Alert · reviewed · open
The program's ach unauthorized return rate is 1.14% over 440 originated debits, above the 0.5% network threshold.
- Detector
- return_rate_breach
- Severity
- high
- Program
- Meridian Remit (simulated)
- Subject
- program 48915275-d6d2-4068-8e62-f51a51f9da77
- Transfer
- —
- Skoor at alert
- null unscored
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-18 00:17Z
- Closed
- —
- Decision clock
- appeal · due 2026-09-25 00:17Z due 2026-09-25 00:17Z
- Escalated
- —
Draft narrative
What happened. Alert a901856c-c765-469b-846e-afa9b1e0df71 fired on detector return_rate_breach for program 48915275-d6d2-4068-8e62-f51a51f9da77 (Meridian Remit). The program's ACH unauthorized return rate reached 1.14% (0.011363636363636364) over 440 originated debits, above the 0.5% network threshold. Severity is high, route is 'reviewed' per detector default, and there is no hard signal flag. No prior dispositions exist for this program.
What the evidence shows. The unauthorized return rate KRI shows status breach at n=440, consistent with the alert summary. The same evidence snapshot shows three other KRIs in breach status for this program: reserve_coverage_ratio at 0.467 (n=440), manual_review_aging_hours at 1151.6 (n=3), and sanctioned_country_transfers at 2 (n=966). Two additional KRIs sit at watch: hold_aging_hours (1369.7 hours, n=5) and pep_flagged_entities (1, n=30). The overall ACH return rate (2.5%, n=440) and administrative return rate (0.45%, n=440) are within normal range, indicating the breach is specific to unauthorized returns rather than a broad ACH processing issue.
What was checked. Reviewed the alert evidence block for the triggering KRI and threshold. Reviewed the full program KRI panel for co-occurring signals. Checked for prior dispositions on this program (none found) and for a hard signal or existing skoor band (none present, band unscored). Confirmed this alert concerns a rate metric, not a specific held transfer, so no transfer-release action applies.
What is recommended. Escalate. The unauthorized return rate breach does not stand alone: it co-occurs with a reserve coverage breach, a manual review aging breach, and two sanctioned country transfers on the same program within the same evidence window. This combination points to a pattern broader than a single KRI threshold crossing and warrants review beyond this individual alert, including the underlying originator files driving unauthorized returns and the sanctioned-country transfer records.
- Recommendation
- escalate
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-18 00:17Z
- Rationale
- ach_unauthorized_return_rate is confirmed in breach status at 1.14% against a 0.5% threshold on n=440, matching the alert summary.
- Three additional program KRIs (reserve_coverage_ratio, manual_review_aging_hours, sanctioned_country_transfers) show breach status in the same evidence snapshot, indicating multiple concurrent issues rather than an isolated metric.
- No prior dispositions exist for this program, so there is no history to indicate this is a known, already-addressed condition.
- The alert concerns a program-level rate KRI, not a specific held transfer, so 'release' does not apply and 'close' is not supported given the co-occurring breaches.
- Confidence is held at moderate because the context does not include the underlying transaction-level detail for the sanctioned country transfers or the specific unauthorized return cases, limiting certainty about root cause.
Evidence
{
"n": 440,
"kri": "ach_unauthorized_return_rate",
"unit": "ratio",
"value": 0.011363636363636364,
"status": "breach",
"threshold": 0.005,
"routeReason": "detector always reviewed"
}
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.