SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

First transfer to a new counterparty, $857.09, above the program's 95th percentile.

Detector
first_time_counterparty_large
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_ar15193w3xz
Transfer
acht_sim_harb_ar15193w3xz · $857.09 · ach outgoing
Skoor at alert
null unscored
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. A detector flagged transfer acht_sim_harb_ar15193w3xz as a first-time payment to a new counterparty in an amount ($857.09) above the program's 95th percentile threshold ($784.96). The alert was auto-routed for review under the program's standing rule that this detector type always gets reviewed. What the evidence shows. The transfer is an outgoing ACH credit of $857.09, status COMPLETED, with no return code recorded, created 2026-07-10. The two triggering signals are counterparty.first_time (+10) and counterparty.first_time_and_large (+15); the transfer itself carries no skoor (band unscored, n=14, confidence null), so no independent risk score corroborates the signals. The originating entity, Heath Holdings 119, is VERIFIED, not flagged high risk, not PEP, has no open review reasons, and was screened on 2026-09-01, after this transfer's creation date. The counterparty's country is unknown, but no sanctioned-country or geographic signal fired. Program-level KRIs show ach_unauthorized_return_rate and manual_review_aging_hours in breach and several others in watch status (hold_aging_hours, pep_flagged_entities, high_risk_entity_share), but none of these are tied to this specific transfer or entity in the evidence provided. What was checked. Transfer status and return code, entity verification and risk/PEP flags, screening recency relative to transfer date, program KRIs for related patterns (sanctioned country transfers, ach return rates, high-risk entity share), and prior dispositions on this alert (none exist). What is recommended. Close the alert. The transfer has already completed with no return or reversal, the entity is verified with no risk or PEP indicators, and the only evidence is a first-time/large-amount detector trigger with no corroborating skoor or KRI linkage. There is nothing in the evidence to hold on, since the funds have already settled, and no basis to escalate absent a broader pattern tied to this entity or counterparty.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is COMPLETED with no return code, so a hold/release recommendation does not apply.
  • Entity is VERIFIED, not high risk, not PEP, with no open review reasons and screening postdating the transfer.
  • Triggering signals (first_time, first_time_and_large) are the only evidence; transfer skoor is null/unscored (n=14), limiting confidence in the alert's own risk assessment.
  • Program KRI breaches (ach_unauthorized_return_rate, manual_review_aging_hours) are program-wide metrics with no direct link shown to this transfer or entity, so they do not support escalation on this alert alone.
  • No prior dispositions exist to indicate a repeated or worsening pattern for this entity or counterparty.
  • Confidence is moderate rather than high because the counterparty's country is unknown and the transfer's own risk band is unscored, leaving some evidentiary thinness.

Evidence

{
  "n": 14,
  "band": "unscored",
  "skoor": null,
  "signals": [
    {
      "code": "counterparty.first_time",
      "detail": "first transfer with this counterparty",
      "weight": 10
    },
    {
      "code": "counterparty.first_time_and_large",
      "detail": "amount above the program p95 (78496)",
      "weight": 15
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
counterparty.first_time+10first transfer with this counterparty
counterparty.first_time_and_large+15amount above the program p95 (78496)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.