SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Counterparty Receiver 3 entered the hold band (Skoor 80, n=36): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.new.

Detector
counterparty_hold
Severity
high
Program
Meridian Remit (simulated)
Subject
counterparty cpty_sim_meri_76hym53h9pv
Transfer
Skoor at alert
80 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Counterparty cpty_sim_meri_76hym53h9pv, tracked under Meridian Remit (simulated), tripped the counterparty_hold detector and entered the hold band on 2026-09-17T19:32:13.453Z. The alert was auto-held and routed to review because the detector is not auto-closable. What the evidence shows. Skoor is 80 against an n of 36 transactions. Four signals fed the score: 2 unauthorized returns drawn (weight 40), an unauthorized rate of 2/36 that exceeds the network threshold (weight 15), a return rate of 3/36 (weight 15), and counterparty newness with first seen 0 days ago (weight 10). Hard_signal is marked false and detector confidence is 0.604, indicating the score is composite rather than a single definitive trigger. There are no prior dispositions on this alert. What was checked. I reviewed the alert evidence block, the counterparty signal weights, and the program-level KRI panel for Meridian Remit. The program shows several breaches concurrent with this alert: reserve_coverage_ratio at 0.48 (breach), manual_review_aging_hours at 1146.87 (breach), ach_unauthorized_return_rate at 0.0118 (breach), and sanctioned_country_transfers at 2 of n=923 (breach), alongside watch-level hold_aging_hours (1364.98) and pep_flagged_entities (1 of 30). These are program-wide metrics and are not individually attributed to this counterparty in the evidence provided, so I cannot confirm this alert is the cause or a component of those breaches, only that they coexist in the same program and period. What is recommended. Hold this counterparty's funds pending review. The combination of unauthorized returns, an above-threshold unauthorized rate, and zero-day counterparty age is sufficient to warrant a person's look before any transfer to or from this counterparty proceeds. A reviewer should also check whether this counterparty contributes to the program-level unauthorized-return and sanctioned-country breaches, since those are open at the program level and this alert is thematically related, though the evidence here does not establish a direct link.
Recommendation
hold
Confidence
0.60
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Skoor 80 places the counterparty in the hold band with autoHold true, and no prior disposition has reviewed or cleared it.
  • Two unauthorized returns and an above-threshold unauthorized rate are transaction-level facts drawn directly from the evidence, not inferred.
  • Counterparty newness (first seen 0d ago) compounds the risk of an unauthorized-return pattern before payment history exists.
  • Hard_signal is false and detector confidence is 0.604, so this is a composite score rather than a certain violation, which argues against outright closure without review.
  • Program KRIs show concurrent breaches in ach_unauthorized_return_rate, sanctioned_country_transfers, reserve_coverage_ratio, and manual_review_aging_hours, but the evidence does not tie this specific counterparty to those metrics, so escalation to a program-wide pattern is not yet supported and is noted only as a follow-up check.

Evidence

{
  "n": 36,
  "band": "hold",
  "skoor": 80,
  "signals": [
    {
      "code": "counterparty.unauthorized_returns",
      "detail": "drew 2 unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "counterparty.unauthorized_rate",
      "detail": "unauthorized rate 2/36 above the network threshold",
      "weight": 15
    },
    {
      "code": "counterparty.return_rate",
      "detail": "return rate 3/36",
      "weight": 15
    },
    {
      "code": "counterparty.new",
      "detail": "first seen 0d ago",
      "weight": 10
    }
  ],
  "version": "crs-v1",
  "autoHold": true,
  "confidence": 0.604,
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.