Skip to main content
All answers

What is a compliance exception?

A compliance exception is a documented deviation from a required control, with a formally approved compensating control documenting equivalent risk reduction. Exceptions exist because no control set perfectly fits every environment: legacy systems, vendor constraints, and operational realities sometimes require deviation. Auditors expect exception registers with approval chains, supporting evidence, and auto-expiry to prevent stale waivers.

The longer answer.

Exceptions are a normal and healthy part of a mature program, not an admission of failure. A rigid requirement will occasionally conflict with reality: an application vendor mandates a setting the benchmark forbids, or a legacy platform cannot support a modern cryptographic control. The disciplined response is not to silently ignore the control but to record the deviation, name the compensating measure that reduces the residual risk, and get someone accountable to approve it.

The difference between a governed exception and an ungoverned one is the paper trail. Auditors look for a register showing who approved each deviation, the justification, the supporting evidence, and crucially an expiry date so waivers are revisited rather than left to accumulate forever. Without expiry and periodic review, an exception register slowly becomes a list of forgotten weaknesses that nobody re-examines, which is exactly the outcome the process is meant to prevent.

More questions on Fundamentals?

Our compliance engineers can show you exactly how CISGuard handles Fundamentals in a briefing scoped to your environment.