SKOOR Risk Money movement. Skoored by AI.

Alert · reviewed · open

Transaction Risk Skoor 40 (review band) on a $2,199.39 ach transfer: returns.counterparty_prior_unauthorized.

Detector
skoor_review
Severity
medium
Program
Lantern Lending (simulated)
Subject
transfer acht_sim_lant_4ahy2h3we8y
Transfer
acht_sim_lant_4ahy2h3we8y · $2,199.39 · ach outgoing
Skoor at alert
40 review
Hard signal
no
Policy
policy-v1
Opened
2026-09-17 19:31Z
Closed
Decision clock
none · due — no clock
Escalated

Draft narrative

What happened. Alert fa9cf89e-ba65-4d7d-974f-8961550221ab flagged an outgoing ACH transfer of $2,199.39 (acht_sim_lant_4ahy2h3we8y) under the skoor_review detector at severity medium. The transfer skoor is 40, placing it in the review band, driven by a single signal: returns.counterparty_prior_unauthorized, weighted 40, indicating one prior unauthorized return associated with the counterparty cpty_sim_lant_asr3v7ggcjp. What the evidence shows. The transfer itself is status SETTLED with return code none, meaning it completed without a return or dispute. The signal is based on the counterparty's history, not on this transaction's outcome. The originating entity, Kestrel Partners 322, is VERIFIED, not high risk, not PEP, has no open review reasons, and was screened on 2026-08-25, roughly two weeks before the transfer. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=248, ok) and ach_overall_return_rate at 1.2% (n=248, ok), both within normal range, so there is no program-wide pattern of unauthorized returns. Two KRIs are outside normal range but unrelated to this alert's signal: manual_review_aging_hours is in breach (1433.6 hours, n=6) and hold_aging_hours is in watch (1406.4 hours, n=2), both reflecting review/hold processing delays rather than transaction risk. Counterparty country is unknown, which is an evidence gap. What was checked. Transfer status and return code, entity verification and screening status, program declared volume and velocity (0.346 vs declared, n=226, ok), counterparty concentration (0.122, ok), and the full KRI panel. No prior dispositions exist for this alert or subject. Confidence on the skoor computation is stated as 1 with n=695. What is recommended. Because the transfer has already settled with no return, and the flagged entity is verified with no other adverse findings, there is no transaction to hold and no basis in the evidence for further transaction-level action on this alert. The manual_review_aging_hours breach and hold_aging_hours watch are process-level KRIs unrelated to this specific alert's signal and should be tracked separately, not as part of this disposition. Close this alert; no person action is needed on this transfer.
Recommendation
close
Confidence
0.62
Model
claude-sonnet-5
Drafted
2026-09-17 19:32Z
Rationale
  • Signal is based on counterparty's prior unauthorized return, not this transfer, which settled cleanly with return code none.
  • Entity is VERIFIED, not high risk, not PEP, no open review reasons, screened within the last month.
  • Program-level ach_unauthorized_return_rate is 0 (n=248), showing no broader pattern of unauthorized returns tied to this program.
  • Transfer is already SETTLED, so 'hold' or 'release' recommendations do not apply; funds have already moved.
  • Counterparty country is unknown, which limits full verification of counterparty risk and is noted as a gap lowering confidence.
  • Manual_review_aging_hours breach and hold_aging_hours watch are unrelated KRIs reflecting operational timing, not evidence of risk on this specific alert.

Evidence

{
  "n": 695,
  "band": "review",
  "skoor": 40,
  "signals": [
    {
      "code": "returns.counterparty_prior_unauthorized",
      "detail": "1 prior unauthorized return(s)",
      "weight": 40
    }
  ],
  "confidence": 1,
  "routeReason": "detector not auto-closable"
}

Skoor signals

SignalWeightHardDetail
returns.counterparty_prior_unauthorized+401 prior unauthorized return(s)

Decision

Sign in as an operator to decide. Operator sign-in →

Dispositions

No disposition yet.

Actions

Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.

No actions requested.