Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Assess risk for a policy exception

After the review of a policy exception request and before deciding to approve or reject a request, the compliance manager may choose to request a risk assessment by the risk manager.

Before you begin

Role required: compliance manager

About this task

For more information, see Manage policy exceptions and extensions.

Procedure

  1. Navigate to All > Policy and Compliance > My Policy Exceptions.

  2. Select the policy exception.

  3. Review the form details, as necessary.

  4. Click the Business Impact Analysis tab and update the following fields:

FieldValue
Risk descriptionDescription of the risk.
Residual likelihoodLikelihood of the risk occurring. If it is not None, select the likelihood of this risk occurring:- 5 — Extremely Likely - 4 — Likely - 3 — Neutral - 2 — Unlikely - 1 — Extremely Unlikely
Residual impactResidual impact of the risk. If it is not None, select the residual impact of this risk:- 5 — Very High - 4 — High - 3 — Moderate - 2 — Low - 1 — Very Low
Residual scoreValue calculated after you select a residual likelihood and residual impact rating:- 5 — Very High - 4 — High - 3 — Moderate - 2 — Low - 1 — Very Low
  1. Perform one of the following actions.
OptionAction
To view or add impacted controls to the policy exception
  1. Click the Impacted Controls tab.
  2. Click Add or Add All.
  3. Choose the controls to associate to the policy exception.
To view mitigating controls on the policy exceptionClick the Mitigating Controls tab.
To view or add risks to the policy exception

Click the Risks tab.

Note: This option is available when Governance, Risk, and Compliance is also activated.

To view or add approvers to the policy exceptionClick the Approvers tab.
To view or add task service level agreements to the policy exceptionClick the Task SLAs tab.
  1. Click Update.

Parent Topic:Assess risks