Terminology Index

Glossary

1801 terms

Open concept maps

Showing 609-640 of 1801 terms

E
32

Exception Process Design

Designing how policy exceptions are requested, reviewed, approved, tracked, and expired, so deviations from policy are managed as deliberate, time-bound, accountable risk decisions rather than uncontrolled loopholes.

A sound exception process defines the whole lifecycle of a deviation: how it is requested with justification, who reviews and approves it by risk level, what compensating controls are required, how it is documented and tracked, and when it expires and is re-reviewed. Designing this well keeps exceptions legitimate and visible, prevents abuse, and ties each exception to an accountable owner and a real risk-acceptance decision.

Introduced in: Policy Writing in Practice

Examples

  • Requiring every exception to have justification, an owner, and an expiry date.
  • Mandating compensating controls as a condition of an exception.
  • Tracking active exceptions and re-reviewing them when they expire.

No related terms linked yet.