When a business approves an AI system, it usually treats the decision as final. The system was reviewed, it passed, it is signed off. The trouble is that an AI system is not a fixed thing. The models underneath it are updated, retired and replaced over time, which means the system you approved can behave differently a few months later without anyone deciding that it should. This is the exposure most buyers never price in, and it is one of the specific things a proper AI governance standard is built to manage.
The moving target problem
Traditional software is stable. The version you approved runs the same way until you choose to change it. AI is different. The large language models that power these systems are updated and deprecated on the provider’s schedule, not yours. A model you relied on can be retired, replaced with a newer one, or subtly change how it responds. The capability might improve. It might also drift in ways that matter, handling an edge case differently or phrasing something in a way your compliance team would not have approved. The point is that the change can happen underneath you, and if nobody is managing it, you find out from a customer rather than from a process.
Why a one-time approval is not enough
This is why treating AI governance as a single sign off is a mistake. Approving the system once tells you it was acceptable on the day you looked. It says nothing about whether it is still acceptable after the model behind it has been updated three times. Real governance is continuous. It assumes the system will change and puts a process around that change, so that every material update is tested, checked against the same standards, and accountable to someone. Without that, your approval has a quiet expiry date that nobody wrote down.
What ISO 42001 actually governs
ISO 42001, the international management standard for AI, is designed around exactly this reality. It covers three things a buyer should care about. Ethics, meaning the system is held to defined principles about how it treats people. Transparency, meaning how it reaches a decision can be explained rather than hidden. And model change management, meaning there is a documented process for what happens when the underlying model changes, so an update does not quietly move the system outside the bounds it was approved within. Certification means an independent body has audited that these processes exist and work. 1Stream is certified to ISO 42001 for this reason, because governing a system that evolves is a different job to certifying one that stands still.
What model change management looks like in practice
In practice it means the boring, essential things. Knowing which model version is live and when it changes. Testing the system against your standards when a model is updated, not just when it is first deployed. Being able to explain and evidence how the system behaves after a change. And having a named accountability for that process rather than assuming the provider will simply get it right. For an organisation, this is the difference between an AI system you can trust on day one and one you can trust on day two hundred, after the technology underneath it has moved on.
What this means for your organisation
The lesson for any organisation adopting AI is to stop treating it as a fixed purchase and start treating it as a managed capability. The question to ask a provider is not only whether the system works today, but what happens when the model behind it changes, and whether that process is governed and audited. A provider certified to ISO 42001 can answer that with evidence rather than assurance. That is what protects you from the AI you carefully approved slowly becoming something you did not.
If you want to understand how a governed, certified approach to AI would protect your organisation over time, not just at launch, start with a structured conversation.
Book a CX AI Readiness Assessment at 1stream.co.za/cx-ai-readiness-assessment.
Frequently asked questions
Does an AI system stay the same after you approve it?
No. The models that power AI systems are updated, retired and replaced over time, so a system can behave differently months after it was approved unless that change is managed.
What is model change management?
It is the documented process for handling what happens when the underlying AI model changes, including testing the system against your standards on each update and keeping accountability for the outcome.
What does ISO 42001 cover?
It covers ethics, transparency and the management of AI systems, including model change management, and certification means an independent body has audited that those processes exist and work.
Why is a one-time AI approval not enough?
Because it only confirms the system was acceptable on the day it was reviewed. Continuous governance is needed because the model behind the system can change without your decision.
Is 1Stream certified for this?
1Stream is certified to ISO 42001, the international standard for AI management, which includes governing how the system is managed as the underlying models change.


