The Technical Round
Explore how to design a regulated loan document flagging system using Claude by framing constraints, managing document ingestion, extracting fields with traceable sources, and applying explicit rule checks. Understand defenses against prompt injection and cost management, ensuring compliance and reliability in financial environments.
We'll cover the following...
- Framing the design before building
- The pipeline at a glance
- Handling the ingestion boundary
- Extracting fields with their source
- Cross-checking with explicit rules
- Defending against injected instructions
- Managing tokens and cost
- Choosing where it runs
- How interviewers probe this design
- Designing for the people who check the work
Discovery turned Northfield's request into a scoping brief with agreed rules for names, addresses, income, and dates, and a written boundary that the system flags and never decides. The next step is to design the system that delivers it.
In Anthropic's FDE loop, this is the design an interviewer would push on in the technical use-case screen or the final panel. The interviewer wants to see how the design handles messy documents, keeps every flag traceable, resists manipulation, and stays within budget.
The first decision shapes everything after it.
Framing the design before building
The scoping brief sets the constraints. The system must flag inconsistencies, cite the exact source of each flag, leave lending decisions to underwriters, and survive validation by people outside the build team.
Those constraints point to a clear division of work. Claude extracts the fields from each document, along with where each value came from. Ordinary code then checks consistency, applying the rules the underwriters agreed to in discovery. Claude never decides on its own whether two documents match.
This split earns its place for three reasons. The rules stay explicit and auditable, so model risk can read them, test them, and approve changes to them. Extraction and checking can be validated separately, which makes failures easier to locate. And a document that tries to manipulate the system can, at worst, distort one extracted value. It cannot rewrite a rule.
With that division settled, the pipeline takes shape.
The pipeline at a glance
The system runs as a sequence of steps, each with one job.
The loan origination system (LOS) is mocked for this engagement, so a small MCP server exposes read-only tools such as fetching an application packet by ID.
The ...