Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $757.15 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_5mkfi8t4dcz
- Transfer
- acht_sim_lant_5mkfi8t4dcz · $757.15 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert 9209e2ba-4b80-46f3-b1d8-96948eba8162 was opened on 2026-09-17T19:30:50.629Z by the skoor_review detector at medium severity for a $757.15 outgoing ACH transfer (acht_sim_lant_5mkfi8t4dcz) under the Lantern Lending program. The transfer risk skoor was 40, placing it in the review band, driven by one signal: returns.counterparty_prior_unauthorized (1 prior unauthorized return, weight 40, hard signal false).
What the evidence shows. The transfer status is SETTLED with return code none, so the funds have already moved and there is no return on this specific transaction. The counterparty (cpty_sim_lant_asr3v7ggcjp, country unknown) has one prior unauthorized return on record, which is the sole basis for the skoor. The underlying entity, Birch Holdings 313, is VERIFIED, not high risk, not PEP, has no review reasons, and was screened on 2026-07-06. Program-level KRIs show ach_unauthorized_return_rate=0 (n=83, ok) and ach_overall_return_rate=0 (n=83, ok), indicating no broader pattern of unauthorized returns across the program's transaction population. Two KRIs are flagged: manual_review_aging_hours=1433.5 (n=3, breach) and hold_aging_hours=1406.4 (n=1, watch), plus pep_flagged_entities=1 (n=33, watch), but none of these tie directly to this transfer or counterparty in the evidence provided.
What was checked. Reviewed the alert evidence and skoor signal detail, the transfer record (status, return code, amount, dates), the counterparty's return history as stated, the entity verification and screening record, program declared volume and KRI panel, and prior dispositions (none on file). No additional counterparty-level return history beyond the single cited instance was provided in the evidence.
What is recommended. The transfer has already settled with no return on this transaction, so there are no funds to hold or release here. The single prior unauthorized return is the only adverse signal, the entity is verified and low risk, and program-wide unauthorized return rates are at zero, showing this is not part of a broader pattern. This alert does not require a person to act on the transfer itself. The manual_review_aging_hours breach is a program-level operational KRI unrelated to this specific alert's facts and is noted for awareness but does not change the disposition of this alert.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer status is SETTLED with return code none; there is no pending movement to hold or release.
- The skoor is driven by a single prior unauthorized return on the counterparty, not a pattern; program ach_unauthorized_return_rate=0 (n=83) supports this being isolated.
- Entity is VERIFIED, not high risk, not PEP, no review reasons, screened within the last two months.
- No hard signal was triggered (hard signal: false), and confidence on the skoor evidence itself is 0.835, but the evidence tying this specific counterparty to systemic risk is thin (only one prior return, no detail on when or under what program).
- Program KRI breaches (manual_review_aging_hours) and watches (hold_aging_hours, pep_flagged_entities) are not connected in the evidence to this transfer or counterparty, so they are noted but not used to escalate this specific alert.
- Confidence is moderate rather than high because counterparty country is unknown and no further detail on the prior unauthorized return (date, amount, program) was provided.
Evidence
{
"n": 295,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 0.835,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.