SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $1,554.60 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_4qi5rhgp25h
Transfer
acht_sim_nort_4qi5rhgp25h · $1,554.60 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert d17f9e59-7861-46e1-a486-16b9efef8eda fired on a $1,554.60 outgoing ACH transfer (acht_sim_nort_4qi5rhgp25h) under program Northwind Payroll. The skoor_review detector scored the transfer 40, placing it in the review band, on a single signal: the counterparty has one prior unauthorized return on record. What the evidence shows. The transfer itself settled with no return code. The counterparty (cpty_sim_nort_2vu2cgc34a) country is unknown but the paying entity, Dune LLC 03, is VERIFIED, not high risk, not PEP, with no review reasons and a screening date of 2026-07-07. The only risk contribution is the single prior-unauthorized-return signal (weight 40, n=789, confidence 1). No other signals fired on this transfer. Program-level KRIs are mostly within normal range: ach_unauthorized_return_rate is 0, ach_overall_return_rate is 0.99%, sanctioned_country_transfers is 0, reserve_coverage_ratio is 2.39. Two KRIs sit outside normal: manual_review_aging_hours shows a breach (1434.7 hours, n=7) and pep_flagged_entities/high_risk_entity_share are at watch level (n=33 pool). Neither of these KRIs is tied to this entity or this transfer specifically. What was checked. Reviewed the transfer status (SETTLED, no return code), the entity verification record (VERIFIED, low risk, not PEP), the program KRI panel for corroborating patterns (unauthorized return rate at 0 across 302 transfers, no sanctioned-country exposure, no overdraft or frozen-account events), and prior dispositions (none on file for this alert or entity). What is recommended. Close the alert. The transfer has already settled with no return, the paying entity is verified and unflagged, and the single triggering signal (one historical unauthorized return on the counterparty) is not corroborated by any current-transfer irregularity or elevated program-level return metrics. This transfer already settled, so a hold or release disposition does not apply. The manual_review_aging_hours breach is a separate operational concern and should be tracked outside this alert, not used to hold this settled transfer.
Recommendation
close
Confidence
0.72
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Single signal driving the skoor (40): one prior unauthorized return on the counterparty; no other risk signals present on this transfer.
  • Transfer status is SETTLED with return code none; funds are not in a held state, so hold/release actions do not apply.
  • Paying entity is VERIFIED, not high risk, not PEP, no review reasons, screened within the last two months.
  • Program-wide ach_unauthorized_return_rate is 0 across 302 transfers, indicating no broader pattern of unauthorized returns tied to this program.
  • manual_review_aging_hours KRI breach and pep_flagged_entities/high_risk_entity_share watch levels are program-level observations not specific to this entity or transfer and do not by themselves justify escalation of this alert.
  • Evidence set is limited to one signal at n=789 with confidence 1, which is a narrow basis; confidence in this disposition is accordingly held below high.

Evidence

{
  "n": 789,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.