Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $1,533.08 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_a0lqr8osejn
- Transfer
- acht_sim_lant_a0lqr8osejn · $1,533.08 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An ACH outgoing credit transfer of $1,533.08 from entity Birch Holdings 31 (program Lantern Lending) settled on 2026-08-30 and was flagged by the skoor_review detector at a risk score of 40 (review band) due to a single prior unauthorized return associated with the counterparty.
What the evidence shows. The transfer has already settled with no return code recorded, meaning no funds are currently held or reversible through this alert. The sole risk signal is returns.counterparty_prior_unauthorized, weighted 40, based on 1 prior unauthorized return for counterparty cpty_sim_lant_asr3v7ggcjp. The counterparty's country is unknown, and there is no further detail on the prior unauthorized return's date, amount, or resolution. The subject entity is VERIFIED, not high risk, not PEP, with no open review reasons, and was last screened 2026-08-18. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=219, ok), meaning this alert does not appear reflected in a broader unauthorized-return trend at the program level. Two KRIs show breach/watch status: manual_review_aging_hours (breach, n=6) and hold_aging_hours (watch, n=2), and pep_flagged_entities is at watch (1 of 33), but none of these directly connect to this transfer or counterparty.
What was checked. Transfer status and return code, program KRIs for unauthorized/administrative/overall return rates, entity verification status and screening date, and prior dispositions on this alert (none found). No additional detail is present in the evidence for the nature or timing of the counterparty's prior unauthorized return.
What is recommended. Since the transfer has already settled and there is no held transfer to release or block, no immediate funds-control action applies. However, the single unauthorized-return signal on this counterparty, combined with unknown counterparty country and no detail on the prior return, is a fact pattern a person should review before this counterparty is used again. Recommend a person review the counterparty's transaction history and prior unauthorized return before closing.
- Recommendation
- hold
- Confidence
- 0.50
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer is SETTLED with no return code; there are no funds to release or reverse under this alert.
- The only risk signal is a single prior unauthorized return tied to the counterparty, with no additional detail provided (date, amount, resolution).
- Counterparty country is unknown, which limits the ability to assess screening or risk exposure.
- Program-level ach_unauthorized_return_rate is 0 (n=219, ok), indicating no broader pattern at the program level tied to unauthorized returns.
- Subject entity is verified, not high risk, not PEP, with no open review reasons, reducing entity-level concern.
- Because the underlying counterparty risk (prior unauthorized return) is unresolved and could affect future transfers, a person should review before this is closed, even though this specific transfer has already settled.
Evidence
{
"n": 587,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.