SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Transaction Risk Skoor 35 (hold band) on a $2,061.20 ach transfer: structuring.pattern.

Detector
skoor_hold
Severity
high
Program
Lantern Lending (simulated)
Subject
transfer acht_sim_lant_7fzqnsf2eek
Transfer
acht_sim_lant_7fzqnsf2eek · $2,061.20 · ach outgoing
Skoor at alert
35 hold
Hard signal
yes
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An ACH outgoing debit of $2,061.20 from Lantern Lending (entity enti_sim_lant_2spuvci1cfc) to counterparty cpty_sim_lant_6sdfw8xocjp triggered a hold-band Skoor alert (score 35) on 2026-09-17 due to a hard structuring signal: two debits just under $10,000 within 24 hours. The transfer itself has already settled. What the evidence shows. The evidence field shows one hard signal, structuring.pattern, weighted 35, with confidence 1 and routeReason 'hard signal.' The transfer status is SETTLED with no return code, meaning the funds already moved despite the hold-band score. The entity is a verified US business with no PEP flag, no high-risk flag, and no open review reasons; last screened 2026-07-23. Program-level KRIs are mostly in the 'ok' range (return rates, reserve coverage, concentration), but two are flagged: manual_review_aging_hours is in breach (1433.57 hours, n=8) and hold_aging_hours is at watch (1406.45 hours, n=3). There are no prior dispositions on this entity or alert. What was checked. Checked transfer status and amount against the structuring detail cited. Checked entity verification status, PEP status, high-risk flag, and screening recency. Checked program-level KRIs for related stress signals (return rates, concentration, aging). Checked for prior dispositions on this alert or entity; none found. What is recommended. Because the transfer has already settled, there are no funds to hold or release. The hard structuring signal (two debits just under the $10,000 reporting threshold in 24 hours) is not explained or cleared by anything in the evidence and warrants human review of the entity's broader transaction pattern, particularly since manual_review_aging_hours is in breach at the program level, which may indicate a backlog affecting timely review of similar patterns. Recommend escalation for a person to review the entity's full transaction history for a structuring pattern and to consider whether program-level aging KRI breaches are contributing to delayed detection.
Recommendation
escalate
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Hard signal (structuring.pattern) with confidence 1 and routeReason 'hard signal' is present and unexplained by other evidence.
  • Transfer is already SETTLED, so 'hold' or 'release' actions do not apply to this specific transfer.
  • Two debits just under the $10,000 threshold in 24 hours is a named structuring indicator that requires human judgment, not automated closure.
  • Entity is verified with no other risk flags, which limits confidence that this is a large-scale pattern, but the single hard signal is still unresolved.
  • Program KRI manual_review_aging_hours is in breach (1433.57 hours, n=8), suggesting review capacity issues that support escalation rather than closure.
  • No prior dispositions exist to indicate this pattern was already reviewed and cleared.

Evidence

{
  "n": 752,
  "band": "hold",
  "skoor": 35,
  "signals": [
    {
      "code": "structuring.pattern",
      "hard": true,
      "detail": "2 debits just under $10,000 in 24h",
      "weight": 35
    }
  ],
  "autoHold": true,
  "confidence": 1,
  "routeReason": "hard signal"
}

Skoor signals

SignalWeightHardDetail
structuring.pattern+35yes2 debits just under $10,000 in 24h

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.