SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $1,701.75 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_ccbqk1hk2sm
Transfer
acht_sim_nort_ccbqk1hk2sm · $1,701.75 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An outgoing ACH credit transfer of $1,701.75 from program Northwind Payroll to counterparty cpty_sim_nort_5a6oup6d8m was flagged by the skoor_review detector at a risk score of 40 (review band). The transfer has already settled, with no return code posted. What the evidence shows. The single signal driving the score is returns.counterparty_prior_unauthorized, indicating this counterparty has one prior unauthorized ACH return on record. The transfer itself has return code none and status SETTLED, so no return has occurred on this specific transaction. The originating entity, Alder Co 024, is VERIFIED, not high risk, not PEP, with no review reasons and screening current as of 2026-08-17. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=444, ok) and ach_overall_return_rate at 0.011 (ok), suggesting this prior unauthorized return has not translated into a broader pattern at the program level. Two KRIs are outside normal range: manual_review_aging_hours is in breach (1434.68 hours, n=8) and hold_aging_hours is in watch (518.28 hours, n=1), both unrelated to this specific alert's transfer but relevant to review-queue handling generally. What was checked. Reviewed the transfer record, the entity verification status and screening date, the program KRI panel, and prior dispositions for this alert. Prior dispositions: none on file. The counterparty's country is unknown, and the underlying detail behind the 'prior unauthorized return' (date, count beyond one, dollar value) is not provided in this evidence set. What is recommended. The transfer has already settled, so no hold action applies to funds movement. Given a verified, non-high-risk originating entity, a program-level unauthorized return rate at 0, and only one flagged prior unauthorized return on the counterparty with no further detail, this alert does not show evidence of an unfolding pattern requiring escalation, but the counterparty-level history (one prior unauthorized return) warrants a person's review before this alert is closed, given the settled status removes any preventive lever. Recommend a person confirm the counterparty's return history is isolated before closing.
Recommendation
hold
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer status is SETTLED with return code none, meaning no hold can be applied to this transaction; 'hold' here reflects deferring closure pending human review rather than freezing funds already moved.
  • The triggering signal (returns.counterparty_prior_unauthorized) concerns counterparty history, not this transfer's own performance, and the evidence set gives no detail on when or how large that prior unauthorized return was.
  • Program-level ach_unauthorized_return_rate is 0 (n=444), which weighs against escalation to a broader pattern.
  • Entity Alder Co 024 is VERIFIED, not high risk, not PEP, with recent screening, which weighs against elevated concern.
  • manual_review_aging_hours is in breach and hold_aging_hours is in watch at the program level, unrelated to this alert directly but indicating queue handling issues that could affect review timeliness.
  • Evidence does not include full counterparty return history detail (count, recency, amounts), so confidence is capped and a person should confirm before closing.

Evidence

{
  "n": 1051,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.