SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $876.21 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Harbor Marketplace Payouts (simulated)
Subject
transfer acht_sim_harb_163of21a8xt
Transfer
acht_sim_harb_163of21a8xt · $876.21 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An outgoing ACH credit of $876.21 from program Harbor Marketplace Payouts to counterparty cpty_sim_harb_gzii64r41f was flagged by the skoor_review detector at Skoor 40 (review band) due to a single signal: the counterparty has 5 prior unauthorized returns. The transfer itself settled with no return code. What the evidence shows. The transfer status is SETTLED with return code none, so this specific transfer did not itself return unauthorized. The alert score of 40 is driven entirely by the counterparty's return history (weight 40, hard signal false), not by anything on this transaction. The originating entity, Cedar Services 114, is VERIFIED, not high risk, not PEP, with no review reasons and screening current as of 2026-09-01. The counterparty's country is unknown, which limits verification of the counterparty side. Program KRIs show ach_unauthorized_return_rate at 0.00757 flagged as a breach (n=793), and manual_review_aging_hours also flagged as breach (n=15), while frozen_accounts, overdraft_events, pep_flagged_entities, and high_risk_entity_share are at watch level. Other KRIs (reserve_coverage_ratio, velocity_vs_declared, sanctioned_country_transfers, counterparty_concentration_top1) are within normal range. What was checked. Transfer status and return code, entity verification and risk flags for the originating business, program KRI panel, and prior dispositions (none on file). The counterparty entity record itself is not included in the context beyond its country being unknown, so its own verification status could not be checked. What is recommended. Since the transfer already settled with no return, there is no transfer to hold or release. However, the counterparty's 5 prior unauthorized returns combined with the program-level breach on ach_unauthorized_return_rate suggests a pattern beyond this single alert that a person should examine at the counterparty or program level, including whether this counterparty should be restricted from future outgoing credits under this program.
Recommendation
escalate
Confidence
0.55
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer is SETTLED with return code none; no funds movement to hold or release on this specific alert.
  • The only risk signal is counterparty-level history (5 prior unauthorized returns), not a property of this settled transaction.
  • Program KRI ach_unauthorized_return_rate is flagged as a breach, which corroborates a broader pattern worth review beyond this single alert.
  • Originating entity (Cedar Services 114) is verified, low risk, and recently screened, reducing concern on the originator side.
  • Counterparty's country is unknown and no counterparty entity record is provided, leaving a gap in the evidence about that party's verification status.
  • No prior dispositions exist for this subject, so this is a first-look pattern for a person to assess rather than a closed matter.

Evidence

{
  "n": 1993,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "5 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+405 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.