Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $727.79 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_4ujoeslje00
- Transfer
- acht_sim_lant_4ujoeslje00 · $727.79 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert c927e0bc-2963-4a3e-9a45-26c140bc2515 fired on a $727.79 outgoing ACH transfer (acht_sim_lant_4ujoeslje00) under Lantern Lending. The skoor_review detector scored the transfer 40, placing it in the review band, based on a single signal: the counterparty has 1 prior unauthorized return on record.
What the evidence shows. The transfer itself settled with no return code, meaning this specific transaction did not fail or get reversed. The skoor is driven entirely by one signal (returns.counterparty_prior_unauthorized, weight 40) reflecting one prior unauthorized return tied to the counterparty (country unknown). Hard_signal is false, meaning no current-transaction rule violation. The originating entity, Alder Co 30, is a verified business, not flagged high risk, not PEP, has no open review reasons, and was screened 2026-06-27. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=190) and ach_overall_return_rate at 0.0105 (n=190), both in the ok range, indicating no broader return pattern at the program level. Two KRIs are outside ok: hold_aging_hours (watch) and manual_review_aging_hours (breach), and pep_flagged_entities is at watch (1 of 33). None of these three are tied to this transfer or this counterparty in the evidence provided.
What was checked. Reviewed the transfer status and return code, the single signal driving the skoor, the entity's verification and risk flags, program-level return-rate KRIs, and prior dispositions on this subject. Prior dispositions: none on file.
What is recommended. The transfer has already settled; there is no held transfer to act on, so release does not apply. Given a single historical unauthorized-return data point on the counterparty, no current-transaction violation, a verified low-risk originating entity, and program-level return rates within normal range, the evidence does not show a pattern requiring escalation. Close the alert. Note for the record that manual_review_aging_hours is in breach at the program level; this is a program-wide operational issue and not specific to this alert, so it should be tracked separately rather than held against this disposition.
- Recommendation
- close
- Confidence
- 0.62
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer settled with no return code; the flag is not about this transaction failing.
- Only one signal drove the skoor (counterparty prior unauthorized return, weight 40, hard_signal false).
- Originating entity is verified, not high-risk, not PEP, no open review reasons, screened within the last 3 months.
- Program-level ach_unauthorized_return_rate is 0 (n=190) and ach_overall_return_rate is 0.0105 (n=190), showing no broader unauthorized-return pattern.
- Counterparty country is unknown, and the alert evidence gives no count of the counterparty's total transaction history for context, which limits certainty about how isolated the prior return was; confidence is set below 0.7 for this reason.
- Program KRI breaches (manual_review_aging_hours, hold_aging_hours watch, pep_flagged_entities watch) are program-level operational signals, not evidence tied to this specific transfer or counterparty.
Evidence
{
"n": 571,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 0.985,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.