Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $706.42 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_503xflkfdlm
- Transfer
- acht_sim_lant_503xflkfdlm · $706.42 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 73c1ef46-58a5-4b67-8661-1c7608830242 fired on outgoing ACH transfer acht_sim_lant_503xflkfdlm ($706.42, credit) under program Lantern Lending. The detector skoor_review scored the transaction at 40 (review band) due to a single signal: the counterparty has 1 prior unauthorized ACH return on record.
What the evidence shows. The transfer itself is SETTLED with return code none, meaning this specific transaction did not return. The triggering signal (returns.counterparty_prior_unauthorized, weight 40) is a historical flag on the counterparty, not on this transfer. Hard signal is false and confidence on the skoor evidence is 0.97 (n=396-404). The subject entity, Iris Services 320, is VERIFIED, not high risk, not PEP, has no open review reasons, and was screened 2026-06-23. Program-level KRIs relevant to ACH returns are within normal range: ach_unauthorized_return_rate=0, ach_overall_return_rate=0.0145, ach_administrative_return_rate=0, sanctioned_country_transfers=0, verification_denial_rate=0.0303. One KRI, manual_review_aging_hours, shows a breach (1433.55 hours, n=3), but this is a program-wide aging metric, not evidence tied to this alert's subject or transfer. There are no prior dispositions on this alert.
What was checked. Transfer status and return code, skoor signal detail and weight, entity verification and screening status, program declared volume and country scope, and program KRI panel for ACH return and review-related metrics.
What is recommended. The transfer is already settled with no return, the flagged entity is verified with no other risk indicators, and program ACH return rates are normal. The single triggering signal reflects one historical unauthorized return on the counterparty, not a current return on this transaction. No funds are pending and nothing in the evidence requires a person to intervene on this specific alert. The manual_review_aging_hours breach is a program-level condition that should be tracked separately and is not, on its own, evidence of a pattern connected to this alert given the small sample (n=3). Recommend closing this alert.
- Recommendation
- close
- Confidence
- 0.74
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer acht_sim_lant_503xflkfdlm is SETTLED with return code none; no funds are in a holdable state.
- Triggering signal is a single historical counterparty return, weight 40, hard signal false, placing the alert in review band rather than a stronger action band.
- Subject entity Iris Services 320 is VERIFIED, not high risk, not PEP, with no open review reasons and screening current as of 2026-06-23.
- Program KRIs for ACH unauthorized/overall/administrative return rates are all at or near zero, showing no pattern of unauthorized returns at the program level.
- manual_review_aging_hours KRI shows a breach but is based on n=3 and is a program-wide metric unrelated to this alert's specific evidence, so it does not by itself support escalation of this alert.
- No prior dispositions exist on this alert to indicate repeat concern.
Evidence
{
"n": 396,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 0.97,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.