SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $264.41 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_56nj34rz5bv
Transfer
acht_sim_harb_56nj34rz5bv · $264.41 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An ACH outgoing transfer of $264.41 from entity Fern Studio 15 (program Harbor Marketplace Payouts) was flagged by the skoor_review detector at a risk score of 40, placing it in the review band. The single triggering signal is a prior unauthorized return associated with the counterparty. What the evidence shows. The evidence shows one signal: returns.counterparty_prior_unauthorized, weighted 40, described as '1 prior unauthorized return(s)' for counterparty cpty_sim_harb_gzii64r41f. The transfer itself settled with no return code, meaning this specific transfer was not returned. The entity Fern Studio 15 is VERIFIED, not high risk, not PEP, with no review reasons and screening current as of 2026-07-02. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=99, ok) and ach_overall_return_rate at 0 (n=99, ok), indicating no broader unauthorized-return pattern at the program level. Two KRIs are flagged watch (pep_flagged_entities=1 of 30, high_risk_entity_share=0.067) and one is a breach (manual_review_aging_hours=1438.02 hours, n=2), but none of these tie directly to this entity or this counterparty. There are no prior dispositions on this alert. What was checked. Checked the transfer status (SETTLED, no return code), entity verification status and screening date, program declared volume and rails, and program-level KRI panel for return-rate and concentration patterns. Checked for prior dispositions (none found). The counterparty's country is listed as unknown, and no additional detail on the prior unauthorized return (date, amount, or count beyond '1') is provided in the evidence. What is recommended. This transfer already settled and is not a held transfer, so no release action applies. The evidence is limited to a single prior unauthorized return on the counterparty with no further detail, and the entity itself carries no other risk indicators. Given the counterparty has a documented prior unauthorized return, a person should review the counterparty relationship before this or future transfers to the same counterparty, but nothing here shows a broader pattern warranting escalation. Recommend hold for review of the counterparty relationship rather than close, since the underlying concern (counterparty's unauthorized return history) has not been addressed by a person.
Recommendation
hold
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:30Z
Rationale
  • The transfer is SETTLED with no return code, so 'release' does not apply since there is no held transfer.
  • The sole signal driving the alert is a prior unauthorized return on the counterparty, which is unresolved and undetailed in the evidence (no date, no amount given).
  • Entity-level indicators (VERIFIED, not high risk, not PEP, current screening) do not offset the counterparty-level concern, since the signal is about the counterparty, not the entity.
  • Program-level KRIs (ach_unauthorized_return_rate=0, ach_overall_return_rate=0) show no broader program pattern, arguing against escalation.
  • The manual_review_aging_hours breach (1438 hours, n=2) and watch-level PEP/high-risk-entity-share KRIs are program-wide figures not directly tied to this transfer or counterparty, so they inform context but do not independently justify escalation.
  • Confidence is moderate rather than high because the evidence on the prior unauthorized return lacks detail (no date or transaction reference), limiting full assessment of recency or materiality.

Evidence

{
  "n": 483,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.