SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $745.98 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_cfqxlhft926
Transfer
acht_sim_harb_cfqxlhft926 · $745.98 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert cbf95a3d-d3bc-48f2-a383-04a7162a4ab6 was raised by the skoor_review detector on outgoing ACH transfer acht_sim_harb_cfqxlhft926, a $745.98 debit under Harbor Marketplace Payouts. The transfer scored 40 (review band, hard_signal false) driven by one signal: returns.counterparty_prior_unauthorized, weight 40, detail '2 prior unauthorized return(s)' for the counterparty. What the evidence shows. The transfer itself is SETTLED with return code none, so no unauthorized return occurred on this specific transaction. The risk signal is about the counterparty's history (2 prior unauthorized returns), not this transfer's outcome. The originating entity, Kestrel Partners 110, is VERIFIED, not high risk, not PEP, screened 2026-08-29, US-based. At the program level, ach_unauthorized_return_rate is flagged as breach (0.00862 on n=812) and manual_review_aging_hours is also breach (1438 hours on n=15), while most other KRIs (velocity_vs_declared, reserve_coverage_ratio, sanctioned_country_transfers, ach_overall_return_rate) are ok. Counterparty country is unknown, which limits geographic risk assessment. No prior dispositions exist for this alert. What was checked. Reviewed the transfer status and return code, the single triggering signal and its weight, the entity's verification and risk flags, and the program-level KRI panel for corroborating or mitigating patterns. Confirmed the transfer is settled, not in a held state, so no funds-movement decision is pending on this alert. What is recommended. Because the transfer already settled with no return, there is no transaction to hold or release. However, the counterparty's history of 2 prior unauthorized returns combined with a program-level breach in ach_unauthorized_return_rate indicates a pattern extending beyond this single alert. This warrants escalation for a person to review the counterparty's transaction history across the program rather than a routine close.
Recommendation
escalate
Confidence
0.60
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer acht_sim_harb_cfqxlhft926 is SETTLED with return code none, ruling out 'release' since no hold exists.
  • The triggering signal concerns counterparty history (2 prior unauthorized returns), not this transfer's own outcome, so the immediate transaction shows no defect.
  • Program KRI ach_unauthorized_return_rate is in breach status (0.00862, n=812), corroborating that unauthorized returns are an active pattern at the program level, not isolated to this alert.
  • Entity verification and risk flags (VERIFIED, not high risk, not PEP) do not raise concern about the originator, but counterparty country is unknown, limiting full risk assessment.
  • Manual_review_aging_hours breach (1438 hours) suggests review backlog, supporting escalation for prioritized human attention rather than auto-close.
  • Confidence is moderate because the evidence is directly tied to context fields, but the counterparty's full return history and country are not detailed beyond the '2 prior unauthorized returns' summary.

Evidence

{
  "n": 2064,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "2 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+403 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.