SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $825.97 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_briey55o8to
Transfer
acht_sim_harb_briey55o8to · $825.97 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert b6b6b99c-c1a1-4bf8-8734-7805e542b57f fired on an $825.97 outgoing ACH transfer (acht_sim_harb_briey55o8to) under the Harbor Marketplace Payouts program. The detector skoor_review scored the transfer 40 (review band) based on a single signal: the counterparty has one prior unauthorized return. What the evidence shows. The transfer is already SETTLED with no return code recorded, so no funds are currently held or reversible through this alert. The originating entity (Reconciliation Agent (Harbor)) is VERIFIED, not high risk, not PEP, and was screened recently (2026-08-21). The transfer-level skoor is 40 with confidence 1 on n=1951, driven entirely by the counterparty_prior_unauthorized signal (weight 40, one prior unauthorized return). At the program level, ach_unauthorized_return_rate is flagged as a breach (0.78%, n=767), which is consistent with the type of signal this alert raised. Other KRIs (manual_review_aging_hours, hold_aging_hours, pep_flagged_entities, high_risk_entity_share) are at watch or breach but are not directly tied to this specific transfer's evidence. What was checked. Transfer status and return code, entity verification and risk flags, the single risk signal and its weight, and program-level KRIs for corroborating patterns. Prior dispositions: none exist for this alert. What is recommended. This transfer has already settled with no return, so there is nothing to hold or release. However, the ach_unauthorized_return_rate KRI breach at the program level aligns with the specific counterparty-return signal driving this alert, indicating this may not be an isolated case. A person should review whether this counterparty or similar counterparty patterns are contributing to the program-wide unauthorized-return breach.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is SETTLED with no return code, so hold/release actions do not apply to this transfer.
  • The alert's sole signal (counterparty_prior_unauthorized, weight 40) matches the program's KRI breach on ach_unauthorized_return_rate, suggesting a possible pattern beyond this single alert.
  • Entity-level checks (verification, PEP, high-risk flag, screening recency) show no independent concern that would justify escalation on its own.
  • No prior dispositions exist to indicate this has already been reviewed as part of the broader pattern.
  • Evidence is limited to one transfer and one KRI snapshot; a person should confirm whether the KRI breach traces back to this counterparty or is broader before taking action.

Evidence

{
  "n": 1951,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+402 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.