Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $607.68 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_bt5qfmxhddt
- Transfer
- acht_sim_lant_bt5qfmxhddt · $607.68 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:30Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert c69c8137-6ffc-44f4-a9f7-990e1445ff77 fired on outgoing ACH credit acht_sim_lant_bt5qfmxhddt for $607.68, opened 2026-09-17T19:30:52.557Z under program Lantern Lending. The skoor_review detector scored the transfer 40 (review band, hard signal false) driven by one signal: returns.counterparty_prior_unauthorized, weight 40, detail '1 prior unauthorized return(s)' for counterparty cpty_sim_lant_asr3v7ggcjp.
What the evidence shows. The transfer itself settled with no return code. The transfer-level skoor record confirms the same score (40, band review, n=311, confidence 0.76) and the same single signal. The subject entity, Alder Co 324, is VERIFIED, not high risk, not PEP, with no review reasons and screening current as of 2026-06-29. Program KRIs show ach_unauthorized_return_rate at 0 (n=83, ok) and ach_overall_return_rate at 0 (n=83, ok), indicating no active pattern of unauthorized or general returns across the program's ACH volume. counterparty_concentration_top1 is 0.179 (ok), and high_risk_entity_share is 0.030 (ok). Two KRIs are flagged: manual_review_aging_hours is in breach (1433.5h, n=3) and hold_aging_hours is watch (1406.4h, n=1), both program-level backlog indicators unrelated to this specific transfer's facts. There are no prior dispositions on this alert.
What was checked. Transfer status and return code, transfer-level skoor and signal detail, entity verification and screening status, program-level return-rate and concentration KRIs, and prior disposition history.
What is recommended. No hold is warranted because the transfer has already settled with no return code attached; there is no pending movement of funds to hold or release. The single driving signal is a historical counterparty return, not a return on this transaction, and program-wide unauthorized/overall return rates are at 0, showing no corroborating pattern. Entity verification is current and unremarkable. Close this alert. Separately, the manual_review_aging_hours breach and hold_aging_hours watch are program-level backlog conditions that a person should review outside this specific alert, as they are not explained by this transfer's evidence.
- Recommendation
- close
- Confidence
- 0.68
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer acht_sim_lant_bt5qfmxhddt is SETTLED with return code none, so there is no held balance to act on.
- The only driving signal is a single prior unauthorized return by the counterparty, not a return on this transaction.
- Program KRIs ach_unauthorized_return_rate and ach_overall_return_rate are both 0 (n=83), showing no broader return pattern to corroborate escalation.
- Subject entity is VERIFIED, not high risk, not PEP, with no open review reasons and recent screening.
- Manual_review_aging_hours breach and hold_aging_hours watch are noted as program-level conditions unrelated to this transfer's specific evidence and are called out separately rather than folded into this alert's disposition.
- No prior dispositions exist for this alert to indicate a repeat or unresolved issue.
Evidence
{
"n": 311,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 0.76,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.