Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Request a policy exception

Users can request exceptions for policies, control objectives, or issues by specifying the reason of exception on a particular list of the systems, applications, networks, or entities for which the exception will apply. The user must also specify the duration for which the exception is required.

Before you begin

Role required: sn_grc.business_user, sn_grc.business_user_lite

About this task

Exceptions provide temporary relief for users unable to meet compliance requirements due to extraordinary situations. For example, if the user is unable to meet a control that stipulates that all critical OS servers must be patched within 48 hours after the OS vendor releases patches.

Procedure

  1. Navigate to All > Policy and Compliance > My Policy Exceptions.

  2. Click New.

  3. On the form, fill in the fields.

FieldDescription
NumberUnique identification number.
RequesterPerson requesting the policy exception, usually the control owner.
Approval groupGroup that has the compliance manager role. You cannot edit the approval group if the policy exception reaches Review state.If you do not provide an approval group, then the field defaults to compliance manager. Compliance manager is the default role if the policy exception is raised from any upstream application that is integrated with GRC. For example, if you raise a policy exception for a problem that is related to an incident and that problem is related to GRC.
ApproverUser from the approval group. If the exception policy moves to the Analyze state, then you must select an approver.
StateState of the policy exception within the approval workflow.
SubstateApproval substate of the policy exception within the approval workflow.
PriorityApproval priority of this policy exception
Watch listUsers that are notified when the request is updated.
NameUnique name of the policy exception.
ReasonReason for requesting the policy exception. The requester can change the reason until the policy exception is approved.
JustificationStatement of explanation for the policy exception. Justification is also displayed in the Additional comments field of the Comments tab.
Source
Source type

Type of policy exception that you want to create. The options are:- Policy: Create a policy exception based on a policy. - Control objective: Default is a single control objective on which the policy exception is created.

When you select a control objective, theImpacted controls tab appears, where you can select controls associated to the control objective.

  • Controls: Option to create a policy exception on multiple controls.

Select Control to associate multiple controls from different control objectives. This option supports multiple controls objectives for your policy exception, instead of creating multiple policy exceptions that could be applied on multiple controls.

  • Issue: Issue associated with this policy exception.
Control objectiveControl objective associated with this policy exception.
IssueIssue associated with this policy exception.
Target recordTarget record table on which the policy exception is applied. This table is also referenced in the Policy exception target table field of the Policy Exception Integration Registry form.
Risk assessment
Risk ratingSelect the risk rating as determined by the risk assessment performed on the policy exception.
Risk descriptionDescription of the risk as performed by the risk manager during risk assessment.
Analysis of risk and impactDetails on the likelihood of this risk occurring and residual impacts of this risk on the policy exception.
Risk mitigation planThe risk mitigation plan for this policy exception.
Schedule
Valid fromDay on which the policy exception begins.
Valid toDay on which the policy exception ends.Valid to date must be after Valid from date and cannot be a past date.
DurationNumber of days between the Valid from and Valid to dates.
Approved extensionsNumber of times extensions have been requested so far and have been approved.
Remaining extensionsNumber of times extensions can be requested in future.Remaining extensions = Value in the **Number of extensions allowed for a policy exception** property – Number of Approved extensions.
CreatedDate on which the policy exception was requested.
Date approvedDate on which the request was approved.
Extension dateRequested extension date, which is after the Valid to date.
Extension reasonReason for extension.
Original valid toDate until which the policy exception was originally requested and approved. The original Valid to date is populated only when the extension is approved.
Comments
Work NotesWork notes can be used by exception reviewers and approvers to share Information about the exception.
Additional commentsThese comments are used by the reviewer to communicate additional information to the exception requester.
Confidentiality
ConfidentialOption to enable confidentiality of the record. Only the assigned confidential users or confidential groups of users can access the record.For more information on confidential option, see Confidentiality flag for audit and compliance records.
**Note:** In versions prior to Version 10.1, the **Risk assessment** tab was called **Business Impact Analysis** and required that the GRC: Risk Management application be activated. Starting in Version 10.1, the dependency on Risk Management has been removed and the associated field names have changed.

**Approved extensions**, **Remaining extensions**, **Date approved**, **Extension date**, **Extension reason**, **Original valid to** fields appear only when you have requested an extension on the policy exception and has been approved by the approver.
  1. Save the policy exception.

  2. Click any of the tabs to view the various types of information for the policy exception

  3. Click Update.

Parent Topic:Manage policy exceptions and extensions