SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

First transfer to a new counterparty, $777.33, above the program's 95th percentile.

Detector
first_time_counterparty_large
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_9xfxgwmw3yn
Transfer
acht_sim_harb_9xfxgwmw3yn · $777.33 · ach outgoing
Skoor at alert
null unscored
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. A first-time transfer of $777.33 to a new counterparty was flagged because it exceeded the program's 95th percentile threshold ($756.67). The detector fired due to two signals: counterparty.first_time and counterparty.first_time_and_large. What the evidence shows. The transfer is an outgoing ACH credit with status COMPLETED and no return code, indicating no failure or rejection occurred. The subject entity, Juniper LLC 19, is VERIFIED, not flagged as high risk, not a PEP, and has no open review reasons. Its last screening was 2026-09-03, within the program's stale_screening_share=0 metric. The transfer and entity skoor are both null/unscored due to low sample size (n=4), meaning the model has insufficient history on this counterparty to produce a risk score. The counterparty's country is listed as unknown, which is a gap but not itself an evidenced risk signal. Program KRIs show two items in breach (ach_unauthorized_return_rate, manual_review_aging_hours) and three in watch status, but none of these are tied specifically to this transfer, counterparty, or entity. What was checked. Reviewed alert evidence, transfer details, entity verification status, program KRIs, and prior dispositions. No prior dispositions exist for this alert or subject. No sanctioned-country transfers are recorded at the program level (0 of n=1783), and this transfer's country is not flagged as sanctioned. What is recommended. No signal in the evidence indicates unauthorized activity, entity risk, or fund-movement failure. The transfer has already completed with no return code, so there is no pending transfer to hold or release. The alert reflects a first-time large payment that is consistent with a normal, verified business counterparty relationship. Recommend closing the alert. Confidence is limited by the unscored band (n=4) and unknown counterparty country, which should be noted for future monitoring but do not independently justify escalation or hold.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is COMPLETED with return code none, indicating no execution failure.
  • Subject entity is VERIFIED, not high risk, not PEP, with no open review reasons and recent screening.
  • Skoor is null due to low sample size (n=4), not due to any adverse score.
  • Program-level KRI breaches (ach_unauthorized_return_rate, manual_review_aging_hours) are not linked to this specific transfer or entity in the evidence provided.
  • No prior dispositions or pattern evidence link this alert to a broader concern warranting escalation.
  • Counterparty country is unknown, which is a data gap but not a documented risk signal; this lowers confidence slightly rather than changing the recommendation.

Evidence

{
  "n": 4,
  "band": "unscored",
  "skoor": null,
  "signals": [
    {
      "code": "counterparty.first_time",
      "detail": "first transfer with this counterparty",
      "weight": 10
    },
    {
      "code": "counterparty.first_time_and_large",
      "detail": "amount above the program p95 (75667)",
      "weight": 15
    }
  ],
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
counterparty.first_time+10first transfer with this counterparty
counterparty.first_time_and_large+15amount above the program p95 (75667)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.