What is a compliance exception?
More context
Exceptions are a normal and healthy part of a mature program, not an admission of failure. A rigid requirement will occasionally conflict with reality: an application vendor mandates a setting the benchmark forbids, or a legacy platform cannot support a modern cryptographic control. The disciplined response is not to silently ignore the control but to record the deviation, name the compensating measure that reduces the residual risk, and get someone accountable to approve it.
The difference between a governed exception and an ungoverned one is the paper trail. Auditors look for a register showing who approved each deviation, the justification, the supporting evidence, and crucially an expiry date so waivers are revisited rather than left to accumulate forever. Without expiry and periodic review, an exception register slowly becomes a list of forgotten weaknesses that nobody re-examines, which is exactly the outcome the process is meant to prevent.