SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $878.44 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_a3mijuzw3hg
Transfer
acht_sim_nort_a3mijuzw3hg · $878.44 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert f61b9b7b-e19a-43aa-8207-56d608afbc10 fired on transfer acht_sim_nort_a3mijuzw3hg, an $878.44 outgoing ACH credit under program Northwind Payroll, due to a Transaction Risk Skoor of 40 (review band) driven by a single signal: the counterparty has one prior unauthorized ACH return on record. What the evidence shows. The transfer itself settled with no return code, so this specific movement was not returned or flagged as unauthorized. The skoor of 40 is generated entirely by the one signal returns.counterparty_prior_unauthorized (weight 40, detail: 1 prior unauthorized return). Hard signal is false. The counterparty's country is unknown, but the paying entity, Heath Holdings 07, is verified, not high risk, not PEP, has no open review reasons, and was screened 2026-09-04. Program-level KRIs show ach_unauthorized_return_rate at 0.17% (n=599, ok) and ach_overall_return_rate at 1.34% (ok), both within normal range, indicating this is not part of an elevated return pattern at the program level. manual_review_aging_hours is in breach (1434.69 hours, n=11) and hold_aging_hours is at watch (518.28 hours, n=1), which reflect queue-handling metrics rather than anything specific to this transfer. What was checked. Transfer status and return code, entity verification and screening status, the single driving signal and its weight, program declared volume and rails, and the full set of program KRIs for corroborating patterns (unauthorized return rate, overall return rate, high-risk entity share, sanctioned country transfers, counterparty concentration). No prior dispositions exist for this alert. What is recommended. Close the alert. The transfer already settled without a return, the score rests on a single historical counterparty signal rather than a current unauthorized return, the paying entity is verified with no other risk indicators, and program-level return-rate KRIs are within normal bounds. The manual_review_aging_hours breach is a queue-level metric across 11 items and is not evidence tied to this specific transfer; it should be tracked separately, not used to hold this alert.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer acht_sim_nort_a3mijuzw3hg settled with return code none, so no current unauthorized return occurred on this movement.
  • The entire skoor of 40 is attributable to one signal: a single prior unauthorized return on the counterparty, with hard_signal false.
  • Entity Heath Holdings 07 is VERIFIED, not high risk, not PEP, with no open review reasons and recent screening (2026-09-04).
  • Program KRIs ach_unauthorized_return_rate (0.17%) and ach_overall_return_rate (1.34%) are within ok range, showing no broader pattern of unauthorized or returned transfers.
  • manual_review_aging_hours is in breach but reflects program queue aging (n=11), not a fact about this specific transfer, so it does not itself justify holding this alert.
  • Evidence is limited to a single signal and no prior dispositions exist, which caps confidence below high.

Evidence

{
  "n": 1336,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.