Subject
counterparty cpty_sim_meri_6ppd81dfako
Transfer
Skoor at alert
90 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Detector counterparty_hold raised an alert on counterparty cpty_sim_meri_6ppd81dfako for program Meridian Remit (simulated): Counterparty Receiver 45 entered the hold band (Skoor 90, n=5): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.review_share, counterparty.new.. What the evidence shows. Transaction Risk Skoor 90 (band hold). What was checked. Program KRIs as of the latest snapshot: frozen_accounts ok, hold_aging_hours watch, overdraft_events ok, manual_review_rate ok, card_fraud_declines unmeasured, pep_flagged_entities watch, velocity_vs_declared ok, stale_screening_share ok, high_risk_entity_share ok, reserve_coverage_ratio breach, ach_overall_return_rate ok, verification_denial_rate ok, manual_review_aging_hours breach, ach_unauthorized_return_rate breach, sanctioned_country_transfers breach, ach_administrative_return_rate ok, counterparty_concentration_top1 ok. No prior dispositions on this entity or counterparty. What is recommended. Recommended: hold. A person decides; this draft was assembled from the evidence without a model (model call failed).
Recommendation
hold
Confidence
null (template, no model)
Model
none (template)
Drafted
2026-09-17 19:32Z
Rationale
  • Template draft: recommendation follows the band and the hard-signal rule only.

Evidence

{
  "n": 5,
  "band": "hold",
  "skoor": 90,
  "signals": [
    {
      "code": "counterparty.unauthorized_returns",
      "detail": "drew 2 unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "counterparty.unauthorized_rate",
      "detail": "unauthorized rate 2/5 above the network threshold",
      "weight": 15
    },
    {
      "code": "counterparty.return_rate",
      "detail": "return rate 2/5",
      "weight": 15
    },
    {
      "code": "counterparty.review_share",
      "detail": "60% in the review band",
      "weight": 10
    },
    {
      "code": "counterparty.new",
      "detail": "first seen 0d ago",
      "weight": 10
    }
  ],
  "version": "crs-v1",
  "autoHold": true,
  "confidence": 0.166,
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.