SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

The entity's first transfer, $2,146.15, above the program median, came 0.0 hours after verification.

Detector
rapid_onboarding
Severity
medium
Program
Lantern Lending (simulated)
Subject
transfer acht_sim_lant_bk80s93lck1
Transfer
acht_sim_lant_bk80s93lck1 · $2,146.15 · ach outgoing
Skoor at alert
null unscored
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:30Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. The rapid_onboarding detector fired on entity Lantern Lending's first transfer, an outgoing ACH credit of $2,146.15, which posted 0.0 hours after the entity's verification completed. The amount is above the program's median transfer size of $1,265.56. The transfer has already settled. What the evidence shows. The transfer is a single first-time event (n=1) with an unscored band and no skoor confidence value. Signals attached are counterparty.first_time and counterparty.first_time_and_large, both consistent with a first transaction rather than any confirmed adverse finding. The entity is BUSINESS-type, VERIFIED, not high risk, not PEP, with no open review reasons and a screening date of 2026-05-20. The counterparty's country is unknown, and there is no return code on the transfer; status is SETTLED. Program KRIs show frozen_accounts, overdraft_events, stale_screening_share, high_risk_entity_share, and verification_denial_rate all in the 'ok' or 'watch' range with sufficient sample size (n=2 or n=33); several other KRIs (hold_aging_hours, manual_review_rate, velocity_vs_declared, reserve_coverage_ratio, ach return rates, sanctioned_country_transfers, counterparty_concentration_top1) are unmeasured (n=0), so no broader pattern can be confirmed or ruled out from those fields. Prior dispositions: none. What was checked. Reviewed the alert evidence block, the transfer record, the entity verification and risk status, program declared volume, program KRI panel, and prior disposition history. No hard signal is set on this alert, and the route reason recorded is 'detector not auto-closable' rather than any specific derogatory finding. What is recommended. The transfer has already settled, so a hold or release is not applicable. Given the entity is verified with no high-risk or PEP flags, no adverse screening reasons, no return code, and the KRI panel shows no elevated program-level risk in the measured fields, the alert does not present evidence requiring further action beyond confirming this is the entity's baseline first-transaction pattern. Because several KRIs are unmeasured (n=0) and the counterparty's country is unknown, a reviewer may wish to confirm counterparty identity before final closure, but nothing in the record compels escalation or holding funds already settled.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:30Z
Rationale
  • Transfer status is SETTLED; no hold exists, so release/hold recommendations do not apply.
  • Entity is VERIFIED, not high risk, not PEP, with no open review reasons.
  • Signals present (first_time, first_time_and_large) describe expected first-transaction behavior, not a confirmed adverse finding.
  • skoor is null/unscored with n=1, indicating thin statistical basis; confidence is lowered accordingly.
  • Program KRIs with sufficient sample size are in ok/watch range; several others are unmeasured, limiting ability to detect a broader pattern.
  • Counterparty country is unknown and return code is none, which is a minor gap but not sufficient alone to warrant escalation or hold on a settled transfer.

Evidence

{
  "n": 1,
  "band": "unscored",
  "skoor": null,
  "typology": "rapid_onboarding",
  "confidence": null,
  "thresholds": {
    "hours": 24
  },
  "medianCents": "126556",
  "routeReason": "detector not auto-closable",
  "hoursSinceVerification": 0
}

Skoor signals

SignalWeightHardDetail
counterparty.first_time+10first transfer with this counterparty

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.