Alert · reviewed · held
Transaction Risk Skoor 55 (hold band) on a $9,457.89 ach transfer: amount.gt_10x_median, structuring.pattern.
- Detector
- skoor_hold
- Severity
- high
- Program
- Meridian Remit (simulated)
- Subject
- transfer acht_sim_meri_am0xo0b1cdr
- Transfer
- acht_sim_meri_am0xo0b1cdr · $9,457.89 · ach outgoing
- Skoor at alert
- 55 hold
- Hard signal
- yes
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert a9ca1e31-6540-4cad-b058-c90d0b021558 fired on transfer acht_sim_meri_am0xo0b1cdr, an outgoing ACH debit of $9,457.89 from Meridian Remit (simulated). The transaction risk skoor was 55, placing it in the hold band, with a hard signal present. The alert was auto-held per the evidence but the transfer record shows status SETTLED, meaning the funds have already moved.
What the evidence shows. Two signals drove the score: amount.gt_10x_median (weight 20, amount exceeds 10x the program median of $674.32) and structuring.pattern (weight 35, hard signal, two debits just under $10,000 within 24 hours). The structuring signal is marked hard with confidence 1.0 across n=886 observations. The counterparty cpty_sim_meri_73i0nx8nc6o has an unknown country, and the transfer carries no return code. The entity Meridian Remit is VERIFIED, not high risk, not PEP, screened 2026-07-29. Program-level KRIs show three breaches: reserve_coverage_ratio (0.648), manual_review_aging_hours (1146.87), sanctioned_country_transfers (1 of 746), and ach_unauthorized_return_rate (0.0115), alongside two watch-level KRIs (hold_aging_hours, pep_flagged_entities).
What was checked. Reviewed the transfer record, entity verification status, program declared volume and KRI panel, and prior dispositions. No prior dispositions exist for this alert or entity. The transfer status is SETTLED, so there is no pending hold to release. Counterparty country is unknown, which limits assessment of the sanctioned_country_transfers breach in relation to this specific transfer.
What is recommended. The transfer has already settled, so no funds can be held or released on it. However, the hard structuring signal (two sub-$10,000 debits within 24 hours), combined with program-level breaches in sanctioned_country_transfers, reserve_coverage_ratio, and ach_unauthorized_return_rate, indicates a pattern that extends beyond this single alert. This should be escalated for a person to review the program's broader transaction pattern and the counterparty relationship, including confirmation of the counterparty's country.
- Recommendation
- escalate
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Hard signal structuring.pattern (weight 35, confidence 1.0) indicates deliberate sub-threshold structuring, not a one-off anomaly.
- Transfer status is SETTLED, so 'hold' or 'release' recommendations do not apply to this transaction.
- Three program KRIs are in breach (reserve_coverage_ratio, ach_unauthorized_return_rate, sanctioned_country_transfers) and two are in watch, suggesting risk beyond this single alert.
- Counterparty country is unknown, which limits confirmation of any direct sanctioned-country link and lowers confidence.
- No prior dispositions exist to indicate this pattern has already been reviewed or resolved.
Evidence
{
"n": 886,
"band": "hold",
"skoor": 55,
"signals": [
{
"code": "amount.gt_10x_median",
"detail": "amount > 10× program median (67432)",
"weight": 20
},
{
"code": "structuring.pattern",
"hard": true,
"detail": "2 debits just under $10,000 in 24h",
"weight": 35
}
],
"autoHold": true,
"confidence": 1,
"routeReason": "hard signal"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| amount.gt_10x_median | +20 | amount > 10× program median (66942) | |
| structuring.pattern | +35 | yes | 2 debits just under $10,000 in 24h |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.