Alert · reviewed · open
Transaction Risk Skoor 55 (review band) on a $540.09 ach transfer: returns.counterparty_prior_unauthorized, geo.outside_declared_countries.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_ad3m3st602
- Transfer
- acht_sim_harb_ad3m3st602 · $540.09 · ach outgoing
- Skoor at alert
- 55 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. On 2026-08-04 transfer acht_sim_harb_ad3m3st602 moved $540.09 by ACH as an outgoing credit under Harbor Marketplace Payouts. The transfer settled with no return code. The skoor_review detector scored the transfer 55 (review band) and opened this alert on 2026-09-17, citing two signals: a prior unauthorized return from this counterparty and a counterparty country (TR) outside the program's declared country list (US only).
What the evidence shows. The transfer risk skoor is 55 in the review band, driven by two weighted signals: returns.counterparty_prior_unauthorized (weight 40, one prior unauthorized return on file for this counterparty) and geo.outside_declared_countries (weight 15, counterparty located in TR, not in the program's declared US-only footprint). The transfer status is SETTLED with return code none, meaning funds already moved and there is no held transfer to act on. The receiving entity, Dune LLC 13, is verified, not high risk, not PEP, and was last screened 2026-07-02. Program KRIs show two breaches: manual_review_aging_hours at 1438 hours (n=5) and ach_unauthorized_return_rate at 0.85% (n=236), both flagged breach. Two other KRIs are at watch: pep_flagged_entities (1 of 30) and high_risk_entity_share (6.67%). Other KRIs, including sanctioned_country_transfers and stale_screening_share, are ok. There are no prior dispositions on this alert.
What was checked. Reviewed the alert evidence, transfer record, program declared footprint, counterparty screening state via the linked entity, and program KRI panel. Confirmed transfer status is SETTLED with no return code, meaning this is a closed transaction rather than a pending hold. Confirmed the entity attached to the transfer is verified and not flagged high risk or PEP. Confirmed the geo signal is factual: TR is not in the program's declared countries (US only). Confirmed the KRI breaches on manual_review_aging_hours and ach_unauthorized_return_rate are program-wide figures, not specific to this single transfer, indicating this alert may not be an isolated case.
What is recommended. This transfer already settled, so there is no held transfer to release. Given a program-level breach in ach_unauthorized_return_rate and a documented prior unauthorized return tied to this same counterparty, combined with a geo mismatch against the program's declared footprint, this looks like it may be part of a broader pattern rather than an isolated single-transfer issue. Recommend escalation for a person to review whether other transfers to this counterparty or other TR-based counterparties under this program show the same unauthorized-return and geo-mismatch pattern, and whether the program's declared country list needs updating or the counterparty relationship needs to be reassessed.
- Recommendation
- escalate
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer status is SETTLED with return code none; no held funds exist, so hold/release is not applicable.
- Skoor 55 in review band is driven by a documented prior unauthorized return from this same counterparty (weight 40), which is a specific, traceable risk fact, not speculation.
- Geo signal is factual: counterparty country TR is absent from the program's declared countries list (US only), indicating either a program footprint gap or unreported geographic exposure.
- Program KRI panel shows ach_unauthorized_return_rate at breach status (0.85%, n=236) and manual_review_aging_hours at breach status (1438 hours, n=5), suggesting this alert may sit within a larger pattern rather than an isolated event.
- Entity verification data (verified, not high risk, not PEP, screened 2026-07-02) does not itself raise concern, so the escalation basis rests on the counterparty return history and program-level breach signals, not on the receiving entity.
- No prior dispositions exist for this alert, so there is no precedent trail to lean on; confidence is moderate given the alert data is specific but the broader pattern is inferred from program KRIs rather than confirmed multi-transfer data.
Evidence
{
"n": 781,
"band": "review",
"skoor": 55,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
},
{
"code": "geo.outside_declared_countries",
"detail": "counterparty country TR not declared by the program",
"weight": 15
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 2 prior unauthorized return(s) | |
| geo.outside_declared_countries | +15 | counterparty country TR not declared by the program |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.