SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $1,290.69 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Meridian Remit (simulated)
Subject
transfer acht_sim_meri_cgv5dtnhbku
Transfer
acht_sim_meri_cgv5dtnhbku · $1,290.69 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An ACH outgoing credit transfer of $1,290.69 (acht_sim_meri_cgv5dtnhbku) under program Meridian Remit was flagged by the skoor_review detector at a Transaction Risk Skoor of 40, placing it in the review band. The triggering signal is returns.counterparty_prior_unauthorized, based on 2 prior unauthorized returns tied to the counterparty cpty_sim_meri_bts0zmjm9td. What the evidence shows. The transfer itself settled with no return code (return code: none), meaning this specific transaction did not fail or get returned. The originating entity, Larch Studio 211, is VERIFIED, not high-risk, not PEP, and was screened recently (2026-08-12). The skoor is driven entirely by the counterparty's return history (n=718, confidence 1, weight 40), not by anything about this transfer's own outcome. At the program level, several KRIs show breach status: ach_unauthorized_return_rate (0.0143, breach), reserve_coverage_ratio (0.80, breach), and manual_review_aging_hours (1146.86, breach). These program-wide breaches, combined with a counterparty carrying a documented pattern of prior unauthorized returns, indicate the concern extends beyond this single settled transfer. What was checked. Transfer status and return code, entity verification and risk flags, program KRI panel, and prior dispositions for this alert (none on file). The transfer is already SETTLED; funds have moved and there is no held transfer to release. What is recommended. This alert should be escalated rather than closed. The individual transfer completed without incident, so no hold or release action applies to it. However, the counterparty's repeated unauthorized-return history combined with concurrent program-level breaches in unauthorized return rate, reserve coverage, and manual review aging suggests a pattern that a single-alert disposition cannot resolve. A person should review the counterparty relationship and the program KRI breaches together, rather than this alert being closed in isolation.
Recommendation
escalate
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Signal returns.counterparty_prior_unauthorized (weight 40, n=718, confidence 1) reflects 2 prior unauthorized returns on this counterparty, not an issue with this specific transfer.
  • This transfer settled with return code none, so there is no held transfer to hold or release.
  • Entity is VERIFIED, not high-risk, no PEP flags, recently screened, reducing entity-level concern for this transaction alone.
  • Program KRIs show three concurrent breaches (ach_unauthorized_return_rate, reserve_coverage_ratio, manual_review_aging_hours) that align thematically with the counterparty's unauthorized-return pattern, indicating a scope beyond this single alert.
  • No prior dispositions exist for this alert, so this is the first review point for the underlying counterparty pattern.
  • Evidence is limited to skoor and KRI summaries; underlying case details for the counterparty's 2 prior unauthorized returns are not included here, which caps confidence.

Evidence

{
  "n": 718,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "2 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+402 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.