SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $2,550.33 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Lantern Lending (simulated)
Subject
transfer acht_sim_lant_8fk1rdsndh8
Transfer
acht_sim_lant_8fk1rdsndh8 · $2,550.33 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 1c1f0e97-15f7-4ec9-be5e-749ea8155409 was opened by the skoor_review detector on transfer acht_sim_lant_8fk1rdsndh8, an outgoing ACH credit of $2,550.33 from program Lantern Lending. The transfer scored 40, placing it in the review band, driven by a single signal: the counterparty cpty_sim_lant_c9qj5z42ckx has 1 prior unauthorized return on record. What the evidence shows. The transfer itself is SETTLED with return code none, so no return or dispute occurred on this transaction. The skoor is built from n=364 with confidence 0.925, and the only contributing signal is the counterparty's single prior unauthorized return (weight 40). Hard_signal is false. The originating entity, Juniper LLC 39, is VERIFIED, not flagged high risk, not PEP, has no open review reasons, and was screened 2026-06-19. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=110) and ach_overall_return_rate at 0.9% (n=110), both in the ok range, indicating no broader unauthorized-return pattern in this program. manual_review_aging_hours shows a breach (1433.5 hours, n=3) and hold_aging_hours and pep_flagged_entities are in watch status, but these are program-wide backlog/queue metrics, not specific to this transfer or entity. What was checked. Transfer status and return code, entity verification and screening status, the single contributing risk signal and its underlying detail, and program KRIs for unauthorized/overall return rates, high-risk entity share, and review aging. Prior dispositions on this alert: none. What is recommended. Close the alert. The transfer has already settled without a return, the entity is verified with no adverse findings, and the only signal is a single historical unauthorized return on the counterparty that has not recurred (program unauthorized return rate is 0 across 110 transfers). No transfer is pending, so there is nothing to hold. The manual_review_aging_hours breach is a program-level queue issue unrelated to this specific transfer and should be tracked separately, not as grounds to hold this settled transaction.
Recommendation
close
Confidence
0.68
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer status is SETTLED with return code none, so no current return or unauthorized activity is present on this transaction.
  • The sole risk signal is one prior unauthorized return for the counterparty; program-wide ach_unauthorized_return_rate is 0 across n=110, showing no pattern.
  • Entity is VERIFIED, not high risk, not PEP, with no open review reasons and screening within the last 3 months.
  • hard_signal is false and skoor sits at the low end of the review band (40).
  • manual_review_aging_hours breach and hold_aging_hours/pep_flagged_entities watch status are program-level metrics not tied to this specific transfer and do not by themselves indicate an issue with this alert.
  • Release is not applicable since the transfer already settled rather than being held.

Evidence

{
  "n": 364,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 0.925,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.