CASE STUDY
Funding Review at North Mill Equipment Finance
8 minutes read
consistent funding review at scale
North Mill Equipment Finance (NMEF), founded in 2012 and headquartered in Norwalk, Connecticut, is a national small and mid-ticket equipment finance lender. They originate and service commercial equipment loans and leases through a nationwide referral source network concentrated in transportation, construction, healthcare, franchise, and manufacturing.
The final control before money leaves the building is the funding package review. A funding analyst opens a deal package (funding worksheet, wire request, payoff letters, bills of sale, titles, invoices, banking confirmation letters, ACH confirmations, emails) and reads it against North Mill's written Funding Package Review standard operating procedure (SOP). These documents routinely contain regulated personal and financial information: bank routing and account numbers, wire beneficiary details, borrower and guarantor identifying information. They share no common schema, are scans and photographs of wildly varying quality, and the value of the review sits in exactly the places where they disagree: an expired payoff letter, a wire instruction sourced from email rather than bank letterhead, a mismatched VIN, an invoice naming a different legal entity than the wire request.
That review was one person's reading. It was slow, it varied with who did it, and it left no structured record of what had actually been checked, while the errors it missed are dollar denominated and surface after the wire has gone out.
Steven Siler, Chief Technology Officer and executive sponsor of the AI effort, had a second problem underneath the first. A working prototype could already read a funding package and find what an analyst finds. What did not exist was a way to run that prototype safely: no key custody, no tenant sign-on, no entitlement, no audit trail, no data handling controls for the sensitive documents involved. The review that sat closest to the money, and closest to regulated personal data, was the one that most needed the governance nobody had yet built.
how claude reviews the package
Funding Review is not a document parser with a model attached. The uploaded PDFs and images are encoded and sent to Claude as content, together with North Mill's own SOP as the system prompt. The judgment is the model's, because the judgment is the job:
- Cross-document reconciliation. VIN, payee name, and amount are checked across the title, invoice, worksheet, and wire request; an ACH debit account is checked against the debtor of record. Correlation across documents that share no schema is where a model outperforms a template-per-vendor parser.
- Severity triage. Findings are ranked critical, moderate, or informational, reflecting North Mill's own judgment of materiality rather than a fixed lookup table.
- A resolution per flag. Each finding states what to obtain and from whom to clear it, turning the output into an analyst's worklist rather than a list of complaints.
- A recommendation. Proceed, conditional, or hold, with reasoning attached.
The SOP is carried into the model's instructions with a structured output schema layered on top, covering the package's document types, the review workflow, and a ranked taxonomy of flag categories. North Mill's standard is applied as written; the model is never asked to invent what "correct" means. Results render as findings, a payee and totals reconciliation, a document inventory, and the verdict, exportable to PDF or JSON as the retainable record of what was checked. The rubric itself is versioned in the source repository, so changing the standard is a reviewable change, not a retraining cycle.
data handling and sensitive information
The documents Funding Review processes routinely contain regulated personal and financial information: wire routing and account numbers, ACH details, payee and guarantor names, and other data that qualifies as nonpublic personal information.
- Encryption in transit. All traffic between the browser, Azure backend, and the Anthropic API runs over TLS. Documents are never transmitted unencrypted at any hop.
- No direct browser-to-model connection. The API key is never exposed to the browser. The Azure backend calls the Anthropic API, injecting the key server-side.
- Encryption at rest. Azure services encrypt data at rest by default and do not persist after the session is closed.
- Minimisation. Only the documents needed for a given review are sent per request; no document content is retained by Funding Review outside the audit record.
- No downstream write path. No connection to any funding or disbursement system. Nothing is auto-approved, auto-declined, or auto-disbursed — everything requires human intervention to move forward.
technical controls & architecture
Infrastructure as Code in Bicep, with DevOps pipelines across test and production environments, fronted by Azure Front Door. The application received its own Anthropic API key, separating its usage and spend from other internal projects. By design, the application has no write path to any funding system, a control that sits directly on a funding decision, and is enforced by architecture rather than policy.
delivery timeline
The requirement was raised in early May 2026, specifying the target end state in full: key custody, tenant authentication, security group restriction, and audit logging per run. The gateway and Funding Review were designed and built together over roughly seven weeks, reaching all four environments including production in a single pass, with production sign-off in mid-July.
This build was not representative of typical delivery speed. It carried the project framework, gateway, the authentication pattern, the API boundary, the deployment shape, front-end design, and the house stack decisions for the applications that followed, all of which were being created from scratch rather than applied.
impact
- Every package gets the same check. The SOP is applied in full, in the same order, to every deal, independent of who is reviewing and what time it is.
- Findings arrive ranked and actionable. Critical, moderate, and informational, each with the document it came from and the step required to clear it.
- Exceptions surface pre disbursement rather than after the money has left, which is the value of the control.
- From 30 to 45 minutes to under 10. Compiling the information for a funding package review typically took an analyst 30 to 45 minutes; it now takes less than 10.
- There is now a record. Each review exports a structured artifact stating what was present, what was missing, what reconciled, and what did not.
- In daily use. Funding Review is live in production and worked by the Funding and Documentation teams on real deals, not held in a pilot sandbox.
tech stack
- Model: Claude Sonnet 4.6 (via Anthropic Messages API), reached only through NMEF's own gateway, never directly from the browser.
- Frontend: React, MSAL, client-side document encoding.
- Backend: .NET 10 Azure backend as the sole Claude gateway.
- Identity: Microsoft Entra ID, MSAL, app role authorization, per-environment security groups.
- Cloud: Azure Static Web Apps, Azure Front Door, Azure Functions, API Management, Key Vault, Cosmos DB — all with encryption in transit and at rest.
- IaC and CI/CD: Bicep, Azure DevOps Pipelines.