SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $1,710.86 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_3e8p8tpr23d
Transfer
acht_sim_nort_3e8p8tpr23d · $1,710.86 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert e6a78e83-d19b-405f-8e71-5bf3cd22ad89 was opened on 2026-09-17 for transfer acht_sim_nort_3e8p8tpr23d, an outgoing ACH debit of $1,710.86 under program Northwind Payroll. The detector skoor_review fired a Transaction Risk Skoor of 40 (review band, hard_signal false) on a single signal: one prior unauthorized return by the counterparty (weight 40). What the evidence shows. The transfer itself is SETTLED with return code none, meaning this specific transaction completed without an unauthorized return. The signal reflects the counterparty's history, not an outcome on this transfer. The transfer-level skoor matches the alert-level skoor (40, review band, n=771, confidence 1), and no additional signals are present. The entity behind the transfer, Grove Co 018, is VERIFIED, not high risk, not PEP, has no review reasons, and was screened 2026-07-07. Program KRIs are mostly within normal range: ach_unauthorized_return_rate is 0 (n=302, ok), ach_overall_return_rate 0.99% (ok), sanctioned_country_transfers 0 (ok), stale_screening_share 0 (ok). Two KRIs show watch-level values (pep_flagged_entities=1, high_risk_entity_share=6.06%) and one shows a breach (manual_review_aging_hours=1434.67 hours, n=7), but none of these are tied to this specific transfer or counterparty in the evidence provided. What was checked. Reviewed the alert evidence, the transfer record (status, return code, amount, dates), the entity verification status and screening history, and the program-level KRI snapshot. No prior dispositions exist for this alert. Counterparty country is listed as unknown; no further counterparty-level detail (name, other transfer history) is provided in this context. What is recommended. Close the alert. The transfer settled without a return, the entity is verified and carries no elevated risk flags, and the single signal driving the skoor is historical counterparty information rather than an outcome on this transaction. The manual_review_aging_hours breach at the program level is unrelated to this specific transfer and does not by itself indicate a pattern connected to this alert; it may warrant separate operational attention outside this disposition.
Recommendation
close
Confidence
0.72
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer status is SETTLED with return code none; no unauthorized return occurred on this transaction itself.
  • The only alert signal (returns.counterparty_prior_unauthorized) reflects prior history, not this transfer's outcome, and hard_signal is false.
  • Entity is VERIFIED, not high risk, not PEP, with no open review reasons and recent screening.
  • Program-level ach_unauthorized_return_rate is 0 and overall return rate is under 1%, indicating no broader return pattern tied to this counterparty type.
  • Manual_review_aging_hours breach is a program KRI unrelated to this specific alert's subject and evidence does not connect it to this transfer or counterparty.
  • Confidence is moderated because counterparty country is unknown and no further counterparty transaction history is given beyond the single prior unauthorized return.

Evidence

{
  "n": 762,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.