SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Transaction Risk Skoor 70 (hold band) on a $652.28 ach transfer: entity.pep_potential, returns.counterparty_prior_unauthorized, returns.entity_rate_gt_threshold.

Detector
skoor_hold
Severity
high
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_cei5a3h08md
Transfer
acht_sim_harb_cei5a3h08md · $652.28 · ach outgoing
Skoor at alert
70 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert ef6104f2-996b-4b54-bfc8-f93fc304ac79 fired detector skoor_hold at severity high on ACH outgoing credit transfer acht_sim_harb_cei5a3h08md for $652.28, opened 2026-09-17T19:31:50.252Z. The transfer risk score was 70, placing it in the hold band, driven by three signals: entity.pep_potential (potential PEP match, weight 15), returns.counterparty_prior_unauthorized (1 prior unauthorized return, weight 40), and returns.entity_rate_gt_threshold (entity unauthorized return rate 1/45 originated ACH debits in 60 days, weight 15). What the evidence shows. The transfer itself is already SETTLED with return code none, so no return or dispute has occurred on this specific transaction. The risk signals are entity-level: the originating entity (enti_sim_harb_azbiyidj3x2, PERSON 'Potential Pep 1') carries a pep potential flag, has 1 prior unauthorized return on file, and shows an unauthorized return rate of 1/45 on originated ACH debits in the trailing 60 days. Entity verification status is VERIFIED with no open review reasons and last screened 2026-08-16. At the program level, Harbor Marketplace Payouts shows ach_unauthorized_return_rate at breach (0.0081) and manual_review_aging_hours at breach (1438 hours, n=12), alongside watch-level pep_flagged_entities (1/30) and high_risk_entity_share (0.067/30). Counterparty country is unknown. No prior dispositions exist for this alert. What was checked. Reviewed transfer status and return code, entity verification and screening history, the three contributing risk signals and their weights, program declared volume and rails, and the full program KRI panel including return rate, review aging, and PEP-flagged entity metrics. What is recommended. The transfer has already settled, so there are no funds to hold on this transaction. However, the combination of a PEP-potential entity, a documented prior unauthorized return, an entity-level unauthorized return rate above threshold, and program-wide breaches in ach_unauthorized_return_rate and manual_review_aging_hours indicates a pattern that extends beyond this single alert. This should be escalated for entity-level review and possible reassessment of the PEP status and return history, rather than closed as a one-off.
Recommendation
escalate
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer acht_sim_harb_cei5a3h08md is SETTLED with return code none, so no hold action is available on this transaction.
  • Three converging signals (PEP potential, prior unauthorized return, entity return rate above threshold) point to entity-level risk rather than a transaction-specific defect.
  • Program KRIs show two breach-level metrics (ach_unauthorized_return_rate, manual_review_aging_hours) and two watch-level metrics (pep_flagged_entities, high_risk_entity_share) that align with the alert's signal categories, supporting a pattern read.
  • Entity is VERIFIED with no open review reasons and last screened within 60 days, which tempers urgency but does not resolve the unauthorized return history.
  • Counterparty country is unknown, which limits full risk assessment and is noted as a gap rather than a finding.
  • No prior dispositions exist to indicate this entity has already been reviewed for these signals.

Evidence

{
  "n": 1860,
  "band": "hold",
  "skoor": 70,
  "signals": [
    {
      "code": "entity.pep_potential",
      "detail": "potential PEP match",
      "weight": 15
    },
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "returns.entity_rate_gt_threshold",
      "detail": "entity unauthorized return rate 1/45 originated ACH debits in 60d",
      "weight": 15
    }
  ],
  "autoHold": true,
  "confidence": 1,
  "routeReason": "detector always reviewed"
}

Skoor signals

SignalWeightHardDetail
entity.pep_potential+15potential PEP match
returns.counterparty_prior_unauthorized+402 prior unauthorized return(s)
returns.entity_rate_gt_threshold+15entity unauthorized return rate 1/45 originated ACH debits in 60d

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.