Credit unions should design an AI vendor exit before signing the contract: inventory every dependency, define portable records, secure transition rights, maintain a fallback workflow, validate the replacement, remove access and obtain evidence of deletion.

Changing an AI provider is not a normal software cancellation. The service may contain prompts, retrieval indexes, workflow rules, human overrides, evaluation sets, decision logs and connections to member systems. A clean exit must separate what the credit union owns, what the vendor can export, what must be reconstructed and what must remain available for audit or member support.

The NCUA’s active third-party guidance, last modified July 9, says planning should consider exit strategy and contracts should address record ownership and access, continuity, default, termination and escape clauses. The agency also reiterated in June 2026 that it does not approve vendors and that credit unions remain responsible for vendor monitoring, cybersecurity, contract oversight and compliance.

AI adds a model layer to that familiar third-party obligation. The NIST AI Risk Management Framework playbook recommends documenting third-party AI components, verifying contingency processes and decommissioning third-party systems or pretrained models that exceed risk tolerances. That makes exit readiness part of operating control, not a procurement footnote.

1. Map the dependency, not just the product

Create a system map showing the vendor, its model providers and subcontractors, source systems, APIs, data stores, retrieval indexes, downstream decisions and employee handoffs. Name the business owner and technical owner for each connection. Record which service will stop if the vendor becomes unavailable and how long the credit union can operate without it.

Exit test: an independent team can identify every data flow, credential, business rule and member-facing dependency without relying on the vendor’s account representative.

2. Define the portable evidence package

List the records that must leave with the credit union: source data, configuration, prompts, knowledge documents, output history, human overrides, model and policy versions, evaluation results, incidents and decision logs. Specify formats, schemas, metadata, encryption and delivery timing. “Data export available” is not enough if the output cannot be reconciled to the credit union’s records or used by another system.

Do not assume model weights, vendor-generated features or proprietary embeddings are portable. Identify those restrictions during due diligence and decide what can be rebuilt from credit-union-owned source material. Our AI vendor due-diligence checklist provides the broader contract and control questions that should precede this inventory.

3. Put transition rights in the contract

Define termination for cause and convenience, notice periods, cure rights, fees and a capped rate for transition assistance. Require continued service during an orderly handoff, cooperation with a successor, timely export, documentation transfer, subcontractor obligations and a process for returning or destroying data.

The federal banking agencies’ third-party guidance does not govern credit unions, but it provides a useful contract benchmark: reasonable transition time, timely data return or destruction, assigned termination costs, alternatives for continued service and control of access after the relationship ends.

4. Maintain a workable fallback

For a critical workflow, document how employees will continue or safely pause work if the AI service is unavailable. Preserve the last approved non-AI procedure where practical. Define queue limits, manual authority, member communications, service targets and the point at which volume or risk requires escalation.

A fallback that exists only on paper is not sufficient. Run a short exercise using representative cases and measure throughput, error, member delay and evidence capture. Include the cost of parallel operation and exit assistance in the investment case; the CreditUnionAI News business-case framework explains how to keep those lifecycle costs visible.

5. Validate the replacement as a new system

A successor model will not reproduce the prior vendor’s behavior exactly. Re-test the intended use, data permissions, accuracy, explanations, bias and fairness where relevant, security, accessibility, exception routing and human override. Use a controlled set of historical cases, but prevent the test from exposing data beyond its approved purpose.

Compare outcomes by scenario—not only overall agreement. A small difference concentrated in adverse actions, fraud flags, hardship cases or member communications can be more important than a high average match rate. Set explicit go, pause and rollback thresholds before moving production traffic.

6. Cut access and prove disposition

At cutover, revoke users, service accounts, API keys, tokens, network paths and support access. Reconcile copies held by the vendor and its subcontractors. Obtain a dated record of return or destruction, note any legally required retention and preserve the evidence needed for complaints, audits, examinations and prior decisions.

Recent NIST system-planning guidance released June 30 emphasizes documenting data as it is created, collected, used, stored and disposed of, along with owners, components and data flows. The same record makes an AI exit easier to verify.

7. Set triggers and rehearse annually

Define who may initiate an exit and what forces review: persistent control failures, unacceptable model drift, security events, service degradation, material price changes, loss of required transparency, subcontractor changes, acquisition or insolvency. Assign a decision owner, transition leader and board-reporting path for critical services.

Tabletop the plan at least annually and after major model, data or workflow changes. The exercise should produce evidence: export time, missing records, fallback capacity, replacement-test results, unresolved contract dependencies and corrective owners. An exit plan is ready only when the credit union can demonstrate that it can leave without losing control of the member relationship or the record of past decisions.

Make the next AI vendor decision reversible. Subscribe to the CreditUnionAI Weekly Briefing for practical governance and implementation coverage.

Get the Weekly Briefing