SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $2,946.27 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_5cczut9m3em
Transfer
acht_sim_nort_5cczut9m3em · $2,946.27 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 9f27c248-94d7-44a6-93a7-52852b72e040 fired on outgoing ACH transfer acht_sim_nort_5cczut9m3em, a $2,946.27 credit under program Northwind Payroll. The transfer scored 40 (review band) on the skoor_review detector due to a single signal: the counterparty (cpty_sim_nort_5a6oup6d8m) has one prior unauthorized return on record. What the evidence shows. The transfer itself is SETTLED with return code none, meaning it completed without an unauthorized return or any other return event. The originating entity, Fern Studio 05 (enti_sim_nort_aasic8tu1e), is VERIFIED, not flagged high risk, not PEP, has no open review reasons, and was screened on 2026-08-25. The alert's only signal is the counterparty's single prior unauthorized return; there is no detail on when that prior return occurred or whether it relates to this program. Program-level KRIs are mostly in the ok/watch range: ach_unauthorized_return_rate is 0.0017 (ok), ach_overall_return_rate is 0.0139 (ok), manual_review_rate is 0.0094 (ok). Two items sit outside ok: hold_aging_hours (518.3 hrs, watch, n=1) and manual_review_aging_hours (1434.7 hrs, breach, n=11), plus pep_flagged_entities and high_risk_entity_share at watch. None of these breach/watch KRIs are tied in the evidence to this specific counterparty or transfer. What was checked. Reviewed the transfer status and return code, the counterparty's flagged prior unauthorized return, the entity's verification and screening status, program declared volume and rail scope, and the full set of program KRIs for any linkage to this alert's subject. No prior dispositions exist for this alert. What is recommended. Close this alert. The transfer has already settled cleanly with no return, and the account holder is verified with no other risk indicators. The counterparty's single prior unauthorized return is noted for future monitoring but does not, on its own, indicate a problem with this settled transfer requiring a person to act on funds movement (none are pending). The manual_review_aging_hours breach is a separate program-level condition unrelated in the evidence to this specific alert and should be tracked independently, not as part of this disposition.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is SETTLED with return code none; no funds are pending or held, so hold/release do not apply.
  • Entity is VERIFIED, not high risk, not PEP, no open review reasons, screened within the last month.
  • The only alert signal is a single prior unauthorized return on the counterparty, with no further detail (date, program linkage, or recurrence) provided.
  • Program KRIs directly relevant to unauthorized/overall returns are in the ok range (0.0017 and 0.0139), showing no broader return pattern.
  • Manual_review_aging_hours breach and other watch-level KRIs are program-wide metrics with no evidence connecting them to this specific counterparty or transfer, so they do not support escalation on this alert alone.
  • No prior dispositions exist to indicate recurrence for this counterparty or entity.

Evidence

{
  "n": 1322,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.