Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $591.05 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_2h97tc9uect
- Transfer
- acht_sim_lant_2h97tc9uect · $591.05 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An automated skoor_review alert fired on ACH outgoing debit transfer acht_sim_lant_2h97tc9uect for $591.05, citing a single risk signal: the counterparty has one prior unauthorized return on record. The transfer risk skoor was 40, placing it in the review band, with hard_signal false.
What the evidence shows. The transfer is already SETTLED with return code none, meaning no return or dispute has occurred on this specific transaction. The skoor of 40 stems from one signal (returns.counterparty_prior_unauthorized, weight 40) at confidence 0.85 on a base of n=738. The originating entity, Dune LLC 33, is VERIFIED, not high risk, not PEP, with no open review reasons and a recent screening date (2026-09-07). Program-level KRIs show ach_unauthorized_return_rate=0 (n=271) and ach_overall_return_rate=0.011 (n=271), both in the ok band, indicating no current program-wide unauthorized-return pattern. counterparty_concentration_top1=0.127 (n=652) is also ok, showing no concentration risk tied to this counterparty. The only KRIs outside ok are hold_aging_hours (watch), pep_flagged_entities (watch), and manual_review_aging_hours (breach), none of which reference this transfer or this counterparty specifically.
What was checked. Reviewed the transfer status and return code, the entity verification and screening record, the program KRI panel for corroborating patterns (unauthorized/overall/administrative return rates, concentration, PEP flags), and prior dispositions on this alert (none exist).
What is recommended. Close the alert. The transfer has already settled without a return, the entity is verified with no open review flags, and program-wide return-rate KRIs do not corroborate a broader unauthorized-return pattern tied to this counterparty. No transfer is pending, so there are no funds to hold, and no evidence here indicates a pattern beyond this single alert. A person should review the KRI breach on manual_review_aging_hours separately, but that is not specific to this alert.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is SETTLED with return code none, so no funds are pending and hold/release do not apply.
- The only risk signal is a single prior unauthorized return on the counterparty; no current return or dispute exists on this transaction.
- Entity is VERIFIED, not high risk, not PEP, with recent screening and no open review reasons.
- Program KRIs ach_unauthorized_return_rate (0) and ach_overall_return_rate (0.011) are both in the ok band, showing no broader unauthorized-return pattern.
- counterparty_concentration_top1 (0.127) is ok, indicating this counterparty is not a concentration risk.
- Confidence is moderate rather than high because the evidence does not include the counterparty's full return history beyond 'one prior unauthorized return,' and the country of the counterparty is unknown.
Evidence
{
"n": 738,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 0.85,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.