SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $591.05 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Lantern Lending (simulated)
Subject
transfer acht_sim_lant_2h97tc9uect
Transfer
acht_sim_lant_2h97tc9uect · $591.05 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. An automated skoor_review alert fired on ACH outgoing debit transfer acht_sim_lant_2h97tc9uect for $591.05, citing a single risk signal: the counterparty has one prior unauthorized return on record. The transfer risk skoor was 40, placing it in the review band, with hard_signal false. What the evidence shows. The transfer is already SETTLED with return code none, meaning no return or dispute has occurred on this specific transaction. The skoor of 40 stems from one signal (returns.counterparty_prior_unauthorized, weight 40) at confidence 0.85 on a base of n=738. The originating entity, Dune LLC 33, is VERIFIED, not high risk, not PEP, with no open review reasons and a recent screening date (2026-09-07). Program-level KRIs show ach_unauthorized_return_rate=0 (n=271) and ach_overall_return_rate=0.011 (n=271), both in the ok band, indicating no current program-wide unauthorized-return pattern. counterparty_concentration_top1=0.127 (n=652) is also ok, showing no concentration risk tied to this counterparty. The only KRIs outside ok are hold_aging_hours (watch), pep_flagged_entities (watch), and manual_review_aging_hours (breach), none of which reference this transfer or this counterparty specifically. What was checked. Reviewed the transfer status and return code, the entity verification and screening record, the program KRI panel for corroborating patterns (unauthorized/overall/administrative return rates, concentration, PEP flags), and prior dispositions on this alert (none exist). What is recommended. Close the alert. The transfer has already settled without a return, the entity is verified with no open review flags, and program-wide return-rate KRIs do not corroborate a broader unauthorized-return pattern tied to this counterparty. No transfer is pending, so there are no funds to hold, and no evidence here indicates a pattern beyond this single alert. A person should review the KRI breach on manual_review_aging_hours separately, but that is not specific to this alert.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is SETTLED with return code none, so no funds are pending and hold/release do not apply.
  • The only risk signal is a single prior unauthorized return on the counterparty; no current return or dispute exists on this transaction.
  • Entity is VERIFIED, not high risk, not PEP, with recent screening and no open review reasons.
  • Program KRIs ach_unauthorized_return_rate (0) and ach_overall_return_rate (0.011) are both in the ok band, showing no broader unauthorized-return pattern.
  • counterparty_concentration_top1 (0.127) is ok, indicating this counterparty is not a concentration risk.
  • Confidence is moderate rather than high because the evidence does not include the counterparty's full return history beyond 'one prior unauthorized return,' and the country of the counterparty is unknown.

Evidence

{
  "n": 738,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 0.85,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.