SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 55 (review band) on a $218.35 ach transfer: returns.counterparty_prior_unauthorized, returns.entity_rate_gt_threshold.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_cqaaokoh7du
Transfer
acht_sim_harb_cqaaokoh7du · $218.35 · ach outgoing
Skoor at alert
55 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An ACH outgoing credit of $218.35 from the Harbor Marketplace Payouts program to counterparty cpty_sim_harb_1iejz6444vr was flagged by the skoor_review detector at Skoor 55 (review band, hard_signal false). The transfer has already settled with no return code posted. What the evidence shows. Two signals drove the score: the counterparty has 1 prior unauthorized ACH return on file, and the originating entity's unauthorized return rate is 1/20 (5%) of ACH debits over the trailing 60 days, above the configured threshold. The entity, Dune LLC 115, is VERIFIED, not high risk, not PEP, with no open review reasons and screening current as of 2026-08-16. At the program level, ach_unauthorized_return_rate is flagged as a breach (1.18% over n=507) and manual_review_aging_hours is also flagged as a breach (1438 hours over n=9), while ach_overall_return_rate, verification_denial_rate, and other volume/velocity KRIs are within normal range. No prior dispositions exist for this alert. What was checked. Transfer status and return code, entity verification and screening status, program KRI panel, and prior disposition history. The transfer is SETTLED with no return code, so there are no funds to hold or release. The counterparty's country is unknown, which limits assessment of that side of the relationship. What is recommended. This transfer cannot be held or released since it has already settled. However, the combination of a prior unauthorized return on this specific counterparty, an entity-level unauthorized return rate above threshold, and a program-wide breach on the same unauthorized-return metric suggests this alert may be one instance of a broader pattern rather than an isolated event. This should be escalated for a person to review the counterparty and entity return history together with the program-level breach, rather than closed on this alert alone.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer status is SETTLED with no return code, ruling out hold or release.
  • Counterparty has 1 prior unauthorized return and entity unauthorized return rate (5%) exceeds the alerting threshold.
  • Program KRI ach_unauthorized_return_rate is independently flagged as a breach, indicating the counterparty/entity signal may reflect a wider program-level issue rather than a one-off.
  • Entity itself is verified, low risk, and not under active review reasons, so the concern is specific to counterparty and return-rate signals, not entity standing.
  • Counterparty country is unknown, limiting full assessment; combined with the program-level breach this supports escalation over closure.
  • No prior dispositions exist to indicate this pattern has already been reviewed.

Evidence

{
  "n": 1365,
  "band": "review",
  "skoor": 55,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "returns.entity_rate_gt_threshold",
      "detail": "entity unauthorized return rate 1/20 originated ACH debits in 60d",
      "weight": 15
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)
returns.entity_rate_gt_threshold+15entity unauthorized return rate 1/20 originated ACH debits in 60d

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.