SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Counterparty Receiver 36 entered the hold band (Skoor 90, n=6): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.return_rate, counterparty.review_share, counterparty.new.

Detector
counterparty_hold
Severity
high
Program
Meridian Remit (simulated)
Subject
counterparty cpty_sim_meri_6hloyf56aa7
Transfer
Skoor at alert
90 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Detector counterparty_hold flagged counterparty cpty_sim_meri_6hloyf56aa7 (Counterparty Receiver 36) after it entered the hold band with a skoor of 90 on n=6 transactions. The alert routed to review because the detector is not auto-closable, and autoHold was set to true. What the evidence shows. Of 6 observed transactions, 1 drew an unauthorized return (unauthorized rate 1/6, above the network threshold, weight 40) and 2 were returned overall (return rate 2/6, weight 15). Half of the 6 transactions fell in the review band (weight 10). The counterparty was first seen 0 days ago, meaning it is brand new with no track record (weight 10). The alert's own confidence field is 0.184, and hard_signal is false, indicating the scoring model itself treats this as a low-certainty read on a very small sample. What was checked. Program-level KRIs for Meridian Remit were reviewed for context. Three are in breach: reserve_coverage_ratio (0.737, n=307), manual_review_aging_hours (1146.9 hours, n=2), and ach_unauthorized_return_rate (0.013, n=307). Other KRIs (frozen_accounts, overdraft_events, manual_review_rate, velocity_vs_declared, stale_screening_share, high_risk_entity_share, verification_denial_rate, sanctioned_country_transfers, ach_administrative_return_rate, counterparty_concentration_top1) are at ok or watch and show no independent signal tying to this specific counterparty. No prior dispositions exist for this alert or this counterparty. The evidence provided does not identify a specific held transfer, so this is not a release-eligible alert. What is recommended. Hold further activity with this counterparty pending manual review. The sample size (n=6) is too small and the alert confidence too low (0.184) to close without a person examining the underlying unauthorized return and the counterparty's onboarding details. The concurrent breach in manual_review_aging_hours at the program level suggests review capacity may already be strained, which raises the importance of a timely look at this new counterparty rather than deferring it.
Recommendation
hold
Confidence
0.42
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Alert reached the hold band per detector configuration (skoor 90) with autoHold true.
  • Evidence is thin: n=6 total transactions, hard_signal false, and detector-reported confidence of 0.184.
  • Counterparty is brand new (first seen 0 days ago), so no history exists to contextualize the single unauthorized return.
  • Program KRI breaches (reserve_coverage_ratio, manual_review_aging_hours, ach_unauthorized_return_rate) are broader program signals, not direct evidence against this counterparty, so they support caution but do not by themselves justify escalation to a pattern-level finding.
  • No prior dispositions exist to indicate this is a repeat or escalating issue for this specific counterparty.
  • Alert does not concern a held transfer, so release is not applicable.

Evidence

{
  "n": 6,
  "band": "hold",
  "skoor": 90,
  "signals": [
    {
      "code": "counterparty.unauthorized_returns",
      "detail": "drew 1 unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "counterparty.unauthorized_rate",
      "detail": "unauthorized rate 1/6 above the network threshold",
      "weight": 15
    },
    {
      "code": "counterparty.return_rate",
      "detail": "return rate 2/6",
      "weight": 15
    },
    {
      "code": "counterparty.review_share",
      "detail": "50% in the review band",
      "weight": 10
    },
    {
      "code": "counterparty.new",
      "detail": "first seen 0d ago",
      "weight": 10
    }
  ],
  "version": "crs-v1",
  "autoHold": true,
  "confidence": 0.184,
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.