SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

The entity's first transfer, $1,104.13, above the program median, came 0.0 hours after verification.

Detector
rapid_onboarding
Severity
medium
Program
Meridian Remit (simulated)
Subject
transfer acht_sim_meri_aiqkia8j9q7
Transfer
acht_sim_meri_aiqkia8j9q7 · $1,104.13 · ach outgoing
Skoor at alert
null unscored
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. The entity's first transfer, an outgoing ACH credit of $1,104.13, settled 0.0 hours after identity verification. This amount is above the program median of $641.38. The rapid_onboarding detector fired and the alert was routed to review because the detector is not auto-closable. What the evidence shows. The transfer has already settled, so there is no held transfer to release. The entity is flagged high risk true, is a business ('High Risk Trading 2'), and is VERIFIED with no open review reasons and no PEP flag. Screening was last done 2026-06-26, within the program's normal range (stale_screening_share is 0.03 across n=30, marked ok). The counterparty is a first-time counterparty with country unknown, and the transfer skoor is unscored (n=0, no history to compare against). Signals attached to the transfer are entity.high_risk(+20) and counterparty.first_time(+10), both descriptive rather than derived from a scored model. Program KRIs are largely ok or unmeasured; pep_flagged_entities is at watch (1 of 30) but this entity is not the PEP flagged one (pep: no). No return code is present on the transfer, and ach_overall_return_rate and ach_unauthorized_return_rate are both 0 across n=3, though that sample is small. What was checked. Transfer status and settlement, entity verification and risk flags, screening recency, counterparty history, transfer-level skoor, program-level KRIs, and prior dispositions for this entity or transfer. What is recommended. The transfer has already settled, so holding funds is not an option. The evidence shows a verified entity with no adverse screening findings, but the combination of high-risk designation, first-time counterparty with unknown country, and a same-day transfer above the program median warrants a person's review of the counterparty and the entity's risk classification before this pattern repeats. This is not a case for close given the unresolved counterparty country and high-risk flag; escalate to a person for counterparty verification and monitoring of subsequent transfers from this entity.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:30Z
Rationale
  • Transfer already settled; no funds available to hold or release.
  • Entity is flagged high_risk true and this is a first transfer with a first-time counterparty of unknown country, an unresolved risk pair per the evidence.
  • Entity verification is current and screening is not stale, reducing urgency but not eliminating the counterparty risk gap.
  • Transfer skoor is unscored (n=0) and program KRIs relevant to risk (pep_flagged_entities) show watch status at portfolio level, though not directly tied to this entity.
  • No return code or negative outcome on this transfer itself, which lowers confidence that this is fraud rather than a normal but high-risk-flagged onboarding.
  • Evidence is not sufficient for outright closure given the unresolved counterparty country field and the high-risk entity flag combination.

Evidence

{
  "n": 0,
  "band": "unscored",
  "skoor": null,
  "typology": "rapid_onboarding",
  "confidence": null,
  "thresholds": {
    "hours": 24
  },
  "medianCents": "64138",
  "routeReason": "detector not auto-closable",
  "hoursSinceVerification": 0
}

Skoor signals

SignalWeightHardDetail
entity.high_risk+20entity marked high risk by screening
counterparty.first_time+10first transfer with this counterparty
counterparty.first_time_and_large+15amount above the program p95 (109935)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.