Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $905.67 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Northwind Payroll (simulated)
- Subject
- transfer acht_sim_nort_azvzoarp25q
- Transfer
- acht_sim_nort_azvzoarp25q · $905.67 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An ACH outgoing debit transfer of $905.67 from program Northwind Payroll (simulated) was flagged by the skoor_review detector at Transaction Risk Skoor 40, placing it in the review band. The triggering signal is one prior unauthorized return associated with the counterparty.
What the evidence shows. The transfer settled already (status SETTLED, return code none), so no unauthorized return occurred on this specific transaction. The alert is driven entirely by a single historical signal: returns.counterparty_prior_unauthorized, weighted 40, which alone accounts for the full skoor of 40. Confidence on this scoring is stated at 0.94 with n=781. The subject entity, Birch Holdings 01, is VERIFIED, not high risk, not PEP, has no review reasons, and was screened 2026-06-23. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=302, ok) and ach_overall_return_rate at 0.99% (ok), indicating this program does not show a broader unauthorized-return pattern. Two KRIs are flagged watch (pep_flagged_entities, high_risk_entity_share) and one is a breach (manual_review_aging_hours=1434.67 hours, n=7), but none of these are tied to this specific transfer or counterparty in the evidence provided.
What was checked. Transfer status and return code, entity verification and screening status, program-level return-rate and risk KRIs, and prior dispositions (none on record for this alert).
What is recommended. The transfer has already settled, so no funds are being held pending this alert; a hold or release action does not apply. The evidence is a single prior counterparty return event with no corroborating pattern at the program level (unauthorized return rate is 0) and a verified, non-high-risk subject. This does not meet the bar for escalation absent further pattern evidence, but the counterparty's prior unauthorized return and the elevated manual_review_aging_hours breach warrant a person's review before closing, particularly to confirm the counterparty history does not represent a recurring issue outside this single alert's scope.
- Recommendation
- hold
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer already settled with no return code, so this is not a funds-hold scenario in the traditional sense, but recommendation reflects that closure without review is not warranted given an unresolved prior unauthorized return signal on the counterparty.
- Program-level ach_unauthorized_return_rate is 0 (n=302, ok), which weighs against escalation to a broader pattern.
- Entity is VERIFIED, not high risk, not PEP, with no review reasons, reducing but not eliminating concern.
- manual_review_aging_hours KRI is in breach (1434.67 hours, n=7), suggesting review capacity issues that should not be compounded by auto-closing this alert.
- No prior dispositions exist for this alert, so this is the first review point.
- Evidence is limited to one signal and one transfer; confidence is moderate given thin corroborating detail on the counterparty itself (country unknown).
Evidence
{
"n": 781,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 0.94,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.