Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $1,701.75 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Northwind Payroll (simulated)
- Subject
- transfer acht_sim_nort_ccbqk1hk2sm
- Transfer
- acht_sim_nort_ccbqk1hk2sm · $1,701.75 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An outgoing ACH credit transfer of $1,701.75 from program Northwind Payroll to counterparty cpty_sim_nort_5a6oup6d8m was flagged by the skoor_review detector at a risk score of 40 (review band). The transfer has already settled, with no return code posted.
What the evidence shows. The single signal driving the score is returns.counterparty_prior_unauthorized, indicating this counterparty has one prior unauthorized ACH return on record. The transfer itself has return code none and status SETTLED, so no return has occurred on this specific transaction. The originating entity, Alder Co 024, is VERIFIED, not high risk, not PEP, with no review reasons and screening current as of 2026-08-17. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=444, ok) and ach_overall_return_rate at 0.011 (ok), suggesting this prior unauthorized return has not translated into a broader pattern at the program level. Two KRIs are outside normal range: manual_review_aging_hours is in breach (1434.68 hours, n=8) and hold_aging_hours is in watch (518.28 hours, n=1), both unrelated to this specific alert's transfer but relevant to review-queue handling generally.
What was checked. Reviewed the transfer record, the entity verification status and screening date, the program KRI panel, and prior dispositions for this alert. Prior dispositions: none on file. The counterparty's country is unknown, and the underlying detail behind the 'prior unauthorized return' (date, count beyond one, dollar value) is not provided in this evidence set.
What is recommended. The transfer has already settled, so no hold action applies to funds movement. Given a verified, non-high-risk originating entity, a program-level unauthorized return rate at 0, and only one flagged prior unauthorized return on the counterparty with no further detail, this alert does not show evidence of an unfolding pattern requiring escalation, but the counterparty-level history (one prior unauthorized return) warrants a person's review before this alert is closed, given the settled status removes any preventive lever. Recommend a person confirm the counterparty's return history is isolated before closing.
- Recommendation
- hold
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer status is SETTLED with return code none, meaning no hold can be applied to this transaction; 'hold' here reflects deferring closure pending human review rather than freezing funds already moved.
- The triggering signal (returns.counterparty_prior_unauthorized) concerns counterparty history, not this transfer's own performance, and the evidence set gives no detail on when or how large that prior unauthorized return was.
- Program-level ach_unauthorized_return_rate is 0 (n=444), which weighs against escalation to a broader pattern.
- Entity Alder Co 024 is VERIFIED, not high risk, not PEP, with recent screening, which weighs against elevated concern.
- manual_review_aging_hours is in breach and hold_aging_hours is in watch at the program level, unrelated to this alert directly but indicating queue handling issues that could affect review timeliness.
- Evidence does not include full counterparty return history detail (count, recency, amounts), so confidence is capped and a person should confirm before closing.
Evidence
{
"n": 1051,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.