SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $702.25 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_b13qgy5w8f0
Transfer
acht_sim_harb_b13qgy5w8f0 · $702.25 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert e2f7c761-295d-4aaa-a641-555e2ea35912 fired from the skoor_review detector on ACH outgoing credit transfer acht_sim_harb_b13qgy5w8f0 for $702.25, opened 2026-09-17. The transaction risk skoor is 40, placing it in the review band, driven entirely by one signal: returns.counterparty_prior_unauthorized, weighted 40, noting 3 prior unauthorized returns for this counterparty. The transfer itself is already SETTLED with no return code on this specific transaction. What the evidence shows. The transfer settled cleanly; there is no return coded against it. The flagged risk is historical: the counterparty cpty_sim_harb_gzii64r41f has 3 prior unauthorized returns on record, though its country is unknown. The originating entity, Payout Agent (Harbor), is VERIFIED, not high risk, not PEP, with no review reasons and screening current as of 2026-09-02. At the program level (Harbor Marketplace Payouts), most KRIs are in the ok or watch range, but two are in breach: manual_review_aging_hours (1438.04h, n=10) and ach_unauthorized_return_rate (0.00885, n=678). Hold_aging_hours (1023.97h, n=9) and high_risk_entity_share (0.0667, n=30) are at watch. No prior dispositions exist for this alert. What was checked. Reviewed the transfer record (status, amount, rails, return code), the entity verification and screening status, the program's declared volume and KRI dashboard, and prior disposition history. Confirmed the alert's sole driver is the counterparty's return history rather than any defect in this settled transaction. What is recommended. This specific transfer is settled with no return, so there are no funds to hold and nothing to release. However, the counterparty's 3 prior unauthorized returns, combined with the program's concurrent breach-level ach_unauthorized_return_rate and manual_review_aging_hours, indicate a pattern that extends beyond this single alert. This warrants escalation for a person to assess whether the counterparty or program-level return handling needs broader review, rather than a routine close.
Recommendation
escalate
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer is SETTLED with no return code; no action is possible on this specific transaction, ruling out hold or release.
  • The single driving signal (counterparty_prior_unauthorized, 3 priors) concerns counterparty history, not this transaction's outcome, so it does not by itself justify closing without human review.
  • Program KRIs show two concurrent breaches (ach_unauthorized_return_rate and manual_review_aging_hours), suggesting the individual alert may be part of a broader pattern rather than an isolated event.
  • Entity-level checks (verification, PEP, high-risk, screening recency) are all clean, so the concern is isolated to counterparty history and program-level return metrics, not the originating entity.
  • No prior dispositions exist to indicate this pattern has already been reviewed or resolved.

Evidence

{
  "n": 1746,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "3 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+405 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.