SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $1,591.44 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Lantern Lending (simulated)
Subject
transfer acht_sim_lant_9oxv1yweeba
Transfer
acht_sim_lant_9oxv1yweeba · $1,591.44 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert e1e52193-7c22-46fa-8830-ce2be9035381 fired from the skoor_review detector at medium severity on outgoing ACH credit transfer acht_sim_lant_9oxv1yweeba, $1,591.44, under program Lantern Lending. The transfer scored 40 (review band, hard signal false) driven by a single signal: the counterparty has 1 prior unauthorized return. What the evidence shows. The transfer itself is SETTLED with return code none, meaning no return or dispute occurred on this transaction. The counterparty cpty_sim_lant_asr3v7ggcjp has an unspecified country and one prior unauthorized return on record, which is the sole basis for the score. The originating entity, Grove Co 318 (enti_sim_lant_6tljrrozci6), is VERIFIED, not flagged high risk, not PEP, has no open review reasons, and was screened recently (2026-08-30). Program-level KRIs show ach_unauthorized_return_rate at 0 (n=271, ok) and manual_review_rate at 1.2% (n=652, ok), indicating no broader unauthorized-return pattern at the program level. Two KRIs are flagged: manual_review_aging_hours is in breach (1433.6 hrs, n=8) and hold_aging_hours is in watch (1406.4 hrs, n=3), but these describe review-queue timing, not transaction risk, and are not specific to this alert or this counterparty. What was checked. Reviewed the transfer record (status, amount, return code), the alert evidence block (signal code, weight, confidence), the entity verification and screening status, and the program-level KRI panel for corroborating patterns of unauthorized returns or elevated risk. No prior dispositions exist for this alert. What is recommended. Close the alert. The transfer settled without a return, the originating entity is verified with no other risk indicators, and program-level unauthorized-return metrics are within normal range. The single signal reflects the counterparty's return history rather than an issue with this specific transaction. No funds are pending action since the transfer is already settled. The counterparty's prior unauthorized return history may warrant a note for future monitoring, but that is a program-level observation, not a basis to hold or escalate this settled transfer.
Recommendation
close
Confidence
0.68
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Transfer status is SETTLED with return code none; no return occurred on this transaction.
  • Single signal (returns.counterparty_prior_unauthorized) accounts for the entire score; hard signal is false.
  • Originating entity is VERIFIED, not high risk, no PEP, no open review reasons, recently screened.
  • Program-level ach_unauthorized_return_rate is 0 (n=271), showing no broader pattern tied to this alert's signal type.
  • Manual_review_aging_hours and hold_aging_hours flags reflect queue timing at the program level, not transaction-specific risk, and do not change the disposition of this settled transfer.
  • Counterparty country is unknown and history is limited to one prior unauthorized return with no further detail, which limits certainty; confidence is set accordingly rather than higher.

Evidence

{
  "n": 719,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.