SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $1,956.09 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Lantern Lending (simulated)
Subject
transfer acht_sim_lant_kvkjx35e0u
Transfer
acht_sim_lant_kvkjx35e0u · $1,956.09 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 24d9cf33-0828-4b01-a67c-be8169a63141 fired on outgoing ACH transfer acht_sim_lant_kvkjx35e0u for $1,956.09, flagged by the skoor_review detector at a risk score of 40 (review band). The triggering signal is returns.counterparty_prior_unauthorized, noting one prior unauthorized return associated with counterparty cpty_sim_lant_asr3v7ggcjp, weighted 40 of the total 40-point score. What the evidence shows. The transfer itself settled on 2026-08-30 with return code none, meaning no return, unauthorized or otherwise, occurred on this transaction. The originating entity, Iris Services 320, is a US business with verification status VERIFIED, no PEP flag, no high-risk flag, and no review reasons, last screened 2026-08-19. The counterparty's country is unknown, but no other adverse data on the counterparty is present beyond the single prior unauthorized return cited in the signal. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=219, ok) and ach_overall_return_rate at 0.0137 (n=219, ok), both within normal range, indicating this alert is not part of a broader return pattern at the program level. Two KRIs are flagged watch or breach: hold_aging_hours (1406.4, watch) and manual_review_aging_hours (1433.6, breach), but these describe program-wide review handling delays, not this specific transfer or counterparty. There are no prior dispositions on this alert. What was checked. Reviewed the transfer record (status, amount, return code, dates), the triggering signal detail and weight, the entity's verification and risk profile, and the full set of program KRIs for corroborating patterns in returns, sanctions exposure, or entity risk concentration. Checked for prior dispositions on this alert, of which none exist. What is recommended. The transfer has already settled with no return recorded, so there are no funds to hold and release does not apply. The single prior unauthorized return on this counterparty is the only adverse data point; it is not corroborated by elevated program-wide unauthorized return rates, entity risk flags, or other signals in this alert. A person should confirm there is no additional counterparty history outside this alert's evidence before closing, but based on what is documented here, the alert does not show cause to hold or escalate. Recommend close, with a note that if this counterparty generates a second unauthorized return, escalation would be warranted.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer status is SETTLED with return code none; no unauthorized return occurred on this transaction itself.
  • The only adverse signal is one prior unauthorized return on the counterparty, carrying the full 40-point score; no additional corroborating signals are present.
  • Entity is VERIFIED, not high-risk, not PEP, with no open review reasons and recent screening.
  • Program-level ach_unauthorized_return_rate is 0 (n=219), indicating no broader pattern of unauthorized returns tied to this program.
  • Aging KRIs (hold_aging_hours watch, manual_review_aging_hours breach) reflect program-wide review-queue timing, not evidence specific to this transfer or counterparty.
  • Confidence is moderate rather than high because the counterparty's country is unknown and no detail is given on when or how the prior unauthorized return occurred.

Evidence

{
  "n": 585,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.