Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $731.31 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_20f4urp3dqb
- Transfer
- acht_sim_lant_20f4urp3dqb · $731.31 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert ca97d3c7-e4a3-47fd-81fe-bcaa8350bf6c fired on an outgoing ACH transfer of $731.31 from program Lantern Lending, flagged by the skoor_review detector at a risk score of 40 (review band) due to a single signal: the counterparty has one prior unauthorized return on record.
What the evidence shows. The transfer (acht_sim_lant_20f4urp3dqb) is already SETTLED with return code none, meaning no return occurred on this transaction. The triggering signal is the sole contributor to the score (weight 40, hard_signal false), based on a sample of n=464 with confidence 0.985. The subject entity, Juniper LLC 321, is VERIFIED, not high risk, not PEP, US-based, with no open review reasons and screening current as of 2026-07-07. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=164) and ach_overall_return_rate at 0.012 (n=164), both in the ok range, indicating no broader pattern of unauthorized returns tied to this program or counterparty base. Two KRIs are outside normal range: hold_aging_hours (watch) and manual_review_aging_hours (breach at 1433.6 hours, n=3), but neither is specific to this alert or this transfer.
What was checked. Transfer status and return code, entity verification and risk flags, the single scoring signal and its weight, program declared volume and country scope, and program-wide KRIs for unauthorized and overall ACH return rates to assess whether this counterparty's prior unauthorized return reflects a wider pattern.
What is recommended. No funds are at risk on this transfer since it has already settled cleanly with no return. The single prior-unauthorized-return signal on the counterparty did not repeat here, and program-wide unauthorized return metrics are at zero, so there is no pattern evidence to escalate. Recommend closing the alert. Separately, the manual_review_aging_hours breach (1433.6 hours, n=3) is a program-level queue issue unrelated to this specific alert's disposition and should be tracked outside this alert.
- Recommendation
- close
- Confidence
- 0.80
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:31Z
- Rationale
- Transfer status is SETTLED with return code none; no funds are pending or held.
- Only one signal drove the score (counterparty_prior_unauthorized, weight 40); no hard signal was present.
- Subject entity is VERIFIED, not high risk, not PEP, with no open review reasons and recent screening.
- Program-wide ach_unauthorized_return_rate is 0 (n=164), showing no broader pattern to justify escalation.
- No prior dispositions exist for this alert, and evidence is specific and sufficient to close without further review.
Evidence
{
"n": 464,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 0.985,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.