SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $2,866.77 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_18uudqm22ss
Transfer
acht_sim_nort_18uudqm22ss · $2,866.77 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert c86ffae2-29a7-42da-9ee5-5cea54f43bca fired on outgoing ACH transfer acht_sim_nort_18uudqm22ss for $2866.77, flagged by the skoor_review detector at a risk score of 40 (review band) due to a single signal: the counterparty cpty_sim_nort_25c8izfo4a has one prior unauthorized return on record. What the evidence shows. The transfer has already settled; there is no return code on this transfer itself. The only signal driving the alert is returns.counterparty_prior_unauthorized, weighted 40, based on one prior unauthorized return for this counterparty. The hard_signal flag is false, and detector confidence is 1 on a population of 1053. The originating entity, Larch Studio 011, is a verified US business with no high-risk flag, no PEP status, and no open review reasons, last screened 2026-08-14. Program-level KRIs show ach_unauthorized_return_rate at 0 across 444 transfers and ach_overall_return_rate at 1.13%, both in the ok range, indicating no broader pattern of unauthorized returns tied to this program. Counterparty concentration and velocity vs. declared volume are also within normal ranges. Manual_review_aging_hours is in breach (1434.7 hours, n=8), but this is a separate program-level metric not tied to this specific alert's counterparty or entity. What was checked. Transfer status and return code, entity verification status and screening date, program-level KRIs for unauthorized and overall return rates, counterparty concentration, velocity vs. declared volume, and prior dispositions on this alert (none found). What is recommended. The transfer has already settled, so there are no funds to hold or release. The single underlying signal is one prior unauthorized return for this counterparty, which is a low-weight, single-occurrence data point. The originating entity is verified with no other risk indicators, and program-wide return-rate KRIs show no pattern of unauthorized returns. Nothing in the evidence indicates a need for a person to intervene on this specific alert. Recommend closing the alert, noting the counterparty's prior unauthorized return for future reference should additional returns occur.
Recommendation
close
Confidence
0.68
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer status is SETTLED with no return code on this transaction, so no funds are pending or in a holdable state.
  • The alert rests on a single signal (one prior unauthorized return for the counterparty), with hard_signal false and no corroborating entity or program risk flags.
  • Originating entity is VERIFIED, not high risk, not PEP, with no open review reasons.
  • Program KRIs for unauthorized and overall ACH return rates are within normal (ok) ranges, indicating no broader pattern connecting to this alert.
  • The manual_review_aging_hours KRI breach is a program-level metric unrelated to this specific counterparty or transfer and does not by itself change the disposition of this alert.
  • No prior dispositions exist on this alert to indicate escalation history.

Evidence

{
  "n": 1053,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.