SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $582.10 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Meridian Remit (simulated)
Subject
transfer acht_sim_meri_c5j8szdpbnt
Transfer
acht_sim_meri_c5j8szdpbnt · $582.10 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert d166eecb flagged a settled outgoing ACH transfer of $582.10 from Kestrel Partners 210 under program Meridian Remit. The transfer was scored 40 (review band) solely because the counterparty cpty_sim_meri_bts0zmjm9td has 2 prior unauthorized returns on file. What the evidence shows. The transfer itself settled with no return code recorded (return code: none), so this specific transaction did not itself return unauthorized. The single signal returns.counterparty_prior_unauthorized carries the full weight (40) that produced the score; hard_signal is false and there are no other contributing signals. The entity Kestrel Partners 210 is VERIFIED, not high risk, not PEP, has no review reasons, and was screened 2026-07-06 (within policy). Program-level KRIs show ach_unauthorized_return_rate at 0.0143 (n=280) in breach status and reserve_coverage_ratio at 0.801 (n=280) in breach status, along with manual_review_aging_hours in breach (1146.9 hrs, n=2). No prior dispositions exist for this alert or, per the record shown, for this counterparty. What was checked. Reviewed the transfer record (status, return code, amount, dates), the entity verification and risk flags, the program KRI panel for related return-rate and reserve metrics, and the signal weighting behind the skoor. Confirmed no hard signal and no other transfer-level risk indicators (velocity, sanctioned country, concentration all read ok). What is recommended. The transfer has already settled with no return, and the named entity is verified with no other risk flags, so there is no transfer-level action to take on this alert alone. However, the counterparty's 2 prior unauthorized returns combine with a program-level breach on ach_unauthorized_return_rate and reserve_coverage_ratio, which points to a pattern beyond this single alert. This warrants a person reviewing the counterparty's return history across the program rather than a routine close.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Alert score is fully explained by one signal: 2 prior unauthorized returns on the counterparty, with hard_signal false.
  • This specific transfer settled with return code none, so no return event occurred on this transaction.
  • Entity is VERIFIED, not high risk, not PEP, no review reasons, screened within policy window.
  • Program KRIs show ach_unauthorized_return_rate and reserve_coverage_ratio in breach status, suggesting the counterparty pattern may be part of a broader program issue.
  • No prior dispositions exist to indicate this counterparty has already been reviewed.
  • Transfer is already SETTLED, so hold/release is not applicable; the concern is pattern-level, not this transfer's funds movement.

Evidence

{
  "n": 755,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "2 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+402 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.