Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $240.94 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_b4ftxtav8wn
- Transfer
- acht_sim_harb_b4ftxtav8wn · $240.94 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert ca0c1310-ccc4-4d6e-adf4-caa3a7b4af1e was opened on 2026-09-17 for an outgoing ACH credit transfer (acht_sim_harb_b4ftxtav8wn) of $240.94 under the Harbor Marketplace Payouts program. The transfer risk score (skoor) was 40, placing it in the review band, driven by a single signal: the counterparty has 2 prior unauthorized returns.
What the evidence shows. The transfer itself settled with no return code, meaning no unauthorized return occurred on this specific transaction. The counterparty (cpty_sim_harb_39i9ftby3xi) has an unknown country and a history of 2 prior unauthorized returns, which is the sole basis for the score. The originating entity, Alder Co 10, is a verified business with no high-risk flag, no PEP status, no open review reasons, and screening current as of 2026-09-05. Program-level KRIs show ach_unauthorized_return_rate at 0.0076 (n=793) is flagged as a breach, and manual_review_aging_hours (1438 hours, n=15) is also flagged as a breach. Other KRIs (velocity, concentration, sanctioned-country transfers, verification denial rate) are within normal range.
What was checked. Reviewed the transfer status and return code, the entity's verification and screening status, the counterparty's return history as reflected in the signal, and the program's KRI panel for corroborating patterns. No prior dispositions exist for this alert.
What is recommended. The transfer has already settled and there is no return on this transaction, so no funds are held or awaiting release. However, the program's ach_unauthorized_return_rate KRI is independently flagged as a breach, and this alert's own signal (counterparty with 2 prior unauthorized returns) is consistent with that program-level pattern. This combination suggests the counterparty-return issue may extend beyond this single alert and warrants a person to review whether other transfers to or from this counterparty, or similar counterparties, show the same pattern.
- Recommendation
- escalate
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer acht_sim_harb_b4ftxtav8wn is SETTLED with return code none, so there is no current fund-movement issue on this specific alert.
- The only risk signal is counterparty_prior_unauthorized (2 prior unauthorized returns, weight 40), which is a counterparty-level history signal, not a defect on this transfer.
- Program KRI ach_unauthorized_return_rate is flagged as a breach (0.0076, n=793), indicating a program-wide pattern consistent with the alert's signal.
- The originating entity is fully verified, not high risk, not PEP, and screening is current, so no entity-level concern justifies escalation on its own.
- Because the evidence points to a broader program-level pattern rather than an isolated transaction issue, escalation rather than close or hold is appropriate.
- Release is not applicable since the transfer was never held pending this alert.
Evidence
{
"n": 1988,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "2 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 3 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.