Skip to content

Exceptions

An exception records a deliberate, approved deviation from a control, a policy or a requirement: the legacy server that cannot take the current TLS baseline, the contractor laptop outside MDM, the quarterly review skipped during a migration. Documenting it turns an invisible gap into a governed one — with a reason, an owner, an approver and, crucially, a date on which it stops being acceptable.

Governance → Exceptions in the sidebar.

Each exception carries a Reference ID and Name, a Description of what is being deviated from and why, a Severity on the shared scale — undefined, info, low, medium, high, critical — used to prioritise follow-up, an Expiration date marking when the exception no longer applies, one or more Owners responsible for closing it, an Approver who authorised it, an Observation field for review notes, Evidences substantiating the case, and an external Link.

StatusMeaning
DraftBeing written up, not yet submitted
In reviewWith the approver
ApprovedAuthorised and in force
RejectedDeclined; the deviation is not sanctioned
ResolvedThe underlying gap has been closed
ExpiredThe expiration date has passed
DeprecatedSuperseded or no longer relevant

Prefer Resolved or Deprecated over deletion: the record of what was tolerated, by whom, and for how long is often exactly what an assessor asks to see.

An exception is not a free-floating note — it points at the thing it excuses. Exceptions can be linked to assets, applied controls, vulnerabilities, risk scenarios and requirement assessments. That link is what lets a non-conforming requirement in an audit, or an unpatched vulnerability past its SLA, carry a visible, approved reason instead of looking like neglect.

Create one with Add exception, set its domain, severity and expiration date, then attach it to the objects it covers. The list supports search and filters by severity, status, owner and domain, so the standing question — which approved exceptions expire this quarter, and who owns them — is one filter away.

Exceptions roll up into reporting: the analytics dashboard breaks the population down by status, and per-audit analytics show which requirements in that audit are covered by an exception.

  • Risk acceptances — the formal decision to tolerate a whole risk scenario, with its own approval workflow.
  • Applied controls — what an exception typically deviates from.
  • Vulnerabilities — link an exception to a weakness you cannot fix inside the SLA.
  • Audits — where an exception explains a non-conforming requirement.