SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $887.79 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Lantern Lending (simulated)
Subject
transfer acht_sim_lant_2mdaoae4db4
Transfer
acht_sim_lant_2mdaoae4db4 · $887.79 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An ACH outgoing credit of $887.79 to counterparty cpty_sim_lant_asr3v7ggcjp under program Lantern Lending was flagged by the skoor_review detector with a Transaction Risk Skoor of 40, placing it in the review band. The triggering signal is a record of one prior unauthorized return associated with this counterparty. What the evidence shows. The transfer status is SETTLED with return code none, meaning no return occurred on this transaction itself. The skoor of 40 rests entirely on a single signal, returns.counterparty_prior_unauthorized, weighted 40, with model confidence 0.805 over a sample of 290. The subject entity, Elm Partners 34, is VERIFIED, not high risk, not PEP, with no review reasons and a screening date of 2026-06-27. Program-level KRIs are mostly in the 'ok' band: ach_unauthorized_return_rate=0, ach_overall_return_rate=0, sanctioned_country_transfers=0, counterparty_concentration_top1=0.179, reserve_coverage_ratio=5.36. Two KRIs show watch/breach status (hold_aging_hours watch at n=1, manual_review_aging_hours breach at n=3), but these describe program-wide review handling timelines and are not tied to this specific transfer or counterparty. What was checked. Reviewed transfer status and return code, entity verification and risk flags, program KRI panel, and prior dispositions (none on file). Counterparty country is listed as unknown, and no additional counterparty-level detail beyond the single prior unauthorized return is provided in the evidence. What is recommended. The transfer has already settled with no return, and the flagged counterparty risk signal is a single historical event rather than a recurring pattern. The subject entity carries no elevated risk markers. Absent evidence of a broader pattern or a transfer still pending movement, no operational hold action is applicable. This can be closed, with a note that the counterparty's unauthorized return history warrants continued monitoring on future transfers with this counterparty.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer status is SETTLED with return code none; there is no pending movement to hold or release.
  • The alert rests on a single signal (one prior unauthorized return) with no recurrence in this transaction.
  • Subject entity is VERIFIED, not high risk, not PEP, with no review reasons noted.
  • Program KRIs for unauthorized and overall return rates are 0, showing no broader return pattern.
  • Two program KRIs (hold_aging_hours, manual_review_aging_hours) show watch/breach status but reflect review-queue timing across the program, not this specific counterparty or transfer, so they do not by themselves indicate a pattern tied to this alert.
  • No prior dispositions exist on this subject to indicate repeat alerting.

Evidence

{
  "n": 290,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 0.805,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.