SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Transaction Risk Skoor 90 (hold band) on a $2,400.00 ach transfer: entity.denied, entity.high_risk, amount.gt_3x_median.

Detector
skoor_hold
Severity
high
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_1x9rcs6c9kf
Transfer
acht_sim_harb_1x9rcs6c9kf · $2,400.00 · ach outgoing
Skoor at alert
90 hold
Hard signal
yes
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert bbfe17b1-b087-4203-9f10-9031efc1c8b5 fired on an outgoing ACH transfer (acht_sim_harb_1x9rcs6c9kf) for $2,400.00 tied to program Harbor Marketplace Payouts. The transfer risk skoor was 90, placing it in the hold band, with a hard signal present. The alert was routed for review on 2026-09-17T19:32:34.611Z. What the evidence shows. The skoor of 90 was driven by three signals: entity.denied (hard, weight 60) noting the counterparty entity failed verification with a DENIED outcome, entity.high_risk (weight 20), and amount.gt_3x_median (weight 10), since $2,400.00 exceeds 3x the program median of $414.30. The entity record (enti_sim_harb_130qwgg53wz, "Denied Origin 1") confirms verification status DENIED, high_risk true, and review reason sanctions_match, last screened 2026-06-24. Despite this, the transfer record shows status SETTLED with no return code, meaning the $2,400.00 already moved. Program-level KRIs show manual_review_aging_hours in breach (1438.05 hours, n=18) and ach_unauthorized_return_rate in breach (0.0090, n=890), alongside several watch-level metrics (hold_aging_hours, overdraft_events, card_fraud_declines, pep_flagged_entities, high_risk_entity_share). There are no prior dispositions on record for this alert or entity. What was checked. Reviewed the alert signals, the transfer record, the entity record, and program KRIs. Confirmed the transfer status is SETTLED, not held, so no funds are currently pending release. Confirmed the entity's verification denial and sanctions_match reason are recent (last screened three months prior to transfer creation) and not stale per stale_screening_share=0. Checked for prior dispositions on this alert or entity; none exist. What is recommended. Because the transfer already settled, there are no funds to hold or release under this alert. However, a settled transfer to/from an entity with a DENIED verification and sanctions_match reason, combined with two program KRIs in breach (manual_review_aging_hours, ach_unauthorized_return_rate) and several related metrics at watch level, indicates this alert should not be closed on its own. This warrants escalation to determine whether other transactions involving this entity or similar denied entities were also allowed to settle, and whether the program's manual review process is failing to intercept hard-signal alerts before settlement.
Recommendation
escalate
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:33Z
Rationale
  • Transfer status is SETTLED with no return code, so hold/release actions do not apply; funds already moved despite a hard-signal, hold-band alert.
  • Entity verification is DENIED with review reason sanctions_match and high_risk true, which is a hard signal (weight 60) and the primary driver of the skoor 90 hold-band result.
  • Program KRIs show manual_review_aging_hours and ach_unauthorized_return_rate in breach status, suggesting broader review-process or return-handling issues beyond this single alert.
  • No prior dispositions exist for this alert or entity, so there is no established pattern of handling to rely on.
  • Confidence is moderate (0.62) because while the transfer and entity data are clear, the context does not show whether other transfers to this same entity exist or whether the settlement was itself an error worth deeper investigation; a person should confirm scope.

Evidence

{
  "n": 1737,
  "band": "hold",
  "skoor": 90,
  "signals": [
    {
      "code": "entity.denied",
      "hard": true,
      "detail": "entity verification DENIED",
      "weight": 60
    },
    {
      "code": "entity.high_risk",
      "detail": "entity marked high risk by screening",
      "weight": 20
    },
    {
      "code": "amount.gt_3x_median",
      "detail": "amount > 3× program median (41430)",
      "weight": 10
    }
  ],
  "autoHold": true,
  "confidence": 0.715,
  "routeReason": "hard signal"
}

Skoor signals

SignalWeightHardDetail
entity.denied+60yesentity verification DENIED
entity.high_risk+20entity marked high risk by screening
amount.gt_3x_median+10amount > 3× program median (41558)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.