SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 30 (review band) on a $532.64 ach transfer: returns.counterparty_prior_any, returns.entity_rate_gt_threshold.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_bivppnn27vm
Transfer
acht_sim_harb_bivppnn27vm · $532.64 · ach outgoing
Skoor at alert
30 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Transaction Risk Skoor flagged an outgoing ACH debit of $532.64 from transfer acht_sim_harb_bivppnn27vm at score 30 (review band). Two signals fired: one prior return other than NSF on this counterparty, and the originating entity's unauthorized ACH return rate (1 of 21 debits in 60 days) exceeding the alert threshold. The transfer is already SETTLED with no return code recorded. What the evidence shows. The transfer itself settled with no return posted against it, so there is no unauthorized return tied to this specific transaction. The two signals both concern history rather than this transfer's outcome: a prior non-NSF return on the counterparty and an elevated entity-level unauthorized return rate (1/21 = 4.8%). The entity (Larch Studio 111) is VERIFIED, not high risk, not PEP, with no open review reasons and screening current as of 2026-08-21. Program KRIs show ach_unauthorized_return_rate at 1.02% marked as a breach (n=591) and manual_review_aging_hours also breached (n=9), while other KRIs (frozen_accounts, overdraft_events, sanctioned_country_transfers, velocity_vs_declared) are ok. Hard signal is false and detector confidence is 1, meaning the score is reliable but not indicative of a rule-based stop. What was checked. Reviewed transfer status and return code (settled, none), entity verification and screening status, program KRI panel for corroborating breaches, and prior dispositions (none on file). Confirmed the transfer is not in a held state, so no funds are pending release. What is recommended. Because the transfer already settled and carries no return, there is no transaction-level action to take on this alert alone. However, the entity-level unauthorized return rate signal aligns with a program-wide KRI breach on ach_unauthorized_return_rate, which suggests this entity's pattern may be contributing to a broader program-level trend that a single alert disposition cannot resolve. This warrants escalation for pattern review across the entity's recent ACH activity rather than a routine close.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer is SETTLED with no return code; no funds are held, so release/hold do not apply.
  • Signals are historical (prior return, entity return rate) rather than tied to this transfer's outcome.
  • Entity is VERIFIED, not high risk, not PEP, with current screening, reducing urgency for a hold-type action.
  • Program KRI ach_unauthorized_return_rate is flagged as a breach (n=591), and manual_review_aging_hours is also breached, both of which corroborate a possible pattern beyond this single alert.
  • No prior dispositions exist for context, so entity-level trend cannot be confirmed from this alert alone, lowering confidence.

Evidence

{
  "n": 1547,
  "band": "review",
  "skoor": 30,
  "signals": [
    {
      "code": "returns.counterparty_prior_any",
      "detail": "1 prior return(s) other than NSF",
      "weight": 15
    },
    {
      "code": "returns.entity_rate_gt_threshold",
      "detail": "entity unauthorized return rate 1/21 originated ACH debits in 60d",
      "weight": 15
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_any+151 prior return(s) other than NSF
returns.entity_rate_gt_threshold+15entity unauthorized return rate 1/21 originated ACH debits in 60d

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.