Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $694.91 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_2rmk2ye2dth
- Transfer
- acht_sim_lant_2rmk2ye2dth · $694.91 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert acf69a33-5d63-4be1-b48c-e6691a48f7cf fired on transfer acht_sim_lant_2rmk2ye2dth, a $694.91 outgoing ACH credit from program Lantern Lending. The detector skoor_review scored the transfer 40 (review band, hard_signal false) on a single signal: the counterparty (cpty_sim_lant_c9qj5z42ckx) has one prior unauthorized ACH return.
What the evidence shows. The transfer is already SETTLED with no return code recorded, so no unauthorized return occurred on this transaction. The single contributing signal is a historical one: one prior unauthorized return tied to the counterparty, weighted 40 of the 40 total score. The originating entity, Lantern Lending, is VERIFIED, not flagged high risk, not PEP, has no open review reasons, and was screened 2026-07-23. Program-level KRIs are mostly ok: ach_unauthorized_return_rate=0 (n=164), ach_overall_return_rate=0.0122 (n=164), sanctioned_country_transfers=0, high_risk_entity_share=0.030, verification_denial_rate=0.030, reserve_coverage_ratio=2.62. Two KRIs are outside ok: manual_review_aging_hours=1433.55 (n=3, breach) and hold_aging_hours=1406.43 (n=2, watch), and pep_flagged_entities=1 (n=33, watch). These relate to review-queue timeliness and portfolio-level PEP count, not to this specific transfer or counterparty.
What was checked. Confirmed transfer status (SETTLED, no return code), reviewed the single signal and its weight, checked entity verification status and screening date, checked program declared volume against transfer size, and reviewed all listed program KRIs for corroborating patterns. No prior dispositions exist for this alert or counterparty in the record provided.
What is recommended. The transfer has already settled with no return recorded against it; there are no funds to hold or release. The alert rests on a single historical signal (one prior unauthorized return by the counterparty) against an otherwise verified, non-high-risk entity, with program-level unauthorized-return and sanctioned-country KRIs both at zero. Nothing in the evidence points to a broader pattern requiring escalation. Close the alert. Separately, the manual_review_aging_hours breach (1433.55 hrs, n=3) is a program-level queue-timeliness issue that a person should review outside this alert, as it is not evidence about this specific transfer.
- Recommendation
- close
- Confidence
- 0.70
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer status is SETTLED with return code none; no funds are currently held or movable, so hold/release do not apply.
- The only signal driving the score is one prior unauthorized return by the counterparty; this is a single historical data point, not a pattern across the alert's own evidence.
- Entity is VERIFIED, not high risk, not PEP, with no open review reasons and a recent screening date (2026-07-23).
- Program KRIs directly relevant to unauthorized/fraudulent ACH activity (ach_unauthorized_return_rate=0, ach_overall_return_rate=0.0122, sanctioned_country_transfers=0) show no corroborating pattern.
- Two KRIs are outside ok (manual_review_aging_hours breach, hold_aging_hours watch, pep_flagged_entities watch) but these describe queue timeliness and portfolio composition, not this transfer or counterparty, so they do not by themselves justify escalation of this alert.
- Confidence is held at 0.7 rather than higher because the counterparty's country is unknown and no detail on the prior unauthorized return (date, amount) is provided, limiting full assessment of recurrence risk.
Evidence
{
"n": 497,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.