Design account opening workflow

Quick Overview

This question evaluates a candidate's ability to architect a high-scale, secure, and regulated online account opening workflow, including API design, workflow orchestration, data modeling, PII protection, KYC/AML and sanctions integration, auditability, and operational reliability.

Design account opening workflow

Company: Coinbase

Role: Software Engineer

Category: System Design

Difficulty: hard

Interview Round: Online Assessment

Design an online bank account opening workflow. Define APIs to start, save, submit, and resume an application; perform KYC/AML and sanctions checks; prevent duplicate accounts; and provide real-time status. Describe workflow orchestration (synchronous vs. asynchronous steps), idempotency and deduplication, document upload and verification, audit trails, data model for applicants and applications, PII security (encryption, access control), rate limiting, fraud/risk scoring, failure handling and retries, and how to scale to millions of applications per day across regions.

Overview: This question evaluates a candidate's ability to architect a high-scale, secure, and regulated online account opening workflow, including API design, workflow orchestration, data modeling, PII protection, KYC/AML and sanctions integration, auditability, and operational reliability.

Community answers

Answer by esh.feeq

Online Bank Account Opening — Worked Solution (Steps 1–3) Corrected reference for the Coinbase-style prompt. Numbers carry explicit units; assumptions are stated inline. Step 1 — Requirements & Scope Functional Users can start a new application to open an account. Users can save partial progress and resume from a saved point. Users can upload documents; a document is applicant-owned and reusable across multiple applications. Users can provide identity and address proofs via a regional OIDC provider (where available). Users can submit an application. Applications are verified via region-based KYC/AML/sanctions providers. Users can view real-time application status. Users can cancel an active application. On a duplicate submission for the same product, the later submission overrides the earlier. Invariant: a verified identity may hold at most one account per product type. The audit trail (every state transition and decision) is retained for 7 years and is viewable (internal, RBAC-gated). Non-Functional Consistency: strong for account creation / the dedup invariant; eventual (read-your-writes) for status and form snapshots. Availability: 99.9%, with graceful degradation — intake stays available even when a downstream provider is down (queue and process on recovery). Latency: p99 2–5 s on the user-facing path; synchronous acknowledgement, asynchronous fulfillment (account appears greyed-out, activates when checks clear). Durability: application state and audit logs are durably re
|Home/System Design/Coinbase
Coinbase logo
Coinbase
Sep 6, 2025
hardSoftware EngineerOnline AssessmentSystem Design
9
0

System Design: Online Bank Account Opening Workflow

Context

You are designing a high-scale online bank account opening workflow for web and mobile clients. The system must operate in a regulated environment, integrate with external KYC/AML and sanctions providers, and provide a secure, resilient, and auditable experience across multiple regions.

Requirements

Design the following:

  1. APIs
  • Start a new application, save partial progress, submit, and resume an application.
  • Upload documents and verify them.
  • Provide real-time application status.
  1. Workflow orchestration
  • Which steps are synchronous vs. asynchronous, and why.
  • How to model long-running tasks, callbacks, and manual review.
  1. Correctness and safety
  • Idempotency and deduplication to prevent duplicate accounts.
  • Failure handling, retries, and exactly-once or at-least-once guarantees where appropriate.
  • Audit trails sufficient for regulatory compliance.
  1. Data and security
  • Data model for Applicants, Applications, Documents, and related entities.
  • PII security: encryption, key management, access control, and safe logging.
  • Rate limiting and abuse controls.
  1. Risk and compliance
  • KYC/AML and sanctions checks (and re-checks as needed).
  • Fraud/risk scoring and decisioning (auto-approve, reject, manual review).
  1. Scale and reliability
  • Scale to millions of applications per day.
  • Multi-region architecture and data residency.

State any minimal assumptions you make.

Submit Your Answer to Earn 20XP

Sign in to leave a comment

Loading comments...