21 parts · 257 chapters
Core Banking Architecture
One prompt, "design a wallet", and then seventeen rounds of an interviewer making it harder. Every round follows the same loop: the new pressure, the requirements it changes, the tradeoff it forces, and the redrawn design. By the last round the whiteboard holds a real core banking system at 20 million customers: double-entry ledger, sharded postings, Kafka fan-out, loans and liens, six payment rails, multi-currency, card authorisation, fraud scoring, continuous reconciliation, and a BigQuery warehouse that never touches the money path.
The point is not the finished picture. It is that every box on it arrived because something broke, and you can say what broke, what you chose, and what it cost.
00
How to design a system in a room
What the interviewer is actually measuring · The seven-step frame, and why order matters · Functional vs non-functional, stated properly · Back-of-envelope: the four numbers to derive · Latency numbers every engineer should know · The vocabulary of tradeoffs · How to draw so the room follows you · Signals of seniority, and of its absence
8 ch · ~45 min01Round one: “design a wallet”
The prompt, deliberately underspecified · The clarifying questions worth asking · Requirements: functional · Requirements: non-functional, with numbers · Why money is never a float · Balance as a stored column: the naive design · The lost update, demonstrated · Double-entry: the model banks actually use · Balance as derived state · Sketch v1: one service, one database · Why RDBMS here: the guarantees, and how they are kept · What v1 cannot survive
12 ch · ~20 min02Round two: “two requests, same wallet”
The pressure: concurrent debits · Isolation levels, and what each one permits · Inside MVCC: how the snapshot is built · Pessimistic: SELECT FOR UPDATE and the lock manager · Optimistic: version columns and CAS · Choosing per-operation, not per-system · Deadlocks: how they form, how to order writes · Idempotency keys, and the fingerprint · Exactly-once is a lie; here is the truth · Sketch v2: safe under concurrency
10 ch · ~20 min03Round three: “10 million transactions a day”
The pressure: the write path saturates · Deriving the real write amplification · Why the hot row is the bottleneck, not the disk · Sharding the ledger: choosing the key · Why account_id and not transaction_id · Cross-shard transfers, and the two-phase trap · Journal-first: append then post · Snapshots and the balance cache · Redis as a read-through cache, and its failure modes · Cache invalidation that cannot go stale · Sketch v3: sharded ledger with derived reads
11 ch · ~20 min04Round four: “six teams want this data”
The pressure: every team wants a hook · Why not synchronous calls to six services · The log as the integration primitive · Kafka internals: partitions, offsets, ISR · Ordering guarantees, and what they cost · Partition key selection for financial events · The dual-write problem, stated precisely · The transactional outbox · CDC as an alternative to the outbox · Consumer groups, lag, and rebalancing storms · Idempotent consumers and the dedup store · Schema evolution with a registry · Sketch v4: event-driven core
13 ch · ~20 min05Round five: “now add loans, overdraft, liens”
The pressure: the balance is no longer one number · Available vs ledger vs cleared balance · Holds and liens as first-class entries · Overdraft as a negative-bound credit line · Loan disbursement as a ledger movement · Amortisation, accrual, and the daily batch · Savings, interest accrual, and rounding rules · Limits: velocity, per-transaction, cumulative · Company accounts, GL mapping, profit tracking · Fees, and where fee revenue is booked · Sketch v5: product engine over one ledger
11 ch · ~20 min06Round six: “connect to the outside world”
The pressure: rails you do not control · The connector interface, and why it must be narrow · NIBSS and the Nigerian rails · Paystack and Flutterwave as PSPs · SEPA, IBAN, and European settlement · ACH, wire, RTP in the United States · SWIFT MT103 and correspondent banking · The saga: hold, dispatch, confirm, or compensate · Webhooks: signing, replay, and the poller you still need · Timeouts, retries, and the unknown-state problem · Circuit breakers and provider health · Routing: cost, reliability, and failover · Sketch v6: pluggable rails
13 ch · ~20 min07Round seven: “multi-currency, multi-jurisdiction”
The pressure: one ledger, many moneys · Currency as a dimension, not a column · Minor units, exponents, and JPY vs KWD · The zero-sum invariant, restated per currency · FX conversion as two coupled postings · Quote, spread, and the treasury position · Data residency and jurisdictional partitioning · Per-jurisdiction compliance as policy, not code · Sketch v7: currency-aware, region-aware core
9 ch · ~20 min08Round eight: “issue cards”
The pressure: someone else initiates the debit · The four-party model · Authorisation: the 2-second budget · Stand-in processing and the offline window · Auth holds, partial capture, and expiry · Clearing and settlement files · Debit against a wallet vs credit against a line · Multi-currency cards and DCC · Chargebacks and the dispute ledger · PCI DSS scope, tokenisation, and the HSM · Sketch v8: card authorisation on the money path
11 ch · ~20 min09Round nine: “stop the fraud”
The pressure: adversaries, not just load · Rules engine on the synchronous path · Feature stores and the freshness problem · Behavioural baselines per account · Velocity checks in a sliding window · Graph signals: money mules and rings · Scoring: rules, gradient boosting, and LLM triage · Three-tier decisions: allow, review, block · Automated blocking and the blast radius · Account and wallet flagging state machine · Sanctions, PEP, AML transaction monitoring · Case management and the feedback loop · Sketch v9: risk in the path, not beside it
13 ch · ~20 min10Round ten: “prove the money is right”
The pressure: drift is silent · The trial balance, continuously · Internal reconciliation: journal vs postings · External reconciliation: statements vs ledger · Matching: exact, fuzzy, and one-to-many · Suspense accounts and the unmatched bucket · Break classification and auto-resolution · Corrections as new entries, never edits · The nostro position and end-of-day close · Sketch v10: reconciliation as a first-class system
10 ch · ~20 min11Round eleven: “the business wants numbers”
The pressure: OLTP is the wrong shape for questions · Why analytics never touches the money path · Bigtable: the wide-column model · Row key design for time-series banking data · Hot tablets, and designing them away · BigQuery: columnar storage and Dremel · Partitioning and clustering for cost control · Streaming inserts vs batch load · The medallion layering, applied to a bank · Regulatory reporting from the warehouse · Sketch v11: serving, storing, and asking
11 ch · ~20 min12Round twelve: “tell the customer”
The pressure: 10M notifications, ordered, deduped · Fan-out from the event log · Preference resolution and quiet hours · Per-channel workers and blast radius · Deduplication windows · Provider abstraction and failover · Delivery receipts and the feedback loop · Sketch v12: notification subsystem
8 ch · ~50 min13Round thirteen: “run it at 3am”
The pressure: it is broken and you are asleep · SLI, SLO, error budget for a money path · The four golden signals, and the fifth for banks · Business metrics that page · Distributed tracing across the posting path · Structured logs, correlation, and PII · The runbook, and what makes one useful · Graceful degradation: what to shed first · Kill switches and feature flags on money · Disaster recovery: RTO, RPO, and the drill · Sketch v13: the observable core
11 ch · ~20 min14Round fourteen: “how does anything else talk to it?”
The pressure: nine services, one ledger · Choosing a protocol: the honest decision table · TCP, and what it guarantees you already rely on · HTTP/1.1, HTTP/2, and head-of-line blocking · gRPC internals: HTTP/2 streams and protobuf framing · When gRPC is wrong, and REST is right · WebSockets: the balance feed, and backpressure · Server-sent events, and why they often win · UDP, and the two places a bank actually uses it · ISO 8583 and the persistent socket reality of cards · The posting API: one interface, every caller · Loan disbursement, as a ledger call · Loan recovery, sweeps, and partial repayment · Overdraft: how a limit is communicated and enforced · Savings, interest accrual, and scheduled posting · Which transactions may exceed a limit, and who decides · Service decomposition: where the seams go · Service-to-service auth: mTLS, SPIFFE, and scoped tokens · The client SDK, and what belongs inside it · Versioning a money API without breaking anyone · Sketch v14: the integration surface
21 ch · ~20 min15Round fifteen: “ten years of data”
The pressure: the ledger never forgets · Sizing it: from 10 GB to 400 TB, derived · Indexes: what they cost on the write path · B-tree internals, and why index order matters · Covering indexes and index-only scans · Partitioning: range, list, and hash · Time-based partitioning for a ledger · Hot, warm, cold, frozen: the tiering model · Archiving without breaking the audit trail · Restoring an archived account, end to end · The lake, the warehouse, and the lakehouse · File formats: Parquet, ORC, and why columnar wins · Table formats: Iceberg, Delta, and time travel · Entity resolution: linking a customer across systems · Data contracts between teams · Lineage, and answering “where did this number come from” · Retention, deletion, and the GDPR-versus-ledger conflict · Sketch v15: the data platform
18 ch · ~20 min16Bonus round: “now design a different one”
The transferable skeleton · Designing a retail bank, in fifteen minutes · Designing a neobank: Cleva, Grey, and the USD problem · Designing a PSP: Paystack, Flutterwave, Monnify · How a PSP differs from a bank, structurally · Designing a POS network and its offline problem · Designing a lending platform on someone else's ledger · What stays the same in all of them
8 ch · ~50 min18Round sixteen: “who is this customer, and what may they do?”
The pressure: not every account is the same account · KYC tiers: what each tier buys the customer · Account types: personal, business, savings, current · The tier × type matrix, and why it is data · Resolving limits when both apply · Tier upgrades, downgrades, and grandfathering · Business accounts: mandates, signatories, dual control · PND: post-no-debit, and its four varieties · Receiving while restricted: credit-in, debit-out · Auto-debit on credit: the standing sweep instruction · Posting ahead: claims against future credits · Ordering when several claims compete for one credit · Backlog clearing, and why it is not a queue · Restriction precedence: who wins when rules conflict · Support tooling and the four-eyes boundary · Sketch v16: the entitlement layer
16 ch · ~20 min19Round seventeen: “fees, the company books, and who pays for what”
The pressure: revenue is not a number in a spreadsheet · A taxonomy of fees in a bank · Fees we charge: pricing, waivers, and tiers · Fees we pay: interchange, scheme, provider, rail · Fee posting: when, and against which account · Recognition: earned now, deferred, or amortised · Pass-through versus absorbed cost · The company chart of accounts, properly · Customer funds versus company funds · Safeguarding, and proving segregation daily · Reconciling user funds: the two-sided check · Reconciling company accounts and internal transfers · Unit economics: profit per transaction, derived · VAT, withholding, and stamp duty on the ledger · Month-end: accruals, provisions, and the P&L · Fee disputes, refunds, and goodwill credits · What finance actually asks for, and why · Sketch v17: the revenue and books layer
18 ch · ~20 min20Deep dive: the web transport stack
Why a banking engineer should know this layer · The journey of one request, layer by layer · TCP: the handshake, and the cost of a round trip · Congestion control, and why slow start matters · TLS: the handshake, and what 1.3 removed · Certificates, chains, and the failures you will meet · HTTP/1.1: the bottlenecks, and the workarounds · HTTP/2: the binary framing layer · Streams, multiplexing, and stream states · HPACK: how headers get compressed · Flow control, and the window nobody tunes · Server push, and why it was abandoned · The HTTP/2 failure modes in production · HTTP/3 and QUIC: reliability above an unordered transport · Connection migration, and the mobile case · Head-of-line blocking, traced through all three versions · Choosing a version, per hop · Debugging the transport layer · What this means for the bank, concretely
19 ch · ~20 min21The whole board
The complete architecture, walked end to end · A payment, traced through every component · Every major tradeoff, in one table · What we deliberately did not build · How this generalises beyond banking · Defending it: the twenty hardest questions
6 ch · ~40 min