Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $1,710.86 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Northwind Payroll (simulated)
- Subject
- transfer acht_sim_nort_3e8p8tpr23d
- Transfer
- acht_sim_nort_3e8p8tpr23d · $1,710.86 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert e6a78e83-d19b-405f-8e71-5bf3cd22ad89 was opened on 2026-09-17 for transfer acht_sim_nort_3e8p8tpr23d, an outgoing ACH debit of $1,710.86 under program Northwind Payroll. The detector skoor_review fired a Transaction Risk Skoor of 40 (review band, hard_signal false) on a single signal: one prior unauthorized return by the counterparty (weight 40).
What the evidence shows. The transfer itself is SETTLED with return code none, meaning this specific transaction completed without an unauthorized return. The signal reflects the counterparty's history, not an outcome on this transfer. The transfer-level skoor matches the alert-level skoor (40, review band, n=771, confidence 1), and no additional signals are present. The entity behind the transfer, Grove Co 018, is VERIFIED, not high risk, not PEP, has no review reasons, and was screened 2026-07-07. Program KRIs are mostly within normal range: ach_unauthorized_return_rate is 0 (n=302, ok), ach_overall_return_rate 0.99% (ok), sanctioned_country_transfers 0 (ok), stale_screening_share 0 (ok). Two KRIs show watch-level values (pep_flagged_entities=1, high_risk_entity_share=6.06%) and one shows a breach (manual_review_aging_hours=1434.67 hours, n=7), but none of these are tied to this specific transfer or counterparty in the evidence provided.
What was checked. Reviewed the alert evidence, the transfer record (status, return code, amount, dates), the entity verification status and screening history, and the program-level KRI snapshot. No prior dispositions exist for this alert. Counterparty country is listed as unknown; no further counterparty-level detail (name, other transfer history) is provided in this context.
What is recommended. Close the alert. The transfer settled without a return, the entity is verified and carries no elevated risk flags, and the single signal driving the skoor is historical counterparty information rather than an outcome on this transaction. The manual_review_aging_hours breach at the program level is unrelated to this specific transfer and does not by itself indicate a pattern connected to this alert; it may warrant separate operational attention outside this disposition.
- Recommendation
- close
- Confidence
- 0.72
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer status is SETTLED with return code none; no unauthorized return occurred on this transaction itself.
- The only alert signal (returns.counterparty_prior_unauthorized) reflects prior history, not this transfer's outcome, and hard_signal is false.
- Entity is VERIFIED, not high risk, not PEP, with no open review reasons and recent screening.
- Program-level ach_unauthorized_return_rate is 0 and overall return rate is under 1%, indicating no broader return pattern tied to this counterparty type.
- Manual_review_aging_hours breach is a program KRI unrelated to this specific alert's subject and evidence does not connect it to this transfer or counterparty.
- Confidence is moderated because counterparty country is unknown and no further counterparty transaction history is given beyond the single prior unauthorized return.
Evidence
{
"n": 762,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.