SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $3,181.15 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_5qrqrogt2xo
Transfer
acht_sim_nort_5qrqrogt2xo · $3,181.15 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert e2f6f32c fired on a $3,181.15 outgoing ACH transfer (acht_sim_nort_5qrqrogt2xo) under program Northwind Payroll. The transfer risk skoor was 40, placing it in the review band, driven by a single signal: the counterparty has 1 prior unauthorized return on record. What the evidence shows. The transfer itself settled with no return code (return code: none). The skoor is 40 with hard_signal false, meaning no hard block condition was met; the review band was triggered solely by the counterparty_prior_unauthorized signal at weight 40. The transfer's own history shows n=1117 with confidence 1 on the skoor calculation. The receiving entity, Birch Holdings 013, is VERIFIED, not flagged high risk, not PEP, with no open review reasons, last screened 2026-07-06. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=481, ok) and ach_overall_return_rate at 1.25% (ok), indicating no broader unauthorized-return pattern across the program. Program KRIs do show manual_review_aging_hours in breach (1434.68 hours, n=10) and hold_aging_hours in watch (518.28 hours, n=1), but these are portfolio-level backlog metrics, not evidence tied to this specific transfer or counterparty. What was checked. Transfer status and return code, entity verification status and screening date, program declared volume versus this transfer's size, and all listed program KRIs for corroborating or contradicting signals of unauthorized-return risk or velocity anomalies. No prior dispositions exist for this alert or subject. What is recommended. The transfer has already settled; there is no held transfer to release or hold. The single driving signal is one prior unauthorized return on the counterparty, with no current return, no hard signal, a verified low-risk entity, and no program-level unauthorized-return pattern. Evidence does not point to an issue requiring further transfer-level action. The manual_review_aging_hours breach is a separate program-level condition and should be tracked outside this alert. Recommend closing this alert.
Recommendation
close
Confidence
0.68
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer status is SETTLED with return code none; no funds are pending that could be held or released.
  • Skoor is 40 (review band) with hard_signal false, driven by exactly one signal: counterparty_prior_unauthorized, weight 40.
  • Entity Birch Holdings 013 is VERIFIED, not high risk, not PEP, with no open review reasons and a recent screening date.
  • Program ach_unauthorized_return_rate is 0 across n=481, showing no corroborating pattern of unauthorized returns at the program level.
  • Program manual_review_aging_hours shows a breach (1434.68 hours) and hold_aging_hours is in watch, but these are aggregate backlog KRIs not specific to this transfer or counterparty, so they are noted separately rather than driving this alert's disposition.
  • No prior dispositions exist to inform escalation, and the single soft signal does not meet the bar for hold or escalate given the settled status and clean entity profile.

Evidence

{
  "n": 1117,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.