workflow

Policy Exception & Risk Acceptance

Policy Exception & Risk Acceptance as a decision-aware workflow. It carries a waiver from request and justification through risk assessment, compensating controls, time-bound approval, registration with expiry, and re-review so no exception outlives its rationale. The exception IS an Issue item (issue_type: policy_exception) — the workflow runs on it, and the exception register is simply the set of those Issues, queryable by their filterable exception_expiry_date. The affected policy is a Policy item the Issue links to; a granted acceptance also sets treatment: accept on the linked Risk item. In scope: time-bound exceptions/waivers to an existing policy that are risk-accepted for a bounded window. Out of scope: permanent policy-change proposals, which route to the Policy Lifecycle Management workflow (the Policy item's revision process) rather than this waiver workflow. No upstream or downstream workflow feeds or consumes this one; the exception request is the initial input, and recurring-exception patterns are compiled as feedback onto the affected Policy items at close.

In catalog since 2026-09-17T22:28:00Z · Last changed 2026-10-04T21:48:26Z (791ff2dd3a45)

Record JSON · Open in map · Data retrieval guide

Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.

Attributes

domain
grc
department
risk-management
lineOfDefense
monitor

Details

teams
  • risk-management
  • compliance-legal
domains
  • grc
standards
  • coso-erm
  • iso-27001
sourceTemplateId
workflow-library:grc-policy-exception-risk-acceptance
releaseId
sha256:b535910d5f1ed025ef5c23371ab74ab4b326cb89da21e23cdbc1d7560b9ae2cc
canonicalUrl
https://evidenceflows.com/workflows/all/?w=grc-policy-exception-risk-acceptance
capabilities
  • policy-exception-risk-acceptance
mappingStatus
mapped
lineOfDefense
monitor
controls
  • UC-ASSET-10
  • UC-RISK-09
  • UC-RISK-08
  • UC-AUDIT-17
roleIntegrity
activityCount
0
ermPhases
    lineRoles
      serviceModes
        warnings

          Source

          No record-specific source URL is provided.

          Download workflow template · Release: sha256:b535910d5f1ed025ef5c23371ab74ab4b326cb89da21e23cdbc1d7560b9ae2cc

          Connections