SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $1,205.70 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Lantern Lending (simulated)
Subject
transfer acht_sim_lant_4n05gxqcdtn
Transfer
acht_sim_lant_4n05gxqcdtn · $1,205.70 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert cd646ab7-7305-44fb-b36c-0b84734a8fc9 fired on an outgoing ACH transfer of $1,205.70 (acht_sim_lant_4n05gxqcdtn) under the Lantern Lending program. The detector skoor_review scored the transaction at 40, placing it in the review band, driven by a single signal: the counterparty has one prior unauthorized return on record. What the evidence shows. The transfer is SETTLED with return code none, so this specific transaction did not itself return as unauthorized. The signal weight of 40 comes entirely from one prior unauthorized return associated with counterparty cpty_sim_lant_asr3v7ggcjp; no detail beyond count is given and no additional signals fired. The subject entity, Kestrel Partners 322, is VERIFIED, not high risk, not PEP, with no review reasons and a screening date of 2026-07-03. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=164) and ach_overall_return_rate at 0.012 (n=164), both ok, indicating no broader pattern of unauthorized returns in this program. manual_review_aging_hours is flagged breach (n=3) and hold_aging_hours is watch, but these are program-wide aging metrics, not specific to this alert, and there is no prior disposition history for this subject or counterparty. What was checked. Transfer status and return code, entity verification and risk flags, the single signal detail and weight, program KRIs for unauthorized and overall return rates, and prior dispositions (none found). What is recommended. Close the alert. The transfer has already settled without an unauthorized return, the entity is verified and low risk, and program-level unauthorized return rates show no pattern beyond the single prior counterparty return already reflected in the score. No funds are pending, so hold or release do not apply. If the counterparty accumulates further unauthorized returns, a future alert would carry more weight for escalation.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer status is SETTLED with return code none; this transaction itself was not returned.
  • The alert's only signal is a single prior unauthorized return for the counterparty (weight 40), with no corroborating signals.
  • Subject entity is VERIFIED, not high risk, not PEP, screened within the last two months.
  • Program KRI ach_unauthorized_return_rate is 0 across 164 observations, indicating no broader unauthorized-return pattern.
  • No prior dispositions exist for this subject or counterparty to suggest recurrence.
  • Evidence is thin (only one signal, no counterparty history detail beyond the count), so confidence is moderate rather than high.

Evidence

{
  "n": 497,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.