SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $1,948.42 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Lantern Lending (simulated)
Subject
transfer acht_sim_lant_19dig4b9d5e
Transfer
acht_sim_lant_19dig4b9d5e · $1,948.42 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 3606c7a3-0d24-40d6-ba50-3c73cb38084b fired from the skoor_review detector on an outgoing ACH transfer of $1,948.42 (acht_sim_lant_19dig4b9d5e) under program Lantern Lending. The transfer reached a Transaction Risk Skoor of 40, placing it in the review band, driven by a single signal: one prior unauthorized return associated with the counterparty (weight 40). What the evidence shows. The transfer itself is already SETTLED with return code none, meaning no unauthorized or administrative return occurred on this specific transaction. The skoor model (n=220, confidence 0.88) flagged it solely because the counterparty cpty_sim_lant_asr3v7ggcjp has one prior unauthorized return on record; no other risk signals contributed. The receiving/originating entity, Birch Holdings 325, is VERIFIED, not high risk, not PEP, with no open review reasons and screening current as of 2026-06-22. Program-level KRIs are largely within normal range: ach_unauthorized_return_rate=0, ach_overall_return_rate=0, sanctioned_country_transfers=0, high_risk_entity_share=0.030, reserve_coverage_ratio=8.67. Two KRIs show elevated aging (hold_aging_hours watch at 1406 hours, manual_review_aging_hours breach at 1434 hours), but these describe general review-queue timing across the program (n=1, n=2) and are not tied to this specific transfer or counterparty. What was checked. Reviewed the transfer status and return code (settled, no return), the entity verification and screening record, the single triggering signal and its weight, and the full set of program KRIs for corroborating patterns such as elevated return rates, sanctioned-country exposure, or counterparty concentration. No prior dispositions exist for this alert. What is recommended. Because the transfer has already settled without any return, and the only signal is a single historical unauthorized return on the counterparty with no repeat or corroborating pattern in the current period (ach_unauthorized_return_rate=0, n=54), no person needs to intervene on this transfer's funds. The manual_review_aging_hours breach reflects a program-level queue timing issue, not evidence that this alert is part of a broader fraud pattern, so escalation is not supported by the data provided. This can be closed.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer status is SETTLED with return code none, indicating no current unauthorized or failed return.
  • The only triggering signal is a single prior unauthorized return on the counterparty; program-wide ach_unauthorized_return_rate is 0 (n=54), showing no broader pattern.
  • Entity is VERIFIED, not high risk, not PEP, with no open review reasons and screening within the last quarter.
  • Program KRIs are mostly in the 'ok' band; the two flagged KRIs (hold_aging_hours watch, manual_review_aging_hours breach) are program-level queue metrics with small sample sizes (n=1, n=2) and not directly linked to this transfer or counterparty.
  • No prior dispositions exist to suggest recurrence for this counterparty or entity.

Evidence

{
  "n": 220,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 0.88,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.