SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Counterparty Receiver 1 entered the hold band (Skoor 75, n=146): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.review_share, counterparty.new.

Detector
counterparty_hold
Severity
high
Program
Northwind Payroll (simulated)
Subject
counterparty cpty_sim_nort_25c8izfo4a
Transfer
Skoor at alert
75 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Counterparty cpty_sim_nort_25c8izfo4a entered the hold band under the counterparty_hold detector. The composite Skoor reached 75 against a threshold band of 'hold,' based on 146 observed transactions. The alert was auto-held by the detector and routed to review because it is not auto-closable. What the evidence shows. The score of 75 is built from four signals: one unauthorized return recorded for this counterparty (weight 40), an unauthorized-return rate of 1/146 that exceeds the network threshold (weight 15), 38% of this counterparty's transaction volume sitting in the review band (weight 10), and the counterparty being newly seen with zero days of history (weight 10). The hard_signal flag is false, meaning no single deterministic rule fired; the hold is driven by the combination of a thin, new relationship plus one unauthorized return. Program-level KRIs show the overall ACH unauthorized return rate at 0.17% (ok) and administrative return rate at 0.33% (ok), so this counterparty's 0.68% rate is elevated relative to the program baseline but is based on a single event out of 146. What was checked. Program KRIs were reviewed for corroborating signal: frozen_accounts, overdraft_events, sanctioned_country_transfers, stale_screening_share, and verification_denial_rate are all in the ok range. hold_aging_hours, pep_flagged_entities, and high_risk_entity_share are flagged watch but are not specific to this counterparty. manual_review_aging_hours shows a breach at 1434.7 hours on n=11, which points to a backlog in review processing generally, but the sample size is small and there is no field linking that backlog to this specific counterparty or alert. No prior dispositions exist for this subject. What is recommended. Hold. The counterparty is new, has drawn one unauthorized return against a small transaction base, and a substantial share (38%) of its activity is already in the review band. This combination is exactly what the detector's hold band is designed to catch, and the sample size (n=146, 1 event) is too small to close without a person examining the underlying transaction and any return documentation. The program-level manual_review_aging_hours breach is noted but does not by itself indicate a pattern broader than this single counterparty; it should be tracked separately rather than driving escalation of this alert.
Recommendation
hold
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Skoor 75 falls in the defined hold band with autoHold true, indicating the detector itself withholds further movement pending review.
  • Evidence combines a real unauthorized return with a new-counterparty flag and elevated review-band share, all traceable to the alert's signal list.
  • hard_signal is false and n is small (146 transactions, 1 unauthorized return), so certainty is moderate, not high.
  • Program KRIs are largely ok or watch, not breach, except for manual_review_aging_hours which is a program-wide backlog metric with no direct link to this counterparty, so escalation is not supported by current evidence.
  • No prior dispositions exist to compare against, and no transfer-hold-release condition applies here, ruling out 'release'.

Evidence

{
  "n": 146,
  "band": "hold",
  "skoor": 75,
  "signals": [
    {
      "code": "counterparty.unauthorized_returns",
      "detail": "drew 1 unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "counterparty.unauthorized_rate",
      "detail": "unauthorized rate 1/146 above the network threshold",
      "weight": 15
    },
    {
      "code": "counterparty.review_share",
      "detail": "38% in the review band",
      "weight": 10
    },
    {
      "code": "counterparty.new",
      "detail": "first seen 0d ago",
      "weight": 10
    }
  ],
  "version": "crs-v1",
  "autoHold": true,
  "confidence": 0.8,
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.