Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $3,498.44 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Northwind Payroll (simulated)
- Subject
- transfer acht_sim_nort_9ofa8xxc2hk
- Transfer
- acht_sim_nort_9ofa8xxc2hk · $3,498.44 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 8d8d3b27-7f13-4676-b991-f09732fe6e3c fired on transfer acht_sim_nort_9ofa8xxc2hk, a $3,498.44 outgoing ACH credit under the Northwind Payroll program. The skoor_review detector scored the transfer 40 (review band, hard_signal false) based on one signal: returns.counterparty_prior_unauthorized, reflecting one prior unauthorized return for this counterparty, weighted 40.
What the evidence shows. The transfer itself settled with no return code (return code: none), so no return occurred on this transaction. The flagged issue is a prior unauthorized return tied to the counterparty (cpty_sim_nort_25c8izfo4a), country unknown, count of one. The paying entity, Fern Studio 017, is VERIFIED, not high risk, not PEP, has no review reasons, and was screened 2026-08-19. Program-level KRIs are mostly in range: ach_unauthorized_return_rate is 0 across 374 transfers, ach_overall_return_rate is 1.07%, sanctioned_country_transfers is 0, counterparty_concentration_top1 is 10.4%. Two KRIs are outside normal: pep_flagged_entities (1 of 33, watch) and high_risk_entity_share (6.06%, watch), and manual_review_aging_hours shows a breach (1434.7 hours, n=7), but none of these tie directly to this counterparty or this transfer.
What was checked. Transfer status and return code, entity verification and risk flags, program-level KRIs for return rates and concentration, and prior dispositions on this alert (none exist). No corroborating signal beyond the single prior unauthorized return was found in the evidence provided; there is no detail on when that prior return occurred or its dollar amount.
What is recommended. The transfer has already settled, so there are no funds to hold or release. The single prior-unauthorized-return signal is isolated to this one counterparty and is not corroborated by elevated return rates at the program level (unauthorized return rate is 0 across 374 transfers) or by any entity-level risk flag. Nothing in the evidence points to a broader pattern needing escalation. This can be closed, with a note that if additional unauthorized returns from this same counterparty appear, the alert should be reopened or escalated.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer status is SETTLED with return code none; there is no pending transfer to hold or release.
- The alert's sole signal is one prior unauthorized return tied to the counterparty; no current return occurred on this transfer.
- Paying entity is VERIFIED, not high risk, not PEP, with no review reasons and recent screening.
- Program-level ach_unauthorized_return_rate is 0 (n=374), which does not support a pattern of unauthorized-return risk beyond this single historical counterparty event.
- Counterparty country is unknown, and no detail on the timing or amount of the prior unauthorized return was provided, which limits confidence in the closure.
- Two program KRIs (pep_flagged_entities, high_risk_entity_share) are in watch status and manual_review_aging_hours is in breach, but none are directly linked to this alert's subject or counterparty.
Evidence
{
"n": 923,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.