SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $757.15 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Lantern Lending (simulated)
Subject
transfer acht_sim_lant_5mkfi8t4dcz
Transfer
acht_sim_lant_5mkfi8t4dcz · $757.15 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert 9209e2ba-4b80-46f3-b1d8-96948eba8162 was opened on 2026-09-17T19:30:50.629Z by the skoor_review detector at medium severity for a $757.15 outgoing ACH transfer (acht_sim_lant_5mkfi8t4dcz) under the Lantern Lending program. The transfer risk skoor was 40, placing it in the review band, driven by one signal: returns.counterparty_prior_unauthorized (1 prior unauthorized return, weight 40, hard signal false). What the evidence shows. The transfer status is SETTLED with return code none, so the funds have already moved and there is no return on this specific transaction. The counterparty (cpty_sim_lant_asr3v7ggcjp, country unknown) has one prior unauthorized return on record, which is the sole basis for the skoor. The underlying entity, Birch Holdings 313, is VERIFIED, not high risk, not PEP, has no review reasons, and was screened on 2026-07-06. Program-level KRIs show ach_unauthorized_return_rate=0 (n=83, ok) and ach_overall_return_rate=0 (n=83, ok), indicating no broader pattern of unauthorized returns across the program's transaction population. Two KRIs are flagged: manual_review_aging_hours=1433.5 (n=3, breach) and hold_aging_hours=1406.4 (n=1, watch), plus pep_flagged_entities=1 (n=33, watch), but none of these tie directly to this transfer or counterparty in the evidence provided. What was checked. Reviewed the alert evidence and skoor signal detail, the transfer record (status, return code, amount, dates), the counterparty's return history as stated, the entity verification and screening record, program declared volume and KRI panel, and prior dispositions (none on file). No additional counterparty-level return history beyond the single cited instance was provided in the evidence. What is recommended. The transfer has already settled with no return on this transaction, so there are no funds to hold or release here. The single prior unauthorized return is the only adverse signal, the entity is verified and low risk, and program-wide unauthorized return rates are at zero, showing this is not part of a broader pattern. This alert does not require a person to act on the transfer itself. The manual_review_aging_hours breach is a program-level operational KRI unrelated to this specific alert's facts and is noted for awareness but does not change the disposition of this alert.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer status is SETTLED with return code none; there is no pending movement to hold or release.
  • The skoor is driven by a single prior unauthorized return on the counterparty, not a pattern; program ach_unauthorized_return_rate=0 (n=83) supports this being isolated.
  • Entity is VERIFIED, not high risk, not PEP, no review reasons, screened within the last two months.
  • No hard signal was triggered (hard signal: false), and confidence on the skoor evidence itself is 0.835, but the evidence tying this specific counterparty to systemic risk is thin (only one prior return, no detail on when or under what program).
  • Program KRI breaches (manual_review_aging_hours) and watches (hold_aging_hours, pep_flagged_entities) are not connected in the evidence to this transfer or counterparty, so they are noted but not used to escalate this specific alert.
  • Confidence is moderate rather than high because counterparty country is unknown and no further detail on the prior unauthorized return (date, amount, program) was provided.

Evidence

{
  "n": 295,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 0.835,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.