Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $1,395.90 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_145f2p46dfk
- Transfer
- acht_sim_lant_145f2p46dfk · $1,395.90 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert b2783d5b-a87a-4041-affe-e11a727f7fe9 fired on outgoing ACH transfer acht_sim_lant_145f2p46dfk for $1,395.90, opened 2026-09-17T19:30:55.792Z under program Lantern Lending. The transfer skoor is 40, review band, driven by a single signal: returns.counterparty_prior_unauthorized, weight 40, detail '1 prior unauthorized return(s)'. The transfer itself is SETTLED with return code none.
What the evidence shows. The only signal present is one prior unauthorized return on the counterparty (cpty_sim_lant_asr3v7ggcjp, country unknown). The transfer in question has no return code and settled normally. The paying entity, Heath Holdings 319, is VERIFIED, not high risk, not PEP, with no review reasons and screening current as of 2026-06-25. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=110) and ach_overall_return_rate near 0.9% (n=110), both in the 'ok' band, indicating no elevated return activity at the program level. manual_review_aging_hours is in breach (1433.5h, n=3) and hold_aging_hours is in watch (1406.4h, n=1), but these are queue-timing KRIs unrelated to this transfer's risk basis. There are no prior dispositions on this subject.
What was checked. Reviewed the alert evidence block, the transfer record, the counterparty and paying-entity fields, program declared volume and KRIs, and prior disposition history. Confirmed transfer status is SETTLED (not held), so the alert is not eligible for a release recommendation. Confirmed the single driving signal traces to a prior unauthorized return on the counterparty, not to this transfer's own return status. Checked program-level return-rate KRIs for corroboration of a broader pattern; none found.
What is recommended. Close the alert. The transfer has already settled with no return, the paying entity is verified and unflagged, and program-level unauthorized/overall return rates are at or near zero, showing no corroborating pattern. The single prior-unauthorized-return signal on the counterparty is noted but does not by itself indicate this transfer needs further action, and funds cannot be held or released since settlement has already occurred.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Single signal (returns.counterparty_prior_unauthorized, weight 40) drives the skoor 40 review band; no other signals present.
- Transfer status is SETTLED with return code none, so hold/release actions do not apply.
- Paying entity is VERIFIED, not high risk, not PEP, screening current within 3 months.
- Program KRIs ach_unauthorized_return_rate=0 and ach_overall_return_rate=0.0091 (both n=110, ok) show no broader return pattern.
- No prior dispositions exist for this subject to suggest recurrence.
- Counterparty country is unknown, and the detail of the prior unauthorized return is not further specified, which limits certainty and caps confidence below high.
Evidence
{
"n": 329,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 0.85,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.