Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $295.76 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_bviq3on06td
- Transfer
- acht_sim_harb_bviq3on06td · $295.76 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An automated risk detector (skoor_review) flagged outgoing ACH transfer acht_sim_harb_bviq3on06td for $295.76 under program Harbor Marketplace Payouts. The transfer risk score is 40, placing it in the review band, driven by a single signal: the counterparty has one prior unauthorized ACH return.
What the evidence shows. The transfer status is SETTLED with no return code on this transaction itself, meaning it completed without issue. The risk score of 40 comes entirely from one signal, returns.counterparty_prior_unauthorized, weighted at 40, with hard_signal marked false. The paying entity, Heath Holdings 119, is VERIFIED, not high risk, not PEP, has no open review reasons, and was screened as recently as 2026-07-07. The counterparty's country is unknown, but no sanctioned-country or velocity signals fired. Program-level KRIs show ach_unauthorized_return_rate at 1.06% flagged as a breach and manual_review_aging_hours at 1438 hours also flagged as a breach; these are program-wide metrics and are not tied specifically to this transfer or this counterparty in the evidence provided.
What was checked. Reviewed the transfer record (status, amount, return code, counterparty), the entity verification and screening status, the transfer-level skoor and its single contributing signal, and the program KRI panel for related patterns. No prior dispositions exist for this alert. No hard signal was present, and no evidence in this alert ties the entity or counterparty to the program's aggregate KRI breaches beyond the one historical unauthorized return already reflected in the score.
What is recommended. Because the transfer already settled, there are no funds to hold and release is not applicable. The evidence supporting escalation is limited to two program-wide KRI breaches that are not shown here to be linked to this specific counterparty or entity beyond the single prior unauthorized return already scored. Given the verified, non-high-risk entity, the absence of a hard signal, and the transfer's completed status, this alert does not present evidence requiring further review by a person. Recommend closing the alert. A person should independently monitor the program-wide ach_unauthorized_return_rate and manual_review_aging_hours breaches, as those may warrant separate review outside this alert.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer status is SETTLED; no funds are pending, so hold/release do not apply.
- Single contributing signal is one prior unauthorized return from the counterparty, with hard_signal false and skoor only 40 (review band, not high).
- Paying entity is VERIFIED, not high risk, not PEP, no open review reasons, recently screened.
- No sanctioned-country, velocity, or other elevated signals fired for this transfer.
- Program KRI breaches (ach_unauthorized_return_rate, manual_review_aging_hours) are aggregate metrics not directly tied in the evidence to this specific transfer or counterparty, so they support a note for separate monitoring rather than escalation of this alert.
- No prior dispositions exist to suggest a repeating pattern for this specific subject.
Evidence
{
"n": 1088,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 2 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.