Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $876.21 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Harbor Marketplace Payouts (simulated)
- Subject
- transfer acht_sim_harb_163of21a8xt
- Transfer
- acht_sim_harb_163of21a8xt · $876.21 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An outgoing ACH credit of $876.21 from program Harbor Marketplace Payouts to counterparty cpty_sim_harb_gzii64r41f was flagged by the skoor_review detector at Skoor 40 (review band) due to a single signal: the counterparty has 5 prior unauthorized returns. The transfer itself settled with no return code.
What the evidence shows. The transfer status is SETTLED with return code none, so this specific transfer did not itself return unauthorized. The alert score of 40 is driven entirely by the counterparty's return history (weight 40, hard signal false), not by anything on this transaction. The originating entity, Cedar Services 114, is VERIFIED, not high risk, not PEP, with no review reasons and screening current as of 2026-09-01. The counterparty's country is unknown, which limits verification of the counterparty side. Program KRIs show ach_unauthorized_return_rate at 0.00757 flagged as a breach (n=793), and manual_review_aging_hours also flagged as breach (n=15), while frozen_accounts, overdraft_events, pep_flagged_entities, and high_risk_entity_share are at watch level. Other KRIs (reserve_coverage_ratio, velocity_vs_declared, sanctioned_country_transfers, counterparty_concentration_top1) are within normal range.
What was checked. Transfer status and return code, entity verification and risk flags for the originating business, program KRI panel, and prior dispositions (none on file). The counterparty entity record itself is not included in the context beyond its country being unknown, so its own verification status could not be checked.
What is recommended. Since the transfer already settled with no return, there is no transfer to hold or release. However, the counterparty's 5 prior unauthorized returns combined with the program-level breach on ach_unauthorized_return_rate suggests a pattern beyond this single alert that a person should examine at the counterparty or program level, including whether this counterparty should be restricted from future outgoing credits under this program.
- Recommendation
- escalate
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer is SETTLED with return code none; no funds movement to hold or release on this specific alert.
- The only risk signal is counterparty-level history (5 prior unauthorized returns), not a property of this settled transaction.
- Program KRI ach_unauthorized_return_rate is flagged as a breach, which corroborates a broader pattern worth review beyond this single alert.
- Originating entity (Cedar Services 114) is verified, low risk, and recently screened, reducing concern on the originator side.
- Counterparty's country is unknown and no counterparty entity record is provided, leaving a gap in the evidence about that party's verification status.
- No prior dispositions exist for this subject, so this is a first-look pattern for a person to assess rather than a closed matter.
Evidence
{
"n": 1993,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "5 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 5 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.