Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $2,408.96 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_57edhf8d4e
- Transfer
- acht_sim_lant_57edhf8d4e · $2,408.96 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An ACH outgoing credit transfer of $2,408.96 from Lantern Lending settled and was flagged by the skoor_review detector at a risk score of 40 (review band) due to a prior unauthorized return associated with the counterparty.
What the evidence shows. The evidence lists one signal: returns.counterparty_prior_unauthorized, weighted 40, described as one prior unauthorized return for this counterparty, with detector confidence 0.865 based on n=208. The transfer itself settled with return code none, meaning this specific transaction was not returned. The counterparty's country is unknown. The originating entity, Payout Agent (Lantern), is verified, not high risk, not PEP, with no review reasons and screening current as of 2026-06-27. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=54, ok) and ach_overall_return_rate at 0 (n=54, ok), indicating no broader unauthorized-return pattern at the program level. Two KRIs show watch/breach status: hold_aging_hours (watch, n=1) and manual_review_aging_hours (breach, n=2), but neither is directly tied to this transfer or counterparty. There are no prior dispositions on this alert.
What was checked. Reviewed the alert signal and weight, the transfer status and return code, the counterparty verification and country field, the originating entity's verification and risk flags, program-level KRIs for return rates and manual review aging, and prior disposition history.
What is recommended. The transfer has already settled, so no funds are held pending this alert; a release recommendation does not apply. The single signal driving this alert is a prior unauthorized return tied to the counterparty, which is a substantive concern given the counterparty's country is unknown and no counterparty-level detail beyond the one prior return is provided. This warrants a person to review the counterparty's return history and country status before closing, since the evidence is not sufficient to rule out recurring risk at the counterparty level, even though program-wide return rates are clean.
- Recommendation
- hold
- Confidence
- 0.55
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:30Z
- Rationale
- Single signal (returns.counterparty_prior_unauthorized, weight 40) is the sole basis for the review band score and reflects a documented prior unauthorized return for this counterparty.
- The flagged transfer itself settled with no return code, so no funds are recoverable via hold on this transaction, but a person should still assess whether related counterparty activity needs restriction.
- Counterparty country is listed as unknown, which adds uncertainty not resolved by the entity verification (entity is verified, low risk, not PEP).
- Program-level KRIs (ach_unauthorized_return_rate=0, ach_overall_return_rate=0) show no broader pattern, arguing against escalation.
- No prior dispositions exist for this alert or apparent related alerts, so there is no established precedent to rely on for closing without review.
- Evidence is moderately thin (only one signal, no counterparty return history beyond the count of one, no country data), which lowers confidence in a definitive close recommendation.
Evidence
{
"n": 208,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 0.865,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.