SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 55 (review band) on a $602.44 ach transfer: returns.counterparty_prior_unauthorized, returns.entity_rate_gt_threshold.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_253holxp93x
Transfer
acht_sim_harb_253holxp93x · $602.44 · ach outgoing
Skoor at alert
55 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert ce1186eb-3d6a-4b8c-8836-11350b0b81ae fired on ach transfer acht_sim_harb_253holxp93x, a $602.44 outgoing ACH credit under Harbor Marketplace Payouts. The transfer risk score was 55 (review band, not hard-stop) driven by two signals: the counterparty has 2 prior unauthorized returns, and the entity's unauthorized return rate (1/29 originated ACH debits in 60d) exceeds the configured threshold. The transfer itself settled on 2026-09-11 with no return code recorded. What the evidence shows. The transfer status is SETTLED with return code none, meaning funds already moved and no return has posted against this specific transfer. The originating entity, Larch Studio 111, is VERIFIED, not flagged high risk, not PEP, and was screened as recently as 2026-08-21 with no open review reasons. The risk signals relate to counterparty and entity return history rather than this transfer's own outcome. At the program level, the ach_unauthorized_return_rate KRI is listed in breach status (0.00862, n=812), and pep_flagged_entities, high_risk_entity_share, and overdraft_events are all in watch status. Manual_review_aging_hours is also in breach (1438 hours, n=15). No prior dispositions exist for this alert or entity. What was checked. Reviewed the transfer record (status, return code, amount, counterparty), the entity verification and screening record, the alert's underlying signal weights and confidence, and the program-level KRI panel for corroborating patterns. Confirmed there is no hard signal on this alert and no prior dispositions to reference. What is recommended. Because this transfer has already settled with no return, there are no funds to hold and release does not apply. However, the combination of a counterparty with two prior unauthorized returns, an entity-level return rate above threshold, and a program-wide breach on ach_unauthorized_return_rate together indicate a pattern that extends beyond this single alert. This warrants escalation for a person to assess whether the counterparty or entity requires broader review across other transfers, rather than a routine close.
Recommendation
escalate
Confidence
0.60
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer is SETTLED with return code none; no funds are in a holdable state, so hold/release do not apply.
  • Two independent signals (counterparty_prior_unauthorized, entity_rate_gt_threshold) both point to a return-history pattern rather than a one-off anomaly.
  • Program KRI ach_unauthorized_return_rate is flagged breach, which corroborates that unauthorized returns are an active program-level concern, not isolated to this alert.
  • Entity itself is verified, not high risk, and recently screened, which lowers concern about this specific entity but does not resolve the counterparty-level pattern.
  • No prior dispositions exist to indicate this pattern has already been reviewed and cleared, so a person should assess before treating this as routine.

Evidence

{
  "n": 2045,
  "band": "review",
  "skoor": 55,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "2 prior unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "returns.entity_rate_gt_threshold",
      "detail": "entity unauthorized return rate 1/29 originated ACH debits in 60d",
      "weight": 15
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+402 prior unauthorized return(s)
returns.entity_rate_gt_threshold+15entity unauthorized return rate 1/29 originated ACH debits in 60d

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.