Alert · reviewed · held
Counterparty Receiver 3 entered the hold band (Skoor 80, n=36): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.new.
- Detector
- counterparty_hold
- Severity
- high
- Program
- Meridian Remit (simulated)
- Subject
- counterparty cpty_sim_meri_76hym53h9pv
- Transfer
- —
- Skoor at alert
- 80 hold
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Counterparty cpty_sim_meri_76hym53h9pv, tracked under Meridian Remit (simulated), tripped the counterparty_hold detector and entered the hold band on 2026-09-17T19:32:13.453Z. The alert was auto-held and routed to review because the detector is not auto-closable.
What the evidence shows. Skoor is 80 against an n of 36 transactions. Four signals fed the score: 2 unauthorized returns drawn (weight 40), an unauthorized rate of 2/36 that exceeds the network threshold (weight 15), a return rate of 3/36 (weight 15), and counterparty newness with first seen 0 days ago (weight 10). Hard_signal is marked false and detector confidence is 0.604, indicating the score is composite rather than a single definitive trigger. There are no prior dispositions on this alert.
What was checked. I reviewed the alert evidence block, the counterparty signal weights, and the program-level KRI panel for Meridian Remit. The program shows several breaches concurrent with this alert: reserve_coverage_ratio at 0.48 (breach), manual_review_aging_hours at 1146.87 (breach), ach_unauthorized_return_rate at 0.0118 (breach), and sanctioned_country_transfers at 2 of n=923 (breach), alongside watch-level hold_aging_hours (1364.98) and pep_flagged_entities (1 of 30). These are program-wide metrics and are not individually attributed to this counterparty in the evidence provided, so I cannot confirm this alert is the cause or a component of those breaches, only that they coexist in the same program and period.
What is recommended. Hold this counterparty's funds pending review. The combination of unauthorized returns, an above-threshold unauthorized rate, and zero-day counterparty age is sufficient to warrant a person's look before any transfer to or from this counterparty proceeds. A reviewer should also check whether this counterparty contributes to the program-level unauthorized-return and sanctioned-country breaches, since those are open at the program level and this alert is thematically related, though the evidence here does not establish a direct link.
- Recommendation
- hold
- Confidence
- 0.60
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Skoor 80 places the counterparty in the hold band with autoHold true, and no prior disposition has reviewed or cleared it.
- Two unauthorized returns and an above-threshold unauthorized rate are transaction-level facts drawn directly from the evidence, not inferred.
- Counterparty newness (first seen 0d ago) compounds the risk of an unauthorized-return pattern before payment history exists.
- Hard_signal is false and detector confidence is 0.604, so this is a composite score rather than a certain violation, which argues against outright closure without review.
- Program KRIs show concurrent breaches in ach_unauthorized_return_rate, sanctioned_country_transfers, reserve_coverage_ratio, and manual_review_aging_hours, but the evidence does not tie this specific counterparty to those metrics, so escalation to a program-wide pattern is not yet supported and is noted only as a follow-up check.
Evidence
{
"n": 36,
"band": "hold",
"skoor": 80,
"signals": [
{
"code": "counterparty.unauthorized_returns",
"detail": "drew 2 unauthorized return(s)",
"weight": 40
},
{
"code": "counterparty.unauthorized_rate",
"detail": "unauthorized rate 2/36 above the network threshold",
"weight": 15
},
{
"code": "counterparty.return_rate",
"detail": "return rate 3/36",
"weight": 15
},
{
"code": "counterparty.new",
"detail": "first seen 0d ago",
"weight": 10
}
],
"version": "crs-v1",
"autoHold": true,
"confidence": 0.604,
"routeReason": "detector not auto-closable"
}
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.