AI Playbook for Model Deprecation Risk Management
A financial institution has deployed a third-party AI model for credit risk assessment that the vendor has announced will be deprecated in 9 months. The model is used in 3 credit products affecting $2.1B in originations annually. The bank has no approved replacement and the vendor's next-generation model requires re-validation.
When to use this playbook
- Use this playbook when the decision looks like the situation above: A financial institution has deployed a third-party AI model for credit risk assessment that the vendor has announced will be deprecated in 9 months.
- It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Model Deprecation Risk Management".
- Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.
What you'll need
- Vendor deprecation notice and migration guidance
- Current model documentation and validation report
- 3 credit product SOPs that depend on the model
- Candidate replacement model technical documentation
- OCC model risk guidance on model replacement and validation
Attachments: Documents (Documents)
The Prompt
You are an AI governance specialist managing a model deprecation risk for a financial institution. I am attaching: Work only from the attached source files. If a conclusion is not supported, say so. Produce: 1. Build the risk timeline: what happens at month 9 if no replacement is in place — operational and regulatory consequences of running an unsupported model? 2. Design the replacement model validation plan: what SR 11-7 requirements apply and what is the minimum validation timeline? 3. Identify interim risk management options: what compensating controls can the bank implement if replacement is not validated in time? 4. Assess the vendor's migration path: is the next-generation model the best option, or should the bank evaluate alternatives? 5. Tell me the board and examiner communication strategy for the deprecation risk and mitigation plan. Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.
What to expect
- Deprecation risk timeline with operational and regulatory consequences
- SR 11-7 replacement validation plan
- Interim compensating controls
- Vendor vs. alternative model assessment
- Board and examiner communication strategy
Review before you act
- Validate this output against source files before relying on it: Build the risk timeline: what happens at month 9 if no replacement is in place — operational and regulatory consequences of running an unsupported model?.
- Validate this output against source files before relying on it: Design the replacement model validation plan: what SR 11-7 requirements apply and what is the minimum validation timeline?.
- Validate this output against source files before relying on it: Identify interim risk management options: what compensating controls can the bank implement if replacement is not validated in time?.
- Validate this output against source files before relying on it: Assess the vendor's migration path: is the next-generation model the best option, or should the bank evaluate alternatives?.
- Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
- Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
- Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.
Why compare models on this
For Model Deprecation Risk Management, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface deprecation risk timeline with operational and regulatory consequences; sr 11-7 replacement validation plan; interim compensating controls; vendor vs. alternative model assessment. Those are comparison artifacts — they only exist if more than one model runs. Reconciliation protocols exist because models disagree. The playbook's job is to make disagreement inspectable, not to hide it behind a single blended answer.
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

