Exceptions
The Exceptions section allows you to track controls or compliance requirements where a vendor does not fully meet the expected requirement and an exception has been raised.
Each exception includes:
Third Party Name — The vendor associated with the exception.
Domain — The area of security or compliance where the exception applies.
Control — The specific control or requirement for which the exception was raised.
Status — The current status of the exception, such as Opened.
Due Date — The date by which the exception is expected to be reviewed or resolved.
Raised By — The user who raised the exception and the date it was created.
Managing Exceptions
Use the Search field to find a specific exception and the status filter to view exceptions based on their current status.
Exceptions can be used to:
Document gaps or deviations from required controls.
Assign a due date for remediation or review.
Track the status of outstanding exceptions.
Maintain a record of who raised the exception and when.
This provides a centralized view of control exceptions and helps teams track outstanding risk items through to resolution.
