SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 30 (review band) on a $780.85 ach transfer: returns.counterparty_prior_any, returns.entity_rate_gt_threshold.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_52q7fa6y6oe
Transfer
acht_sim_harb_52q7fa6y6oe · $780.85 · ach outgoing
Skoor at alert
30 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. A $780.85 outgoing ACH debit transfer for counterparty cpty_sim_harb_bmqeuc7o3xi under program Harbor Marketplace Payouts was scored by the skoor_review detector at 30 (review band, hard_signal false) and routed for review because the detector is not auto-closable. The transfer settled on 2026-08-12 with no return code recorded. What the evidence shows. The alert fired on two signals: the counterparty has 1 prior return other than NSF (returns.counterparty_prior_any, weight 15), and the entity's unauthorized return rate is 1 of 21 originated ACH debits in the trailing 60 days, above the configured threshold (returns.entity_rate_gt_threshold, weight 15). The entity, Juniper LLC 121, is VERIFIED, not high risk, not PEP, has no open review reasons, and was screened 2026-07-01. This transfer itself carries no return code and is already SETTLED. Separately, program-level KRIs show ach_unauthorized_return_rate at 0.0115 (n=347) flagged as a breach, and manual_review_aging_hours at 1438 hours (n=6) also flagged as a breach. These two program-level breaches are not explained by this single transfer but indicate the entity-level signal driving this alert sits within a program that is independently breaching its unauthorized-return threshold. What was checked. Transfer status and return code, entity verification and screening status, program declared volume and KRI panel, and prior dispositions for this alert (none on file). What is recommended. The transfer has already settled with no return code, so there is no held transaction to release or hold. The entity-level evidence alone (one prior non-NSF return, marginal rate breach) is thin and would not by itself warrant escalation. However, the alert coincides with a program-wide ach_unauthorized_return_rate breach and a manual_review_aging_hours breach, suggesting this alert may be one instance of a broader pattern the review team should examine across the program rather than close in isolation.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer is SETTLED with no return code; no funds are held, so hold/release do not apply.
  • Entity is VERIFIED, not high risk, not PEP, with no open review reasons, weakening the case for standalone escalation on entity facts alone.
  • Program KRI ach_unauthorized_return_rate is flagged as a breach (0.0115, n=347), independent of this single alert, indicating a pattern larger than one transfer.
  • manual_review_aging_hours is also flagged as a breach (1438 hours, n=6), suggesting review capacity or backlog issues compounding pattern risk.
  • Evidence for this specific alert is limited to two moderate-weight signals (15+15=30, review band, hard_signal false), so confidence in a definitive fraud/AML finding is not established; a person should assess whether this alert is representative of the program-level breach.

Evidence

{
  "n": 1056,
  "band": "review",
  "skoor": 30,
  "signals": [
    {
      "code": "returns.counterparty_prior_any",
      "detail": "1 prior return(s) other than NSF",
      "weight": 15
    },
    {
      "code": "returns.entity_rate_gt_threshold",
      "detail": "entity unauthorized return rate 1/21 originated ACH debits in 60d",
      "weight": 15
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_any+151 prior return(s) other than NSF
returns.entity_rate_gt_threshold+15entity unauthorized return rate 1/21 originated ACH debits in 60d

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.