Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $1,591.44 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_9oxv1yweeba
- Transfer
- acht_sim_lant_9oxv1yweeba · $1,591.44 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:31Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. Alert e1e52193-7c22-46fa-8830-ce2be9035381 fired from the skoor_review detector at medium severity on outgoing ACH credit transfer acht_sim_lant_9oxv1yweeba, $1,591.44, under program Lantern Lending. The transfer scored 40 (review band, hard signal false) driven by a single signal: the counterparty has 1 prior unauthorized return.
What the evidence shows. The transfer itself is SETTLED with return code none, meaning no return or dispute occurred on this transaction. The counterparty cpty_sim_lant_asr3v7ggcjp has an unspecified country and one prior unauthorized return on record, which is the sole basis for the score. The originating entity, Grove Co 318 (enti_sim_lant_6tljrrozci6), is VERIFIED, not flagged high risk, not PEP, has no open review reasons, and was screened recently (2026-08-30). Program-level KRIs show ach_unauthorized_return_rate at 0 (n=271, ok) and manual_review_rate at 1.2% (n=652, ok), indicating no broader unauthorized-return pattern at the program level. Two KRIs are flagged: manual_review_aging_hours is in breach (1433.6 hrs, n=8) and hold_aging_hours is in watch (1406.4 hrs, n=3), but these describe review-queue timing, not transaction risk, and are not specific to this alert or this counterparty.
What was checked. Reviewed the transfer record (status, amount, return code), the alert evidence block (signal code, weight, confidence), the entity verification and screening status, and the program-level KRI panel for corroborating patterns of unauthorized returns or elevated risk. No prior dispositions exist for this alert.
What is recommended. Close the alert. The transfer settled without a return, the originating entity is verified with no other risk indicators, and program-level unauthorized-return metrics are within normal range. The single signal reflects the counterparty's return history rather than an issue with this specific transaction. No funds are pending action since the transfer is already settled. The counterparty's prior unauthorized return history may warrant a note for future monitoring, but that is a program-level observation, not a basis to hold or escalate this settled transfer.
- Recommendation
- close
- Confidence
- 0.68
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is SETTLED with return code none; no return occurred on this transaction.
- Single signal (returns.counterparty_prior_unauthorized) accounts for the entire score; hard signal is false.
- Originating entity is VERIFIED, not high risk, no PEP, no open review reasons, recently screened.
- Program-level ach_unauthorized_return_rate is 0 (n=271), showing no broader pattern tied to this alert's signal type.
- Manual_review_aging_hours and hold_aging_hours flags reflect queue timing at the program level, not transaction-specific risk, and do not change the disposition of this settled transfer.
- Counterparty country is unknown and history is limited to one prior unauthorized return with no further detail, which limits certainty; confidence is set accordingly rather than higher.
Evidence
{
"n": 719,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 1,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.