Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $595.25 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_7fpov794dqw
- Transfer
- acht_sim_lant_7fpov794dqw · $595.25 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An ACH outgoing credit transfer of $595.25 (acht_sim_lant_7fpov794dqw) under program Lantern Lending was flagged by the skoor_review detector with a Transaction Risk Skoor of 40, placing it in the review band. The triggering signal is a single flag: the counterparty has 1 prior unauthorized ACH return.
What the evidence shows. The transfer itself settled with no return code, indicating it cleared without incident. The skoor is driven entirely by one signal (returns.counterparty_prior_unauthorized, weight 40) with model confidence 0.97 on n=459. The counterparty's country is unknown. The subject entity, Iris Services 38, is a US person, verified, not high risk, not PEP, has no open review reasons, and was screened as recently as 2026-06-20. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=164) and ach_overall_return_rate at 0.012 (n=164), both in the 'ok' band, indicating no broader pattern of unauthorized returns across the program. manual_review_aging_hours is in breach (1433.6 hours, n=3) and hold_aging_hours is in watch (1406.4 hours, n=2), but these are program-wide backlog metrics, not specific to this alert or this counterparty. There are no prior dispositions on this alert.
What was checked. Transfer status and return code, entity verification and screening status, program KRI panel for related return-rate and screening metrics, and prior disposition history for this alert.
What is recommended. The transfer has already settled, so there are no funds to hold or release. The single signal is historical (one prior unauthorized return by the counterparty) and is not corroborated by any current program-wide unauthorized-return trend or entity-level risk flag. Close the alert. If the counterparty generates a second unauthorized return, that would warrant escalation.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer status is SETTLED with return code none, so no funds are currently held or at risk of movement.
- The alert rests on a single signal (one prior unauthorized return by the counterparty) with no corroborating entity or program-level risk indicators.
- Subject entity is VERIFIED, not high risk, not PEP, with no open review reasons and recent screening.
- Program KRIs for unauthorized and overall ACH return rates are both in the 'ok' band, showing no evidence of a broader pattern.
- Counterparty country is unknown, which is a data gap but not itself a triggering signal in this alert.
- Confidence is moderate rather than high because the counterparty's own return history and country risk profile are not detailed beyond the single flag.
Evidence
{
"n": 459,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 0.97,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.