SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 30 (review band) on a $499.09 ach transfer: returns.counterparty_prior_any, returns.entity_rate_gt_threshold.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_b0sos7qh79i
Transfer
acht_sim_harb_b0sos7qh79i · $499.09 · ach outgoing
Skoor at alert
30 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. A $499.09 outgoing ACH debit transfer for entity Grove Co 16 (program Harbor Marketplace Payouts) settled on 2026-08-19. The transfer risk model produced a Transaction Risk Skoor of 30, placing it in the review band, based on two signals: one prior non-NSF return for this counterparty and an entity-level unauthorized/other return rate of 1/23 originated ACH debits in the trailing 60 days. What the evidence shows. The transfer itself carries no return code and is marked SETTLED, so no funds are currently recoverable or held. The entity is VERIFIED, not flagged high risk, not PEP, and was last screened 2026-07-01 with no open review reasons. The alert's two weighted signals (15+15=30) reflect counterparty and entity return history rather than anything anomalous about this specific transfer. At the program level, two KRIs are in breach status: ach_unauthorized_return_rate (0.0104, n=479) and manual_review_aging_hours (1438.0, n=8). Three other KRIs are in watch status: hold_aging_hours, pep_flagged_entities, and high_risk_entity_share. No prior dispositions exist for this subject. What was checked. Reviewed the alert evidence block, transfer record (status, amount, return code, counterparty), entity verification and screening status, and the program KRI panel. Confirmed the transfer is settled with no return code attached, meaning this specific transaction shows no confirmed loss event. Confirmed the entity has no elevated risk flags on file. What is recommended. This transfer is settled with no return code, so there is no fund to hold or release. The alert itself, taken alone, does not show a completed unauthorized event tied to this transaction. However, the program-level ach_unauthorized_return_rate and manual_review_aging_hours are both in breach, which is broader than this single alert and warrants a person to look at whether this entity's return pattern is part of a wider program-level trend rather than an isolated case. Recommend escalation for pattern review rather than closing outright.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer is SETTLED with return code none, so hold/release actions do not apply to this transaction.
  • Alert-level signals (prior non-NSF return, entity return rate 1/23) are moderate and already reflected in the review-band Skoor of 30, not a hard signal.
  • Entity is VERIFIED, not high-risk, not PEP, screened recently with no open review reasons, which weighs against escalation on entity risk alone.
  • Program KRIs show ach_unauthorized_return_rate and manual_review_aging_hours in breach status, indicating a pattern beyond this single alert that a person should evaluate.
  • No prior dispositions exist for this subject, so there is no history to indicate this is a repeat false positive.
  • Evidence is limited to counts and rates without underlying case-level detail on the prior return or the 1/23 unauthorized returns, so confidence in a firm pattern conclusion is moderate, not high.

Evidence

{
  "n": 1278,
  "band": "review",
  "skoor": 30,
  "signals": [
    {
      "code": "returns.counterparty_prior_any",
      "detail": "1 prior return(s) other than NSF",
      "weight": 15
    },
    {
      "code": "returns.entity_rate_gt_threshold",
      "detail": "entity unauthorized return rate 1/23 originated ACH debits in 60d",
      "weight": 15
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)
returns.entity_rate_gt_threshold+15entity unauthorized return rate 1/23 originated ACH debits in 60d

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.