SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $2,325.04 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_4lwa6uqg3de
Transfer
acht_sim_nort_4lwa6uqg3de · $2,325.04 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An outgoing ACH transfer of $2325.04 from Northwind Payroll to counterparty cpty_sim_nort_25c8izfo4a settled on 2026-09-08. The transaction risk skoor engine scored it 40 (review band) due to a single prior unauthorized return associated with this counterparty. What the evidence shows. The alert is driven by one signal: returns.counterparty_prior_unauthorized, weight 40, detail '1 prior unauthorized return(s)'. The transfer itself has no return code and settled normally. The originating entity, Payout Agent (Northwind), is VERIFIED, not high risk, not PEP, with no review reasons and screening current as of 2026-09-03. The counterparty's country is unknown, and no counterparty-level verification or history detail is provided beyond the single prior unauthorized return. Program-level KRIs show ach_unauthorized_return_rate at 0.0018 (ok) and ach_overall_return_rate at 0.0127 (ok), both within normal range, indicating this is not part of a broader return pattern at the program level. Two KRIs show breach/watch status not specific to this alert: manual_review_aging_hours is in breach (1434.7 hours, n=10) and hold_aging_hours is watch (518.3 hours, n=1), suggesting review queue backlog generally, not tied to this transfer. What was checked. Reviewed the transfer status, skoor signal detail, originating entity verification status and screening date, and program-level KRIs for unauthorized/overall return rates, high-risk entity share, and review aging. No prior dispositions exist for this alert. No further detail on the counterparty's identity, verification status, or the nature of its prior unauthorized return is available in the evidence provided. What is recommended. This transfer has already settled, so there is no transfer to hold or release. The single prior unauthorized return tied to this counterparty is a documented risk signal that a person should evaluate before this counterparty is used again, particularly since the counterparty's country and verification status are not established in the evidence. Program-level return rates do not indicate a broader pattern. Recommend a person reviews the counterparty relationship; this does not meet the bar for close given the unresolved counterparty risk signal, but it also does not show a broader pattern warranting escalation.
Recommendation
hold
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Single signal driving alert: one prior unauthorized return for this counterparty, weight 40, review band (not auto-closable per detector).
  • Transfer already settled with no return code on this specific transaction, so 'hold' here refers to a person reviewing before further transactions with this counterparty, not to funds movement on this settled transfer.
  • Originating entity is verified, low risk, recently screened, which reduces concern on the sending side.
  • Counterparty country is unknown and no counterparty verification details are in evidence, leaving the underlying risk signal unresolved.
  • Program KRIs for unauthorized and overall ACH return rates are both in the 'ok' range (0.0018 and 0.0127 respectively), which weighs against escalating this as a program-wide pattern.
  • No prior dispositions exist to inform whether this counterparty has been reviewed before.

Evidence

{
  "n": 1278,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.