SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

The program reserve covers 47% of rolling 60-day ACH debit volume; the bank requires 100%.

Detector
reserve_coverage
Severity
high
Program
Meridian Remit (simulated)
Subject
program 48915275-d6d2-4068-8e62-f51a51f9da77
Transfer
Skoor at alert
null unscored
Hard signal
no
Policy
policy-v1
Opened
2026-09-18 00:17Z
Closed
Decision clock
appeal · due 2026-09-25 00:17Z due 2026-09-25 00:17Z
Escalated

Draft narrative

What happened. Alert de3f04b9 fired from the reserve_coverage detector on program Meridian Remit (48915275-d6d2-4068-8e62-f51a51f9da77). The reserve on file covers 47% of rolling 60-day ACH debit volume against a bank requirement of 100%. Severity is high, route is reviewed, and there is no prior disposition history for this program. What the evidence shows. The reserve_coverage_ratio KRI is 0.4669 (n=440) against a threshold of 1.0, status breach. This is the metric the alert is built on. Alongside it, the same program's KRI panel shows three other breaching metrics: manual_review_aging_hours=1151.6 (n=3, breach), ach_unauthorized_return_rate=0.0114 (n=440, breach), and sanctioned_country_transfers=2 (n=966, breach). Two KRIs sit at watch: hold_aging_hours=1369.7 hours (n=5) and pep_flagged_entities=1 (n=30). Other KRIs (frozen_accounts, overdraft_events, manual_review_rate, velocity_vs_declared, stale_screening_share, high_risk_entity_share, ach_overall_return_rate, verification_denial_rate, ach_administrative_return_rate, counterparty_concentration_top1) are within normal range. card_fraud_declines is unmeasured (n=0). The program declares $1,200,000.00 monthly volume across ach, wire, swift rails in US, MX, PH. What was checked. I reviewed the alert evidence block (n=440, kri=reserve_coverage_ratio, value=0.4669, status=breach, threshold=1) against the full program KRI panel to see whether the reserve shortfall is isolated or accompanied by other signals. I checked for prior dispositions on this program (none found) and confirmed the alert is unscored (skoor null) with hard_signal false, meaning no scoring engine has weighed in independently. What is recommended. This is not a single held transfer, so release does not apply. The reserve shortfall itself is a program-level capital adequacy issue that a person must evaluate before any assumption of adequate coverage is restored. Combined with a breaching sanctioned_country_transfers count (2, on a program with MX and PH rail exposure) and a breaching manual_review_aging_hours metric, the evidence points to more than an isolated coverage gap — it suggests broader program-level control weakness. I recommend escalate: the reserve breach should be reviewed alongside the sanctioned-country and review-aging breaches as a single program-level pattern rather than dispositioned as an isolated KRI miss.
Recommendation
escalate
Confidence
0.72
Model
claude-sonnet-5
Drafted
2026-09-18 00:18Z
Rationale
  • reserve_coverage_ratio is confirmed breach at 0.4669 against threshold 1.0 with n=440, directly matching the alert summary
  • three additional KRIs on the same program are in breach status (manual_review_aging_hours, ach_unauthorized_return_rate, sanctioned_country_transfers), indicating the reserve gap is not an isolated metric
  • sanctioned_country_transfers=2 (breach) alongside declared country exposure to MX and PH raises the stakes beyond a funding/coverage question alone
  • alert is unscored (skoor null) and hard_signal is false, so no independent scoring has assessed materiality, which argues against closing without review
  • no prior dispositions exist on this program, so there is no established pattern of this being previously reviewed and cleared
  • this alert does not concern a held transfer, so 'release' is not applicable regardless of other findings

Evidence

{
  "n": 440,
  "kri": "reserve_coverage_ratio",
  "unit": "ratio",
  "value": 0.46692560418477086,
  "status": "breach",
  "threshold": 1,
  "routeReason": "detector always reviewed"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.