{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:4cf2f22767e9a99b893684ffb6e0d1fa7238fa4bcafda89190b6a2052a31b0ef","slug":"grc-policy-exception-risk-acceptance","url":"/assets/agent_workflow-grc-policy-exception-risk-acceptance-9c6e70fa.1d5caa144fe51a24.json"},"kind":"record","record":{"attributes":{"department":"risk-management","domain":"grc","lineOfDefense":"monitor"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-policy-exception-risk-acceptance","description":"Policy Exception & Risk Acceptance as a decision-aware workflow. It carries a waiver from request and justification through risk assessment, compensating controls, time-bound approval, registration with expiry, and re-review so no exception outlives its rationale. The exception IS an Issue item (issue_type: policy_exception) — the workflow runs on it, and the exception register is simply the set of those Issues, queryable by their filterable exception_expiry_date. The affected policy is a Policy item the Issue links to; a granted acceptance also sets treatment: accept on the linked Risk item. In scope: time-bound exceptions/waivers to an existing policy that are risk-accepted for a bounded window. Out of scope: permanent policy-change proposals, which route to the Policy Lifecycle Management workflow (the Policy item's revision process) rather than this waiver workflow. No upstream or downstream workflow feeds or consumes this one; the exception request is the initial input, and recurring-exception patterns are compiled as feedback onto the affected Policy items at close.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-policy-exception-risk-acceptance","capabilities":[],"controls":["UC-ASSET-10","UC-RISK-09","UC-RISK-08","UC-AUDIT-17"],"domains":["grc"],"lineOfDefense":"monitor","mappingStatus":"mapped","releaseId":"sha256:4cf2f22767e9a99b893684ffb6e0d1fa7238fa4bcafda89190b6a2052a31b0ef","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:grc-policy-exception-risk-acceptance","standards":["coso-erm","iso-27001"],"teams":["risk-management","compliance-legal"]},"id":"wf:G14","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AG14","slug":"grc-policy-exception-risk-acceptance","sourceIds":["coso-erm","iia-2024","iso-31000","nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"Policy Exception & Risk Acceptance","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:20ca9fdeac78f3bd82223a0bda4382f3648081dec9c4cdfb9a1f4fb481ea7a7e","properties":{},"sourceDetailPath":"/data/v1/records/wf-g14-215df6e0.json","sourceId":"wf:G14","targetDetailPath":"/data/v1/records/uc-uc-risk-09-06ffdff1.json","targetId":"uc:UC-RISK-09","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4de2d177e0abba737d6b95765bcecc5e40aed137ee41021eb545c3f7fb5c8f4c","properties":{},"sourceDetailPath":"/data/v1/records/wf-g14-215df6e0.json","sourceId":"wf:G14","targetDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","targetId":"uc:UC-AUDIT-17","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4ec6630df08c5ab168ab44645fd41a8871e501f0529c34b79ebb0185897aa741","properties":{},"sourceDetailPath":"/data/v1/records/wf-g14-215df6e0.json","sourceId":"wf:G14","targetDetailPath":"/data/v1/records/uc-uc-asset-10-bbda2a79.json","targetId":"uc:UC-ASSET-10","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ae243ab2fe7e15f86644ba813290ee70005b0bd5655d568ebb19b1b327214793","properties":{},"sourceDetailPath":"/data/v1/records/wf-g14-215df6e0.json","sourceId":"wf:G14","targetDetailPath":"/data/v1/records/uc-uc-risk-08-5f27bebc.json","targetId":"uc:UC-RISK-08","type":"oversees"}],"schemaVersion":1}
