workflow
Policy Exception & Risk Acceptance
Policy Exception & Risk Acceptance as a decision-aware workflow. It carries a waiver from request and justification through risk assessment, compensating controls, time-bound approval, registration with expiry, and re-review so no exception outlives its rationale. The exception IS an Issue item (issue_type: policy_exception) — the workflow runs on it, and the exception register is simply the set of those Issues, queryable by their filterable exception_expiry_date. The affected policy is a Policy item the Issue links to; a granted acceptance also sets treatment: accept on the linked Risk item. In scope: time-bound exceptions/waivers to an existing policy that are risk-accepted for a bounded window. Out of scope: permanent policy-change proposals, which route to the Policy Lifecycle Management workflow (the Policy item's revision process) rather than this waiver workflow. No upstream or downstream workflow feeds or consumes this one; the exception request is the initial input, and recurring-exception patterns are compiled as feedback onto the affected Policy items at close.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- risk-management
- lineOfDefense
- monitor
Details
- teams
- risk-management
- compliance-legal
- domains
- grc
- standards
- coso-erm
- iso-27001
- sourceTemplateId
- workflow-library:grc-policy-exception-risk-acceptance
- releaseId
- sha256:4cf2f22767e9a99b893684ffb6e0d1fa7238fa4bcafda89190b6a2052a31b0ef
- canonicalUrl
- https://workflow-library.com/all/?w=grc-policy-exception-risk-acceptance
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-ASSET-10
- UC-RISK-09
- UC-RISK-08
- UC-AUDIT-17
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:4cf2f22767e9a99b893684ffb6e0d1fa7238fa4bcafda89190b6a2052a31b0ef
Connections
- Policy Exception & Risk Acceptance oversees UC-RISK-09 — Select, plan, and implement risk treatments
- Policy Exception & Risk Acceptance oversees UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
- Policy Exception & Risk Acceptance oversees UC-ASSET-10 — Assess and track changes and exceptions for risk impact
- Policy Exception & Risk Acceptance oversees UC-RISK-08 — Evaluate and prioritize risks against risk criteria