SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $2,803.18 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Northwind Payroll (simulated)
Subject
transfer acht_sim_nort_4mm8g67g34w
Transfer
acht_sim_nort_4mm8g67g34w · $2,803.18 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An automated review flagged an outgoing ACH transfer of $2,803.18 under program Northwind Payroll (simulated). The transfer risk score is 40, placing it in the review band. The triggering signal is a single prior unauthorized return associated with the counterparty. What the evidence shows. The evidence array shows one signal, returns.counterparty_prior_unauthorized, weight 40, detail '1 prior unauthorized return(s)', confidence 1, n=1180. The transfer itself has status SETTLED with return code none, meaning no return occurred on this specific transaction. The counterparty's country is unknown. The originating entity, Kestrel Partners 022, is VERIFIED, not high risk, not PEP, with no review reasons and a screening date of 2026-09-02, within a reasonable window of the transfer creation date of 2026-09-04. Hard_signal is false, indicating the detector did not treat this as a definitive risk marker. Program-level KRIs show ach_unauthorized_return_rate at 0.0019 (n=518, ok) and ach_overall_return_rate at 0.0135 (n=518, ok), both within normal range, which does not support a broader pattern of unauthorized returns tied to this program or counterparty base. What was checked. Transfer status and return code, entity verification status and screening recency, program declared volume and rail/country scope, program-level KRI panel including return rates, concentration, and review aging metrics, and prior dispositions on this alert (none found). What is recommended. No person action is required on this specific transfer since it is already settled with no return and the underlying entity is verified and clean. The single prior unauthorized return on the counterparty is the sole basis for the alert and does not, on its own or against program KRIs, indicate an active or emerging pattern. Separately, the program-level manual_review_aging_hours KRI shows a breach (1434.68 hours, n=10), which is not tied to this alert but may warrant separate attention by the risk team outside this disposition.
Recommendation
close
Confidence
0.68
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is SETTLED with return code none; there is no pending movement of funds to hold or release.
  • The alert rests on a single signal (one prior unauthorized return) with hard_signal false, indicating it is not a definitive risk marker on its own.
  • Entity is VERIFIED, not high risk, not PEP, with no review reasons and screening within roughly two days of the transfer.
  • Program-level unauthorized and overall ACH return rates are both within normal ranges (0.0019 and 0.0135 respectively), which does not support a pattern beyond this single historical event.
  • The manual_review_aging_hours KRI breach is a program-wide condition unrelated to the specifics of this transfer and should be tracked separately rather than driving this disposition.
  • No prior dispositions exist on this alert to indicate recurring escalation.

Evidence

{
  "n": 1180,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.