SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $585.48 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Lantern Lending (simulated)
Subject
transfer acht_sim_lant_74nwuf6behq
Transfer
acht_sim_lant_74nwuf6behq · $585.48 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:32Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert d627373d-15ef-467d-b597-b4fc3422f647 fired on ACH outgoing credit acht_sim_lant_74nwuf6behq for $585.48, flagged by skoor_review at score 40 (review band) due to a single signal: the counterparty has one prior unauthorized return. What the evidence shows. The transfer is already SETTLED with no return code recorded against it. The only signal driving the score is returns.counterparty_prior_unauthorized, weighted 40, based on one prior unauthorized return by counterparty cpty_sim_lant_asr3v7ggcjp; no other signals contributed. The subject entity, Iris Services 38, is VERIFIED, not high risk, not PEP, has no review reasons, and was screened recently (2026-08-24). Program-level KRIs show ach_unauthorized_return_rate at 0 across n=304 and ach_overall_return_rate at 0.99%, both in the ok range, indicating no broader pattern of unauthorized returns in this program. Two KRIs are flagged watch/breach (hold_aging_hours watch, manual_review_aging_hours breach) but neither is tied to this transfer or this entity. Prior dispositions: none. What was checked. Transfer status and return code, entity verification and risk flags, program-level return-rate and screening KRIs, and prior disposition history for this alert subject. What is recommended. The transfer has already settled and there is no return code, so there is nothing to hold or release. The single supporting signal is a historical prior unauthorized return by the counterparty, not a current return or a flag on the verified subject entity, and program-wide unauthorized-return metrics are at zero. This does not show a pattern extending beyond this alert. Recommend closing the alert; a person should confirm no linked alerts exist for this counterparty before closing.
Recommendation
close
Confidence
0.68
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is SETTLED with return code none; no funds movement is pending, so hold/release do not apply.
  • The only risk signal is one prior unauthorized return tied to the counterparty, not the subject entity, weighted 40 out of a 100-point scale, landing in review band, not action band.
  • Subject entity is VERIFIED, not high risk, not PEP, with no review reasons and recent screening.
  • Program KRI ach_unauthorized_return_rate is 0 (n=304) and ach_overall_return_rate is 0.99%, both ok, indicating no systemic unauthorized-return pattern that would support escalation.
  • No prior dispositions exist for this alert, so there is no history of repeated flags on this counterparty or entity.
  • Confidence is not higher because the counterparty's country is unknown and no independent verification of the counterparty's return history beyond the single flagged instance is present in the evidence.

Evidence

{
  "n": 807,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.