SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · held

Counterparty Receiver 1 entered the hold band (Skoor 75, n=73): counterparty.unauthorized_returns, counterparty.unauthorized_rate, counterparty.review_share, counterparty.new.

Detector
counterparty_hold
Severity
high
Program
Lantern Lending (simulated)
Subject
counterparty cpty_sim_lant_asr3v7ggcjp
Transfer
Skoor at alert
75 hold
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 84acd04b-5bfd-4fdf-ae95-ee81a9fb35de fired on counterparty cpty_sim_lant_asr3v7ggcjp under the counterparty_hold detector. The counterparty's Skoor reached 75, placing it in the hold band, based on 73 observed transactions. The alert was auto-held and routed to review because the detector is not auto-closable. What the evidence shows. The score is driven by four signals: one unauthorized return drawn against this counterparty (weight 40), an unauthorized rate of 1/73 that exceeds the network threshold (weight 15), 40% of this counterparty's volume sitting in the review band (weight 10), and the counterparty being newly seen as of 0 days ago (weight 10). The hard_signal flag is false, meaning this is a model-derived score rather than a definitive rule violation, and detector confidence is 0.787. There are no prior dispositions on this counterparty. What was checked. Program-level KRIs for Lantern Lending (ACH, US, declared volume $900,000.00/month) were reviewed for context. ach_unauthorized_return_rate across the program is 0 (n=138), indicating the single unauthorized return in this alert is isolated to this counterparty rather than reflecting a program-wide unauthorized-return problem. manual_review_aging_hours shows a breach (1433.55 hours, n=3) and hold_aging_hours is at watch (1406.43 hours, n=2), but both are based on very small samples (n=2-3) and are not directly tied to this specific alert. pep_flagged_entities is at watch (1/33). All other KRIs (frozen_accounts, overdraft_events, manual_review_rate, stale_screening_share, high_risk_entity_share, reserve_coverage_ratio, verification_denial_rate, sanctioned_country_transfers, ach_administrative_return_rate, counterparty_concentration_top1) are in the ok range. What is recommended. Hold. The counterparty is new, has drawn an unauthorized return, and sits in the score's hold band with a routeReason of 'not auto-closable.' A person should review the underlying unauthorized return and the counterparty's transaction history before further funds move through this counterparty. This does not appear to be a program-wide pattern given the 0% unauthorized-return rate across the full ACH book, so escalation beyond this counterparty is not supported by current evidence.
Recommendation
hold
Confidence
0.60
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Detector auto-held the alert and marked it not auto-closable (routeReason), indicating human review is expected before disposition.
  • hard_signal is false and confidence is 0.787, so this is model-scored rather than a confirmed violation, which limits certainty but does not eliminate the need for review.
  • The unauthorized return and elevated review-band share are counterparty-specific; program-level ach_unauthorized_return_rate is 0 across 138 transactions, so escalation to a broader pattern is not supported.
  • Program KRI breaches (manual_review_aging_hours, hold_aging_hours) rest on very small samples (n=2-3) and are not directly linked to this alert's evidence, so they are noted as context only, not grounds for escalation.
  • No prior dispositions exist for this counterparty, so there is no history indicating the hold can be closed without review.

Evidence

{
  "n": 73,
  "band": "hold",
  "skoor": 75,
  "signals": [
    {
      "code": "counterparty.unauthorized_returns",
      "detail": "drew 1 unauthorized return(s)",
      "weight": 40
    },
    {
      "code": "counterparty.unauthorized_rate",
      "detail": "unauthorized rate 1/73 above the network threshold",
      "weight": 15
    },
    {
      "code": "counterparty.review_share",
      "detail": "40% in the review band",
      "weight": 10
    },
    {
      "code": "counterparty.new",
      "detail": "first seen 0d ago",
      "weight": 10
    }
  ],
  "version": "crs-v1",
  "autoHold": true,
  "confidence": 0.787,
  "routeReason": "detector not auto-closable"
}

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.