After entering the two digits of the 'Security Number' you then receive a 'One Time Access Code' through a text or phone call, although I have never logged in to my account before, and seem to be unable to get past this step now.
I think you then enter your proper password in, which I would hope is not stored in plain text, although the article I linked seemed to imply this was the case back in 2012.
It's a bit like having a number of related passwords, which the bank can ask you for any of them, and then verify is correct.
At the same time, they advise you to never give your password away, and that they will never ask you for your (full) password.
Talk about a mixed message...
They'd do a hash of each character of the password (in Lloyds' case, your "memorable word" combo), to compare your entries to.
Password: money
Secret word: ABCD
If they're going to ask for two characters from the secret word, they could then hash
saltmoneyAB
saltmoneyAC
saltmoneyAD
saltmoneyBC
saltmoneyBD
saltmoneyCD
and check against the relevant one.