SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $905.67 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_azvzoarp25q
Transfer
acht_sim_nort_azvzoarp25q · $905.67 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An ACH outgoing debit transfer of $905.67 from program Northwind Payroll (simulated) was flagged by the skoor_review detector at Transaction Risk Skoor 40, placing it in the review band. The triggering signal is one prior unauthorized return associated with the counterparty. What the evidence shows. The transfer settled already (status SETTLED, return code none), so no unauthorized return occurred on this specific transaction. The alert is driven entirely by a single historical signal: returns.counterparty_prior_unauthorized, weighted 40, which alone accounts for the full skoor of 40. Confidence on this scoring is stated at 0.94 with n=781. The subject entity, Birch Holdings 01, is VERIFIED, not high risk, not PEP, has no review reasons, and was screened 2026-06-23. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=302, ok) and ach_overall_return_rate at 0.99% (ok), indicating this program does not show a broader unauthorized-return pattern. Two KRIs are flagged watch (pep_flagged_entities, high_risk_entity_share) and one is a breach (manual_review_aging_hours=1434.67 hours, n=7), but none of these are tied to this specific transfer or counterparty in the evidence provided. What was checked. Transfer status and return code, entity verification and screening status, program-level return-rate and risk KRIs, and prior dispositions (none on record for this alert). What is recommended. The transfer has already settled, so no funds are being held pending this alert; a hold or release action does not apply. The evidence is a single prior counterparty return event with no corroborating pattern at the program level (unauthorized return rate is 0) and a verified, non-high-risk subject. This does not meet the bar for escalation absent further pattern evidence, but the counterparty's prior unauthorized return and the elevated manual_review_aging_hours breach warrant a person's review before closing, particularly to confirm the counterparty history does not represent a recurring issue outside this single alert's scope.
Recommendation
hold
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer already settled with no return code, so this is not a funds-hold scenario in the traditional sense, but recommendation reflects that closure without review is not warranted given an unresolved prior unauthorized return signal on the counterparty.
  • Program-level ach_unauthorized_return_rate is 0 (n=302, ok), which weighs against escalation to a broader pattern.
  • Entity is VERIFIED, not high risk, not PEP, with no review reasons, reducing but not eliminating concern.
  • manual_review_aging_hours KRI is in breach (1434.67 hours, n=7), suggesting review capacity issues that should not be compounded by auto-closing this alert.
  • No prior dispositions exist for this alert, so this is the first review point.
  • Evidence is limited to one signal and one transfer; confidence is moderate given thin corroborating detail on the counterparty itself (country unknown).

Evidence

{
  "n": 781,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 0.94,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.