SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Counterparty Receiver 21 entered the hold band (Skoor 90, n=10): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.review_share, counterparty.new.

Detector
counterparty_hold
Severity
high
Program
Northwind Payroll (simulated)
Subject
counterparty cpty_sim_nort_5a6oup6d8m
Transfer
Skoor at alert
90 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Counterparty cpty_sim_nort_5a6oup6d8m (Counterparty Receiver 21) was placed into the hold band by the counterparty_hold detector on 2026-09-17T19:31:19.298Z. The alert fired at skoor 90 against a hold threshold, based on a population of n=10 transactions, and routed to review because the detector is not auto-closable. autoHold is true, meaning funds tied to this counterparty are currently held. What the evidence shows. The evidence lists five contributing signals: one unauthorized return out of 10 transactions (weight 40, the largest single contributor), an unauthorized rate of 1/10 flagged as above the network threshold (weight 15), a return rate of 1/10 (weight 15), an 80% share of transactions already in the review band (weight 10), and the counterparty being newly seen as of 0 days ago (weight 10). The detector's own confidence field is 0.24, and hard_signal is false, indicating the score is driven by a thin sample rather than a corroborated high-certainty event. At the program level, Northwind Payroll's ach_unauthorized_return_rate is 0 across n=338, so this counterparty's single unauthorized return stands out against an otherwise clean program population. Program KRIs also show manual_review_aging_hours in breach (1434.68 hours, n=7) and pep_flagged_entities and high_risk_entity_share both at watch, but none of these are tied to this specific counterparty in the evidence provided. What was checked. Reviewed the alert evidence block (signals, weights, n, skoor, band, confidence), the program declared volume and rails (ACH, US), and the program KRI panel for any counterparty-specific or program-wide corroboration. Checked prior dispositions for this subject: none exist. No transaction-level detail beyond the aggregate n=10 sample was available in the context. What is recommended. Hold. Do not release funds to or from this counterparty pending review. The alert is driven by a single unauthorized return in a very small sample (n=10) from a counterparty first seen the same day, which is consistent with a hold-band score but does not by itself establish a pattern warranting escalation beyond this alert. A person should confirm the nature of the unauthorized return (true unauthorized debit vs. administrative/other) and decide whether to maintain the hold, request additional counterparty verification, or clear it once reviewed.
Recommendation
hold
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • autoHold is true and hard_signal is false; the score rests on one unauthorized return in a 10-transaction sample, which needs human confirmation before funds move.
  • Detector confidence is explicitly low (0.24), and the counterparty is brand new (0 days), so there is no track record to independently corroborate the signal.
  • Program-wide ach_unauthorized_return_rate is 0 across 338 transactions, making this counterparty's single unauthorized return a notable outlier worth a person's review rather than an automatic close.
  • No prior dispositions exist for this subject, and the evidence does not show a broader pattern across multiple counterparties, so escalation beyond this alert is not supported by the given context.
  • Program KRI breaches (manual_review_aging_hours) and watch-level flags (pep_flagged_entities, high_risk_entity_share) are noted for context but are not linked in the evidence to this specific counterparty, so they do not change the recommendation for this alert alone.

Evidence

{
  "n": 10,
  "band": "hold",
  "skoor": 90,
  "signals": [
    {
      "code": "counterparty.unauthorized_returns",
      "detail": "drew 1 unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "counterparty.unauthorized_rate",
      "detail": "unauthorized rate 1/10 above the network threshold",
      "weight": 15
    },
    {
      "code": "counterparty.return_rate",
      "detail": "return rate 1/10",
      "weight": 15
    },
    {
      "code": "counterparty.review_share",
      "detail": "80% in the review band",
      "weight": 10
    },
    {
      "code": "counterparty.new",
      "detail": "first seen 0d ago",
      "weight": 10
    }
  ],
  "version": "crs-v1",
  "autoHold": true,
  "confidence": 0.24,
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.