Skip to content

Exceptions

Where to find it: Risk Management, then Exceptions (/exceptions).

An Exception (EXC-YYYY-NNNN) is a formal, time-bound, approved decision to deviate from a requirement or control.


What an exception is for

Every organisation has situations where the prescribed control is not achievable: a legacy platform that cannot support a modern authentication method, a regulatory requirement that conflicts with another jurisdiction, a control that will be met once a migration completes in nine months.

The choice is between recording that honestly with an owner and an expiry, or letting it sit as an unexplained red item that gradually stops being read.

An exception is the first option.


What an exception is not

An exception never makes an unmet requirement satisfied

When an approved exception covers a gap, OrviQ records:

  • Requirement satisfaction: unchanged — still not_satisfied if the control is ineffective
  • Governance disposition: accepted_deviation, referencing the exception

Satisfaction is not overwritten, and it is not replaced by a value like "exception applied". The obligation remains unmet, and the record says so. The exception records what the organisation decided to do about an unmet obligation.

This is what makes an exception defensible. An exception that turned a red item green would be a mechanism for hiding gaps; one that leaves the gap visible and adds an approved, expiring decision on top of it is a governance control.


Lifecycle

StatusMeaning
draftBeing prepared
requestedSubmitted for review
in_reviewUnder review
approvedApproved; effective within its validity window
rejectedDeclined, with rationale
activeIn force
expiredValidity window has passed
closedClosed before expiry
revokedWithdrawn

An exception is effective only when it is approved or active and the current time falls within its validity window. An approved exception whose end date has passed automatically becomes ineffective.


What an exception record carries

FieldPurpose
Business referenceEXC-YYYY-NNNN
Title, description, justificationWhat is being deviated from and why
Affected recordsFramework, requirement, obligation, control, scope
Compensating controlsWhat mitigates the residual exposure
Related riskThe risk this deviation contributes to
OwnerWho is accountable
Requested by and atMaker record
Reviewed, approved or rejected by and atChecker record
Validity from and untilThe effective window
Reassessment dateWhen it must be re-examined
Approval or rejection rationaleThe reasoning, on the record
HistoryEvery transition

Maker-checker segregation of duties

A requester cannot approve their own exception

Segregation of duties is enforced at the service layer: the person who requested an exception cannot approve or reject it.

Requesters are excluded from their own review queues, and returned or rejected exceptions route back to the requester's Workbench.

The default chain is four-eye: draft and submit, then review and approval, then a decision. A six-eye chain adding an executive stage is available through workflow template configuration for exceptions that warrant it.


Compensating controls

An exception with no compensating control is a statement that you are simply carrying the exposure. Sometimes that is the honest position; more often something does mitigate it.

Recording the compensating control does three things: it gives the approver something to weigh, it gives the reassessment something to test, and it gives an assessor an answer to the inevitable follow-up question.


Expiry and reassessment

Every exception has an end date. Exceptions do not renew silently.

The reassessment date drives a GRC Calendar entry and a Workbench task, so the exception comes back for a decision before it expires rather than after.

A permanent exception is a control gap with better manners

If an exception has been renewed four times over three years, the underlying issue is not temporary. Either fix it, accept the risk formally through risk acceptance, or change the control standard. Perpetual renewal is a way of never making that decision.


AI assistance

OrviQ can draft an exception justification from the context of the affected requirement and control. The draft is a starting point; the requester owns what is submitted, and the approver decides.

Requires the AI entitlement.


Permissions

ActionPermission
View the register and detailsexception.read
Request a new exceptionexception.create
Update, edit or cancel a draftexception.manage
Review requests and assess compensating controlsexception.review
Approve, reject or grant temporary exceptionexception.approve
Close, renew or retireexception.close

All require the compliance_core entitlement.


Example

Exception EXC-2026-0031 — MFA on legacy trading platform service account.

FieldValue
Affected controlCTL-2026-0041 MFA Standard
Affected requirementA.8.5
Justification"The trading platform's integration service account authenticates via a vendor protocol that does not support MFA. The vendor has committed to protocol support in release 8.2, scheduled for Q4. The account cannot be removed without interrupting settlement processing."
Compensating controls"Account restricted to a single source IP on a dedicated segment; credentials held in the privileged vault with dual-control checkout; all sessions recorded and reviewed weekly; alerting on any authentication from an unexpected source."
Related riskRSK-2026-0014
Requested byIT Security Operations Manager
Approved byChief Risk Officer
Validity90 days
Reassessment dateDay 75

Effect on assurance:

DimensionValue
Requirement satisfactionnot_satisfied — unchanged
Governance dispositionaccepted_deviation, referencing EXC-2026-0031
Exception postureactive

What the board pack shows: an accepted deviation with a named approver, a compensating control set, a 90-day expiry and a reassessment date — not a green tick, and not an unexplained red one.

On day 75 the exception returns to the Workbench. If release 8.2 has shipped, it closes. If not, a renewal decision is made by a person, with the same approval requirements as the original.


Troubleshooting

"The requirement still shows not satisfied." Correct and intentional. Check the governance disposition — it will read accepted_deviation.

"I cannot approve an exception I requested." Maker-checker segregation of duties. A different approver is required.

"An exception stopped applying." Its validity window passed. Expired exceptions become ineffective automatically.

"I want to extend an exception." Use renewal. It goes through the same approval chain — extension is a decision, not an edit.

"Exceptions is not visible." Requires the compliance_core entitlement and exception.read.


OrviQ Enterprise Governance, Risk & Compliance Platform