SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

The entity made 3 ACH debits just under $10,000 within 24 hours.

Detector
structuring_pattern
Severity
high
Program
Lantern Lending (simulated)
Subject
entity enti_sim_lant_2spuvci1cfc
Transfer
acht_sim_lant_7fzqnsf2eek · $2,061.20 · ach outgoing
Skoor at alert
35 hold
Hard signal
yes
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An automated structuring-pattern detector flagged entity enti_sim_lant_2spuvci1cfc (Lantern Lending) for ACH debit activity described in the alert summary as three debits just under $10,000 within 24 hours. The alert carries a hard signal and triggered an automatic hold with a skoor of 35 in the hold band. What the evidence shows. The signal detail attached to the alert states '2 debits just under $10,000 in 24h,' which does not match the summary's count of three. The single transfer record provided, acht_sim_lant_7fzqnsf2eek, is an ACH outgoing debit of $2,061.20 settled on 2026-09-11, which is not close to the $10,000 threshold described by the structuring signal. No other transfer records are included in the evidence to support the structuring claim. The entity is verified, not flagged high risk, not PEP, and has no review reasons on file, last screened 2026-07-23. Program-level KRIs show manual_review_aging_hours in breach (1433.6 hours, n=8) and hold_aging_hours and pep_flagged_entities in watch status; other KRIs including ach return rates, counterparty concentration, and verification denial rate are within normal range. What was checked. The alert summary, signal detail, and the one attached transfer record were compared for consistency. The entity's verification status, risk flags, and screening date were reviewed. Program KRIs were reviewed for related stress indicators. Prior dispositions were checked and none exist for this entity. What is recommended. The structuring claim in the summary is not corroborated by the single transfer provided, and the signal detail itself disagrees with the summary on the count of debits. This inconsistency, combined with the hard signal and autoHold, means the alert should not be closed without a person confirming the actual set of transactions behind the structuring determination. No transfer is currently held pending release; the settled transfer shown is not itself under hold. Recommend a person pull the full 24-hour transaction list for this entity to verify whether a structuring pattern in fact exists before any further action.
Recommendation
hold
Confidence
0.42
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Hard signal (structuring.pattern) with autoHold true and band=hold per skoor evidence
  • Alert summary states 3 debits just under $10,000 but the signal detail states 2, a direct inconsistency in the evidence
  • The only transfer record provided ($2,061.20, settled) does not match the described near-$10,000 structuring pattern, so the specific evidence does not corroborate the alert's own summary
  • Entity is verified, not high risk, not PEP, no review reasons, recently screened, which weighs against escalation absent confirmed transaction data
  • manual_review_aging_hours KRI is in breach (1433.6h, n=8), indicating review backlog risk that supports not closing without human confirmation
  • No prior dispositions exist for this entity, so there is no history to lean on for a close decision

Evidence

{
  "n": 752,
  "band": "hold",
  "skoor": 35,
  "signals": [
    {
      "code": "structuring.pattern",
      "hard": true,
      "detail": "2 debits just under $10,000 in 24h",
      "weight": 35
    }
  ],
  "autoHold": true,
  "routeReason": "hard signal"
}

Skoor signals

SignalWeightHardDetail
structuring.pattern+35yes2 debits just under $10,000 in 24h

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.