SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Counterparty Receiver 12 entered the hold band (Skoor 90, n=17): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.review_share, counterparty.new.

Detector
counterparty_hold
Severity
high
Program
Northwind Payroll (simulated)
Subject
counterparty cpty_sim_nort_2vu2cgc34a
Transfer
Skoor at alert
90 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Counterparty cpty_sim_nort_2vu2cgc34a, associated with the Northwind Payroll (simulated) program, was placed in the hold band by the counterparty_hold detector on 2026-09-17. The counterparty's Skoor reached 90 against a hold threshold, based on 17 observed transactions. What the evidence shows. Of 17 transactions, 1 drew an unauthorized return, which alone contributed 40 of the 90 points. The unauthorized rate (1/17) and return rate (1/17) each exceeded the network threshold, adding 15 points apiece. 43% of the counterparty's activity sits in the review band (10 points), and the counterparty is new, first seen 0 days ago (10 points). The detector's own confidence in this scoring is stated as 0.334, and hard_signal is false, meaning no deterministic rule (e.g., a confirmed fraud match) drove the hold - it is a composite risk score. What was checked. Program-level KRIs for Northwind Payroll show most metrics in range: overall ACH return rate 0.73%, unauthorized return rate 0%, sanctioned country transfers 0, frozen accounts 0, overdraft events 0, reserve coverage 2.66x. Two metrics are at watch: pep_flagged_entities (1 of 33) and high_risk_entity_share (6.06%). One metric is in breach: manual_review_aging_hours at 1434.7 hours (n=6), indicating a backlog in review turnaround, though this is a program-wide figure and not specific to this counterparty. No prior dispositions exist for this alert or counterparty. What is recommended. This is a new counterparty with a small transaction sample (n=17) that has already produced one unauthorized return, and it has been auto-placed in the hold band. The evidence does not show a broader pattern across the program (return and unauthorized rates program-wide are near zero), so escalation is not supported. However, the single unauthorized return, low sample size, and newness of the counterparty mean a person should review the counterparty and any pending transfers before further funds move. The alert itself does not identify a specific transfer already held, so release is not applicable here.
Recommendation
hold
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Skoor 90 places the counterparty in the hold band per detector configuration (autoHold=true), driven primarily by one unauthorized return (40 of 90 points).
  • Detector confidence is low (0.334) and hard_signal is false, meaning this is a composite score without a deterministic fraud confirmation, warranting human review rather than automatic closure.
  • Sample size is small (n=17) and the counterparty is new (0 days), limiting the reliability of the rate-based signals.
  • Program-wide KRIs (ach_unauthorized_return_rate=0, ach_overall_return_rate=0.73%, sanctioned_country_transfers=0) do not show a program-wide pattern, so escalation beyond this single counterparty is not supported by current evidence.
  • Manual_review_aging_hours is in breach (1434.7 hours, n=6), which is relevant context for review timeliness but is a program-level metric, not specific evidence about this counterparty.
  • No prior dispositions exist to inform whether this counterparty was previously reviewed or cleared.

Evidence

{
  "n": 17,
  "band": "hold",
  "skoor": 90,
  "signals": [
    {
      "code": "counterparty.unauthorized_returns",
      "detail": "drew 1 unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "counterparty.unauthorized_rate",
      "detail": "unauthorized rate 1/17 above the network threshold",
      "weight": 15
    },
    {
      "code": "counterparty.return_rate",
      "detail": "return rate 1/17",
      "weight": 15
    },
    {
      "code": "counterparty.review_share",
      "detail": "43% in the review band",
      "weight": 10
    },
    {
      "code": "counterparty.new",
      "detail": "first seen 0d ago",
      "weight": 10
    }
  ],
  "version": "crs-v1",
  "autoHold": true,
  "confidence": 0.334,
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.