Assertions is the way to go. In every domain there are invariants. Check for those invariants after any update to your model. For example - in the submarine case, the two invariants would be - "submarine can float" and "submarine can sink". No matter what your submarine design is, the final product should be able to float and sink as needed and therefore these assertions should always be true. If at any time either of these two invariants are violated, you've got a problem in your design.