Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $386.76 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_2cenkfm88fo
- Transfer
- acht_sim_harb_2cenkfm88fo · $386.76 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An ACH outgoing credit transfer of $386.76 from Harbor Marketplace Payouts to counterparty cpty_sim_harb_362c8piz3xi was flagged by the skoor_review detector at a risk score of 40 (review band) due to a single prior unauthorized return associated with the counterparty. The transfer has already settled and carries no return code.
What the evidence shows. The only risk signal driving the score is returns.counterparty_prior_unauthorized, weighted 40, based on one prior unauthorized return for this counterparty. The transfer itself settled without incident and has no return code. The originating entity, Birch Holdings 113, is verified, not flagged high risk, not PEP, and has no open review reasons; last screened 2026-08-19. Hard_signal is false and route reason is simply 'detector not auto-closable,' meaning no automatic disposition path exists, not that additional risk was found. Program-level KRIs show two items in breach status: ach_unauthorized_return_rate (0.0088, n=678) and manual_review_aging_hours (1438 hours, n=10). Three other KRIs are in watch status: hold_aging_hours, pep_flagged_entities, and high_risk_entity_share. All other KRIs, including reserve_coverage_ratio and velocity_vs_declared, are within normal range.
What was checked. Reviewed the transfer status and amount, the counterparty's return history as cited in the evidence, the originating entity's verification and screening status, and the program's KRI panel for corroborating patterns. No prior dispositions exist for this alert.
What is recommended. The transfer itself is settled and the single-return signal, taken alone, does not show a pattern strong enough to require holding funds that have already moved. However, the coexistence of a breach-level ach_unauthorized_return_rate and a breach-level manual_review_aging_hours across the program suggests this individual alert may be part of a broader pattern of unauthorized-return risk and review backlog that a single-alert disposition cannot resolve. This warrants escalation for a person to assess whether the counterparty or program-level return trend needs broader review, rather than closing this alert as an isolated item.
- Recommendation
- escalate
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Skoor 40 in review band driven solely by one prior unauthorized return on the counterparty; no additional adverse signals on the entity or transfer itself.
- Transfer status is SETTLED with no return code, so there is nothing to hold or release for this specific transfer.
- Program KRIs show breach-level ach_unauthorized_return_rate and manual_review_aging_hours, plus watch-level hold_aging_hours, pep_flagged_entities, and high_risk_entity_share, indicating potential program-wide patterns beyond this single alert.
- Entity verification is current (last screened 2026-08-19), not high risk, not PEP, with no open review reasons, so no entity-level action is indicated.
- Evidence context is limited to the alert and KRI snapshot; no counterparty-level detail beyond 'return count 1' is available, which limits certainty and lowers confidence.
Evidence
{
"n": 1746,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.