Alert · reviewed · held
Counterparty Receiver 12 entered the hold band (Skoor 90, n=17): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.review_share, counterparty.new.
- Detector
- counterparty_hold
- Severity
- high
- Program
- Northwind Payroll (simulated)
- Subject
- counterparty cpty_sim_nort_2vu2cgc34a
- Transfer
- —
- Skoor at alert
- 90 hold
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Counterparty cpty_sim_nort_2vu2cgc34a, associated with the Northwind Payroll (simulated) program, was placed in the hold band by the counterparty_hold detector on 2026-09-17. The counterparty's Skoor reached 90 against a hold threshold, based on 17 observed transactions.
What the evidence shows. Of 17 transactions, 1 drew an unauthorized return, which alone contributed 40 of the 90 points. The unauthorized rate (1/17) and return rate (1/17) each exceeded the network threshold, adding 15 points apiece. 43% of the counterparty's activity sits in the review band (10 points), and the counterparty is new, first seen 0 days ago (10 points). The detector's own confidence in this scoring is stated as 0.334, and hard_signal is false, meaning no deterministic rule (e.g., a confirmed fraud match) drove the hold - it is a composite risk score.
What was checked. Program-level KRIs for Northwind Payroll show most metrics in range: overall ACH return rate 0.73%, unauthorized return rate 0%, sanctioned country transfers 0, frozen accounts 0, overdraft events 0, reserve coverage 2.66x. Two metrics are at watch: pep_flagged_entities (1 of 33) and high_risk_entity_share (6.06%). One metric is in breach: manual_review_aging_hours at 1434.7 hours (n=6), indicating a backlog in review turnaround, though this is a program-wide figure and not specific to this counterparty. No prior dispositions exist for this alert or counterparty.
What is recommended. This is a new counterparty with a small transaction sample (n=17) that has already produced one unauthorized return, and it has been auto-placed in the hold band. The evidence does not show a broader pattern across the program (return and unauthorized rates program-wide are near zero), so escalation is not supported. However, the single unauthorized return, low sample size, and newness of the counterparty mean a person should review the counterparty and any pending transfers before further funds move. The alert itself does not identify a specific transfer already held, so release is not applicable here.
- Recommendation
- hold
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Skoor 90 places the counterparty in the hold band per detector configuration (autoHold=true), driven primarily by one unauthorized return (40 of 90 points).
- Detector confidence is low (0.334) and hard_signal is false, meaning this is a composite score without a deterministic fraud confirmation, warranting human review rather than automatic closure.
- Sample size is small (n=17) and the counterparty is new (0 days), limiting the reliability of the rate-based signals.
- Program-wide KRIs (ach_unauthorized_return_rate=0, ach_overall_return_rate=0.73%, sanctioned_country_transfers=0) do not show a program-wide pattern, so escalation beyond this single counterparty is not supported by current evidence.
- Manual_review_aging_hours is in breach (1434.7 hours, n=6), which is relevant context for review timeliness but is a program-level metric, not specific evidence about this counterparty.
- No prior dispositions exist to inform whether this counterparty was previously reviewed or cleared.
Evidence
{
"n": 17,
"band": "hold",
"skoor": 90,
"signals": [
{
"code": "counterparty.unauthorized_returns",
"detail": "drew 1 unauthorized return(s)",
"weight": 40
},
{
"code": "counterparty.unauthorized_rate",
"detail": "unauthorized rate 1/17 above the network threshold",
"weight": 15
},
{
"code": "counterparty.return_rate",
"detail": "return rate 1/17",
"weight": 15
},
{
"code": "counterparty.review_share",
"detail": "43% in the review band",
"weight": 10
},
{
"code": "counterparty.new",
"detail": "first seen 0d ago",
"weight": 10
}
],
"version": "crs-v1",
"autoHold": true,
"confidence": 0.334,
"routeReason": "detector not auto-closable"
}
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.