Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $659.82 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_aixhjfjqeas
- Transfer
- acht_sim_lant_aixhjfjqeas · $659.82 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. A skoor_review alert fired on a settled ACH outgoing credit of $659.82 from program Lantern Lending, transfer acht_sim_lant_aixhjfjqeas, because the counterparty has one prior unauthorized ACH return on record.
What the evidence shows. The transaction risk skoor is 40, placing it in the review band, driven solely by the signal returns.counterparty_prior_unauthorized (weight 40, detail: 1 prior unauthorized return). The transfer itself carries no return code and is already SETTLED. The associated entity, Birch Holdings 31, is VERIFIED, not high risk, not PEP, with no review reasons, last screened 2026-08-18. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=271) and ach_overall_return_rate at 0.011 (n=271), both in the ok range, with no sanctioned_country_transfers and low counterparty concentration (0.127). manual_review_aging_hours shows a breach (1433.6 hours, n=8) and hold_aging_hours is flagged watch (1406.4 hours, n=3), indicating review backlog at the program level but not specific to this transfer. Prior dispositions for this alert: none.
What was checked. Reviewed the alert evidence block, the transfer record (status, return code, amount, rails, counterparty), the entity verification status and risk flags, and the program KRI panel for corroborating patterns (unauthorized return rate, sanctioned country exposure, concentration, PEP flags). No other signals beyond the single prior-unauthorized-return code were present in the evidence.
What is recommended. This transfer has already settled, so there is no fund movement to hold or release. The single driving signal is one historical unauthorized return by the counterparty, with no unauthorized return on this transfer itself and no other risk indicators on the entity or program tied to this transfer. Absent additional signals or a pattern across other transfers with this counterparty, this alert can be closed. The program-level manual_review_aging_hours breach is noted separately and should be tracked as a program-level operational item, not as grounds to hold this individual settled transfer.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is SETTLED; there is no held transfer to act on, so hold/release do not apply.
- Only one signal drives the skoor (prior unauthorized return, weight 40); no unauthorized return occurred on this transfer.
- Entity is VERIFIED, not high risk, not PEP, with no review reasons and recent screening.
- Program KRIs for unauthorized/overall return rates, sanctioned country exposure, and concentration are all in the ok range, showing no broader pattern tied to this alert.
- manual_review_aging_hours and hold_aging_hours flags are program-level operational metrics, not specific to this transfer or counterparty, and do not by themselves indicate this alert needs escalation.
- Evidence set is thin (single signal, no counterparty transaction history beyond the one prior return), which limits certainty; confidence is set moderately rather than high.
Evidence
{
"n": 719,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.