GO
GovernanceChecklist2026-05-20
ciaCorePolicy Exceptions and Risk Acceptance
What should a policy exception include?
- I see exam questions where management wants to bypass a security or operations policy. What makes an exception acceptable?
38 upvotes
Verified ExpertVerified Expert
AcadiFi Certified Professionalauthor: Verified Expert
- Related article:
cia-production-change-policy-exception-controls-map - Related question-bank placeholders:
["policy-exception-required-elements", "manager-authorization-limits"] - Question:
What should a policy exception include? - Question detail:
- I see exam questions where management wants to bypass a security or operations policy. What makes an exception acceptable?
- Answer:
- A policy exception should identify the policy being excepted, the exact deviation, the business justification, the risk owner, the authorized approver, compensating controls, expiration date, monitoring requirements, and the plan to return to normal compliance.
- The exception should be documented before the deviation when feasible. If the situation is urgent, the organization should still document the decision as soon as possible and perform after-the-fact review.
- The mistake is treating a manager's request as enough. The approver must have authority over the policy and the risk. Otherwise, the request should be escalated to the appropriate control owner or governance channel.
🔍
Master Core with our CIA Course
45 lessons · 90+ hours· Expert instruction
#policy-exception#risk-acceptance#compensating-controls#governance
Related Questions
What should an auditor do if a supervisor weakens a supported finding?
cia·CIA Part 2·46 upvotes
How should auditors prepare for a technical exit meeting?
cia·CIA Part 2·35 upvotes
When should audit quality concerns be escalated beyond the engagement team?
cia·CIA Part 2·56 upvotes
How does business knowledge affect internal audit quality?
cia·CIA Part 2·51 upvotes
Where should an auditor begin a full-company internal control audit?
cia·CIA Part 2·51 upvotes
Join the Discussion
Ask questions and get expert answers.