SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

The entity made 3 ACH debits just under $10,000 within 24 hours.

Detector
structuring_pattern
Severity
high
Program
Harbor Marketplace Payouts (simulated)
Subject
entity enti_sim_harb_kytao1m3ti
Transfer
acht_sim_harb_a0znszfb9k9 · $9,711.80 · ach outgoing
Skoor at alert
65 hold
Hard signal
yes
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. The alert flags entity enti_sim_harb_kytao1m3ti for a structuring pattern: the alert summary states 3 ACH debits just under $10,000 within 24 hours, while the underlying signal detail states 2 debits just under $10,000 in 24h. Only one transfer is included in the evidence, acht_sim_harb_a0znszfb9k9, an outgoing ACH debit of $9,711.80, settled, created 2026-07-27T06:15:35.000Z. The transfer skoor is 65, band hold, with a hard structuring.pattern signal weighted 35, alongside amount.gt_10x_median(+20) and velocity.sum_24h_gt_2x_daily_avg(+10). autoHold is true and routeReason is 'hard signal'. What the evidence shows. The entity is a verified US business, not flagged high risk, not PEP, with no review reasons and a screening date of 2026-07-15 that predates this transfer. Program KRIs are mostly in normal range (ach_overall_return_rate 1.53%, ach_unauthorized_return_rate 0%, reserve_coverage_ratio 5.62), but manual_review_aging_hours shows a breach at 1438 hours on n=2, and high_risk_entity_share and pep_flagged_entities are at watch level. Only one of the transactions referenced by the alert (either 2 or 3, depending on which field is read) is present in the evidence; the other 1-2 debits that would confirm or refute the pattern are not provided. What was checked. Reviewed the transfer record, entity verification and risk status, program KRIs, and prior dispositions. Prior dispositions: none. The alert's own summary and signal detail disagree on the count of near-threshold debits (3 vs 2), and only a single transfer is attached as evidence, so the full structuring pattern cannot be independently confirmed from what is provided. What is recommended. Hold. The structuring signal is hard and the transfer band is hold with autoHold true, which by policy requires a person to review before any further related funds move. A person should pull the complete set of ACH debits in the 24-hour window around 2026-07-27 to reconcile the 2-vs-3 count discrepancy and confirm whether the pattern meets the structuring definition, and should also note the manual_review_aging_hours breach as a separate operational issue.
Recommendation
hold
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Hard signal (structuring.pattern) with autoHold true and band hold per policy requires human review before closing.
  • Alert summary (3 debits) and signal detail (2 debits) disagree, and only 1 transfer is present in evidence, so the pattern is not fully verifiable from the given context.
  • Entity is verified, not high risk, and not PEP, which weighs against escalation absent confirmation of the broader pattern.
  • Transfer status is SETTLED, not held, so 'release' does not apply.
  • manual_review_aging_hours is in breach (1438 hours, n=2), a program-level operational concern not specific to this alert but noted for completeness.

Evidence

{
  "n": 526,
  "band": "hold",
  "skoor": 65,
  "signals": [
    {
      "code": "structuring.pattern",
      "hard": true,
      "detail": "2 debits just under $10,000 in 24h",
      "weight": 35
    }
  ],
  "autoHold": true,
  "routeReason": "hard signal"
}

Skoor signals

SignalWeightHardDetail
amount.gt_10x_median+20amount > 10× program median (42933)
velocity.sum_24h_gt_2x_daily_avg+1024h sum above 2× the program daily average
structuring.pattern+35yes2 debits just under $10,000 in 24h

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.