Alert · reviewed · held
The entity's first transfer, $2,400.00, above the program median, came 0.0 hours after verification.
- Detector
- rapid_onboarding
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_619wbdb5ej7
- Transfer
- acht_sim_lant_619wbdb5ej7 · $2,400.00 · ach outgoing
- Skoor at alert
- 60 hold
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. A rapid-onboarding alert fired on the first transfer for entity Denied Origin 3 (enti_sim_lant_9312rknkcja) under program Lantern Lending. The transfer, an outgoing ACH credit of $2,400.00 (acht_sim_lant_619wbdb5ej7), occurred 0.0 hours after verification and above the program median of $1,224.73. The transfer has already settled.
What the evidence shows. The entity's verification status is DENIED, with review reasons listing sanctions_match, last screened 2026-06-24. The transfer-level skoor evidence carries a hard signal entity.denied(+60,hard), which drove the skoor to 60 (hold band). This conflicts with the alert header's 'hard signal: false' field, an inconsistency worth flagging. Despite the denied verification and sanctions match reason, the $2,400.00 outgoing transfer settled with no return code. Program KRIs show verification_denial_rate at 3.0% (n=33, ok) and pep_flagged_entities at watch (1 of 33), with no other elevated fraud or return-rate metrics. Manual_review_aging_hours is in breach (1433.6 hours, n=8), which may indicate delayed handling of similar cases.
What was checked. Reviewed the alert evidence, transfer record, entity record, program declared volume, and program KRI snapshot. Confirmed the transfer status (SETTLED), counterparty country (unknown), and absence of a return code. Confirmed no prior dispositions exist for this alert or entity. Noted the mismatch between the alert's hard-signal flag and the transfer skoor's hard signal on entity.denied.
What is recommended. This is not a case where funds can be held, since the transfer has already settled. The combination of a DENIED verification status with a sanctions_match review reason on a settled outgoing transfer, plus the breach-level manual_review_aging_hours KRI, indicates a control gap that may extend beyond this single alert. This should be escalated for a person to investigate whether other transfers cleared under the same denied/sanctions-flagged entity or similar entities, and to reconcile the hard-signal discrepancy noted above.
- Recommendation
- escalate
- Confidence
- 0.75
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Entity verification status is DENIED with review reason sanctions_match, yet an outgoing ACH transfer for this entity settled.
- Transfer-level skoor evidence shows a hard signal (entity.denied) that contradicts the alert header's hard_signal:false field.
- Manual_review_aging_hours KRI is in breach (1433.6 hours, n=8), suggesting review backlogs that could affect similar cases.
- Transfer already settled, so hold/release actions do not apply; the concern is pattern and control-gap review, not fund movement.
Evidence
{
"n": 613,
"band": "hold",
"skoor": 60,
"autoHold": true,
"typology": "rapid_onboarding",
"confidence": 0.7,
"thresholds": {
"hours": 24
},
"medianCents": "122473",
"routeReason": "detector not auto-closable",
"hoursSinceVerification": 0
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| entity.denied | +60 | yes | entity verification DENIED |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.