Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $944.92 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Northwind Payroll (simulated)
- Subject
- transfer acht_sim_nort_8wgca6jr2mb
- Transfer
- acht_sim_nort_8wgca6jr2mb · $944.92 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Transfer acht_sim_nort_8wgca6jr2mb, a $944.92 outgoing ACH credit under the Northwind Payroll program, was routed to review after scoring 40 (review band) on the transaction risk skoor. The single contributing signal was returns.counterparty_prior_unauthorized, reflecting one prior unauthorized return associated with the counterparty. The detector flagged the alert because it is not auto-closable, not because the skoor exceeded an auto-escalation threshold.
What the evidence shows. The transfer itself settled with no return code (return code: none), so no unauthorized or administrative return occurred on this transaction. The skoor is based on a single historical signal (weight 40, n=956, confidence 1) with hard_signal false, meaning the review-band placement rests entirely on one prior unauthorized return elsewhere in the counterparty's history, not on this transfer's outcome. The subject entity, Dune LLC 03, is VERIFIED, not high risk, not PEP, with no open review reasons and screening current as of 2026-07-07. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=417) and sanctioned_country_transfers at 0 (n=850), with no indication of a broader unauthorized-return pattern tied to this counterparty or program. Two KRIs sit in watch (pep_flagged_entities, high_risk_entity_share) and one in breach (manual_review_aging_hours), but none of these are specific to this entity or transfer.
What was checked. Transfer status and return code, skoor composition and signal weights, entity verification status and screening recency, prior dispositions on this alert (none found), and program-level KRIs for unauthorized return rate, sanctioned country exposure, and concentration.
What is recommended. Close the alert. The transfer has already settled without a return, the entity is verified with no open review flags, and program-wide unauthorized return metrics show no pattern. The single prior-unauthorized-return signal is the sole basis for the review band and is not corroborated by any other evidence in this alert. A person should still confirm this reading before closing given the thinness of the underlying signal.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer status is SETTLED with return code none; no adverse outcome occurred on this specific transaction.
- Skoor rests on a single signal (one prior unauthorized return) with hard_signal false; no corroborating signals present.
- Subject entity is VERIFIED, not high risk, not PEP, with no open review reasons and recent screening.
- Program-level ach_unauthorized_return_rate is 0 (n=417) and sanctioned_country_transfers is 0 (n=850), showing no broader pattern.
- Funds already moved and no hold exists, so 'hold' or 'release' do not apply.
- Watch/breach KRIs (pep_flagged_entities, high_risk_entity_share, manual_review_aging_hours) are program-wide and not tied to this specific entity or transfer, so they do not independently justify escalation here.
Evidence
{
"n": 956,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.