SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $2,388.85 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Lantern Lending (simulated)
Subject
transfer acht_sim_lant_17pnj5sqdrn
Transfer
acht_sim_lant_17pnj5sqdrn · $2,388.85 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert f37c4014-19d4-45db-a962-8151fc482988 fired on an outgoing ACH transfer (acht_sim_lant_17pnj5sqdrn) for $2,388.85 under program Lantern Lending. The transfer risk skoor was 40, placing it in the review band, driven by a single signal: the counterparty has 1 prior unauthorized return. What the evidence shows. The transfer is already SETTLED with return code none, so no return has occurred on this transfer itself. The skoor is built on a sample of n=470 with confidence 0.94, and the only contributing signal is returns.counterparty_prior_unauthorized (weight 40), which is a hard_signal:false, moderate-strength indicator rather than a confirmed current-transaction problem. The originating entity, Elm Partners 316, is VERIFIED, not flagged high risk, not PEP, has no review reasons, and was screened as recently as 2026-06-30. The counterparty's country is unknown, which limits visibility but is not itself a stated risk flag. Program-level KRIs are mostly ok; two are in watch (hold_aging_hours, pep_flagged_entities) and one is in breach (manual_review_aging_hours, n=3), but none of these are tied to this specific transfer or counterparty, and ach_unauthorized_return_rate for the program is 0 (n=164, ok), which does not corroborate a broader unauthorized-return pattern. What was checked. Transfer status and return code, entity verification and screening status, program KRI panel, and prior dispositions (none on file). No other alerts or returns are recorded against this counterparty or entity in the evidence provided. What is recommended. The transfer has already settled with no return, the originating entity is verified and clean, and the program's own unauthorized-return rate is 0. The single signal driving this alert (one prior unauthorized return on the counterparty) is not corroborated by any current-transaction defect or entity-level flag. There is no fund-movement decision pending, so hold/release do not apply. Recommend closing the alert with a note that the counterparty's prior unauthorized-return history should be retained for future reference if further alerts on this counterparty occur.
Recommendation
close
Confidence
0.72
Model
claude-sonnet-5
Drafted
2026-09-17 19:31Z
Rationale
  • Transfer status is SETTLED with return code none; no return occurred on this specific transaction.
  • Skoor driver is a single non-hard signal (prior unauthorized return on counterparty), weight 40, in the review band, not a confirmed current defect.
  • Originating entity is VERIFIED, not high risk, not PEP, no review reasons, recently screened.
  • Program ach_unauthorized_return_rate is 0 (n=164), not supporting a broader pattern tied to this alert.
  • Counterparty country is unknown, which is a gap in the evidence but not a stated risk flag on its own, so confidence is held below 0.8.
  • No prior dispositions exist on this alert or entity to indicate recurrence.

Evidence

{
  "n": 470,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 0.94,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.