SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

First transfer to a new counterparty, $4,103.93, above the program's 95th percentile.

Detector
first_time_counterparty_large
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_9m9w0v0bie
Transfer
acht_sim_nort_9m9w0v0bie · $4,103.93 · ach outgoing
Skoor at alert
25 clear
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An outgoing ACH debit of $4,103.93 from Northwind Payroll to a new counterparty triggered a first-time-large-counterparty alert. The transfer completed and no prior dispositions exist for this subject. What the evidence shows. The transfer skoor is 25, band clear, with confidence 0.6225 over n=121. Two signals fired: counterparty.first_time (weight 10) and counterparty.first_time_and_large (weight 15), the latter because the amount exceeds the program's p95 of $3,726.40. The transfer status is COMPLETED with no return code, so no return or reversal has occurred. The entity behind the transfer, Fern Studio 017, is VERIFIED, not high risk, not PEP, with no review reasons, last screened 2026-08-19. The counterparty's country is unknown, which is a gap but not flagged as sanctioned or high risk in the evidence provided. What was checked. Alert evidence and skoor, transfer status and return code, program declared volume ($2,500,000/month) against the transfer size, entity verification and screening status, and program KRIs. KRIs show ach_overall_return_rate, ach_unauthorized_return_rate, and sanctioned_country_transfers all at ok/zero. manual_review_aging_hours is flagged breach (1434.7 hours, n=12) and hold_aging_hours, pep_flagged_entities, and high_risk_entity_share are at watch, but none of these are specific to this alert's subject or entity. What is recommended. Close this alert. The transfer already completed, so hold and release do not apply. The entity is verified with clean screening, the transfer produced no return, and the band is clear. The elevated amount relative to p95 is the sole driver and is explainable as a first-time payroll-adjacent transfer at declared volume scale. The program-level manual_review_aging_hours breach is a separate operational KRI not tied to this specific transfer and does not change the disposition of this alert; it may warrant separate attention outside this alert.
Recommendation
close
Confidence
0.68
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is COMPLETED with return code none, indicating no settlement failure.
  • Skoor band is clear (25) with confidence 0.6225 over a reasonable sample (n=121).
  • Entity is VERIFIED, not high risk, not PEP, no review reasons, screened within the last month.
  • Program KRIs for return rates and sanctioned-country transfers are all ok or zero, showing no pattern of elevated risk at the program level tied to this transfer type.
  • Counterparty country is unknown in the evidence, which limits full certainty; confidence is set at 0.68 rather than higher to reflect this gap.
  • manual_review_aging_hours breach and other watch-level KRIs are program-wide and not linked in the evidence to this specific alert or entity, so they do not by themselves justify escalation of this alert.

Evidence

{
  "n": 121,
  "band": "clear",
  "skoor": 25,
  "signals": [
    {
      "code": "counterparty.first_time",
      "detail": "first transfer with this counterparty",
      "weight": 10
    },
    {
      "code": "counterparty.first_time_and_large",
      "detail": "amount above the program p95 (372640)",
      "weight": 15
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
counterparty.first_time+10first transfer with this counterparty
counterparty.first_time_and_large+15amount above the program p95 (373182)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.