Alert · reviewed · open
The entity's first transfer, $1,711.18, above the program median, came 0.0 hours after verification.
- Detector
- rapid_onboarding
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_7eir3otock9
- Transfer
- acht_sim_lant_7eir3otock9 · $1,711.18 · ach outgoing
- Skoor at alert
- null unscored
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. A rapid_onboarding alert fired on entity Payout Agent (Lantern) after its first outgoing ACH transfer of $1,711.18 settled 0.0 hours after the entity's verification timestamp. The amount is above the program's declared median of $1,265.56. The alert was routed to review because the detector is not auto-closable.
What the evidence shows. The transfer acht_sim_lant_7eir3otock9 is status SETTLED with no return code, so no funds are pending action. The entity is BUSINESS-type, VERIFIED, not flagged high risk, not PEP, with no review reasons on file and a last screening date of 2026-06-27. The counterparty is flagged first_time(+10) and its country is unknown. The transfer-level risk score is unscored with n=0 and confidence null, meaning there is no historical scoring basis yet for this entity or counterparty. The program is Lantern Lending with a declared monthly volume of $900,000.00 on US ACH rails; a single transfer of $1,711.18 is a small fraction of that declared volume.
What was checked. Verification status and screening history on the entity, the transfer's settlement and return status, the counterparty's first-time flag and unknown country, the program's declared volume and median transfer size, and prior dispositions, of which none exist for this entity or alert.
What is recommended. Close the alert. The transfer has already settled with no return, the entity is verified with no adverse screening or PEP findings, and the elevated amount relative to median is consistent with a single first-time payout rather than a pattern requiring hold. The unscored, n=0 status reflects thin history rather than adverse evidence. The unknown counterparty country should be noted for the entity's file so that future counterparty screening can close that gap, but it does not on its own justify escalation given the absence of any hard signal or high-risk flag.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:30Z
- Rationale
- Transfer status is SETTLED with no return code, so there is no fund-movement decision left to make (hold/release do not apply).
- Entity is VERIFIED, not high risk, not PEP, with no review reasons, per the ENTITY record.
- hard_signal is false and skoor/band are unscored with n=0, indicating no adverse scoring evidence, only insufficient history.
- Amount above median and zero-hour timing after verification are the detector's stated basis, consistent with expected rapid_onboarding behavior for a first transfer, not with a demonstrated pattern.
- Counterparty country unknown and first_time(+10) signal are noted but do not meet the bar for escalate absent any high-risk or PEP finding or prior dispositions indicating a broader pattern.
- Confidence is moderate rather than high because the transfer-level score is unscored (n=0), leaving limited quantitative basis beyond the qualitative entity and transfer facts.
Evidence
{
"n": 0,
"band": "unscored",
"skoor": null,
"typology": "rapid_onboarding",
"confidence": null,
"thresholds": {
"hours": 24
},
"medianCents": "126556",
"routeReason": "detector not auto-closable",
"hoursSinceVerification": 0
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| counterparty.first_time | +10 | first transfer with this counterparty | |
| counterparty.first_time_and_large | +15 | amount above the program p95 (168783) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.