Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $551.86 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_22p3t9ctdr2
- Transfer
- acht_sim_lant_22p3t9ctdr2 · $551.86 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An ACH outgoing credit transfer of $551.86 (acht_sim_lant_22p3t9ctdr2) under program Lantern Lending was flagged by the skoor_review detector at a risk score of 40 (review band) due to one prior unauthorized return associated with the counterparty (cpty_sim_lant_asr3v7ggcjp).
What the evidence shows. The transfer settled on 2026-08-18 with no return code recorded, meaning this specific transaction did not itself return or fail. The triggering signal is a single prior unauthorized return on the counterparty, weighted at 40, which fully accounts for the review-band score. The originating entity, Juniper LLC 39, is VERIFIED, not flagged high risk, not PEP, has no open review reasons, and was screened as recently as 2026-08-18. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=164), ach_overall_return_rate at 1.22% (n=164, ok), and stale_screening_share at 0 (n=33, ok), indicating no broader pattern of unauthorized returns tied to this program. Counterparty country is listed as unknown, which is a gap in the evidence but does not itself indicate risk beyond what is scored.
What was checked. Transfer status and return code, entity verification and screening status, program-level return and screening KRIs, and prior dispositions on this alert (none found).
What is recommended. Close the alert. The transfer has already settled with no return, the flagged entity is verified with no other risk indicators, and program-wide return rates show no pattern consistent with the single prior counterparty return. No funds are in a holdable state, so release does not apply.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer status is SETTLED with return code none, so the transaction itself completed without incident.
- The alert's only signal is one prior unauthorized return on the counterparty, which is historical and not repeated in this transfer.
- Entity is VERIFIED, not high risk, not PEP, with no open review reasons and recent screening.
- Program KRIs (ach_unauthorized_return_rate=0, ach_overall_return_rate=1.22%, stale_screening_share=0) show no systemic pattern of unauthorized returns.
- Counterparty country is unknown, a minor evidentiary gap that lowers confidence but does not change the disposition given the settled status and clean entity profile.
- No prior dispositions exist on this alert to inform escalation history.
Evidence
{
"n": 455,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.