Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $628.36 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_bbslsie66g
- Transfer
- acht_sim_harb_bbslsie66g · $628.36 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert ae03e63f-7f4d-4d77-823b-c624ed37318a fired on outgoing ACH transfer acht_sim_harb_bbslsie66g for $628.36, already SETTLED, under the Harbor Marketplace Payouts program. The detector skoor_review scored the transfer 40 (review band) based on one prior unauthorized return recorded against the counterparty (signal returns.counterparty_prior_unauthorized, weight 40, confidence 1, n=805).
What the evidence shows. The transfer itself carries no return code and settled normally. The originating entity, Elm Partners 116, is VERIFIED, not flagged high risk, not PEP, and was screened as recently as 2026-06-23. The only adverse signal is the counterparty's single prior unauthorized return; the counterparty's country is unknown, and no further counterparty history is provided. At the program level, ach_unauthorized_return_rate is flagged as a breach (0.85%, n=236) and manual_review_aging_hours is also a breach (1438 hours average, n=5), while pep_flagged_entities (1/30) and high_risk_entity_share (6.7%) are at watch. Other KRIs (frozen_accounts, overdraft_events, sanctioned_country_transfers, reserve_coverage_ratio, administrative_return_rate, concentration) are within normal range.
What was checked. Reviewed the transfer record, the single risk signal and its weight/confidence, the entity's verification and screening status, and the full set of program KRIs for corroborating or contradicting patterns. No prior dispositions exist for this alert or entity.
What is recommended. The transfer has already settled, so there is no fund movement to hold or release. The individual alert evidence (one prior unauthorized return, verified low-risk entity) is not on its own sufficient to require further account-level action. However, the program-level breach in ach_unauthorized_return_rate combined with the manual_review_aging_hours breach indicates the review queue is running behind and unauthorized-return incidence is above the program's own threshold. This combination suggests the pattern extends beyond this single alert and should be escalated for a program-level look at unauthorized-return handling and review backlog, rather than closed as an isolated item.
- Recommendation
- escalate
- Confidence
- 0.58
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer is already SETTLED; no funds are being held, so hold/release do not apply.
- Single alert signal (prior unauthorized return, weight 40) is moderate and tied to a counterparty with unknown country and no further detail provided.
- Subject entity is verified, not high-risk, not PEP, recently screened — nothing in the entity record independently warrants escalation.
- Program KRIs show two breaches (ach_unauthorized_return_rate, manual_review_aging_hours) that are consistent with the alert's underlying signal type and suggest a broader pattern rather than an isolated event.
- Watch-level KRIs (pep_flagged_entities, high_risk_entity_share) add mild corroboration but are not breaches on their own.
- Evidence on the counterparty is thin (country unknown, no return code detail beyond count), which limits confidence in a precise root cause.
Evidence
{
"n": 805,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.