Workflow Template
Policy Exception Request Workflow
Enables a requester to submit a policy exception request. A risk reviewer assesses the exception and compensating controls, then routes the request based on risk level: low-risk exceptions go to the policy owner for approval, high-risk exceptions require risk/compliance approval. Approved exceptions are recorded with an expiry date for review; rejected requests are returned to the requester with a reason. The requester is notified of the final decision.
Policy exceptions often get approved in email threads with no record of who signed off, what controls were checked, or when the exception expires. This workflow gives requesters a structured way to submit exceptions, routes them to the right approver based on risk level, and records the decision with an expiry date for future review. Risk reviewers, policy owners, and compliance teams each get their part of the process without chasing status updates.
Business Outcomes
- Supports faster turnaround on exception requests with clear routing rules
- Helps reduce exceptions that get approved without proper risk review
- Makes it easier to track expiry dates and flag exceptions for renewal or closure
- Improves visibility into who approved what and why, for audit purposes
- Reduces back-and-forth by capturing rejection reasons in one place
Workflow Steps
Steps
- 1Create Exception Request Recordcreate record
Registers the submitted policy exception request as a record.
- 2Set Status: Submittedupdate record
Marks the request as submitted before risk review begins.
- 3Risk Review Assessmentcreate task
A risk reviewer assesses the exception, compensating controls, and assigns a risk level.
- 4Set Status: Under Risk Review Completeupdate record
Persists the risk assessment outcome and marks the request pending approval.
- 5Route Approval by Risk Level
Routes low-risk exceptions to the policy owner and high-risk exceptions to risk/compliance for approval.
risk_level: "Low"→Policy Owner Approvalrisk_level: "High"→Risk / Compliance ApprovalDefault→Risk / Compliance Approval - 6Policy Owner Approvalrequest approval
The policy owner reviews and approves or rejects the low-risk exception.
- 7Route Policy Owner Outcome
Branches based on the policy owner's approval decision.
approval_status: "approved"→Record Approved Exception & Set Review Expiryapproval_status: "rejected"→Record Rejected ExceptionDefault→End - 8Risk / Compliance Approvalrequest approval
Risk or compliance team reviews and approves or rejects the high-risk exception.
- 9Route Risk/Compliance Outcome
Branches based on the risk/compliance team's approval decision.
approval_status: "approved"→Record Approved Exception & Set Review Expiryapproval_status: "rejected"→Record Rejected ExceptionDefault→End - 10Record Approved Exception & Set Review Expiryupdate record
Marks the exception as approved and sets an expiry date based on the requested duration for future review.
- 11Set Exception Expiry Dateset due date
Sets the record's due date to the requested duration for scheduled review.
- 12Notify Requester: Approvedsend email
Emails the requester confirming the exception was approved, including its expiry review date.
- 13Record Rejected Exceptionupdate record
Marks the exception as rejected on the record.
- 14Notify Requester: Rejectedsend email
Emails the requester informing them the exception was rejected, with the reason, returning the request to them.
Fields
- Requester Name*
- Requester Email*
- Policy to Deviate From*
- Exception Requested*
- Business Justification*
- Scope of Exception*
- +5 more fields
Forms
Policy Exception Request Form
7 fields
Data Views
All Policy Exception Requests
policy_name, risk_level, exception_status, requested_duration_days +1 more
Dashboard Widgets
Recommended integrations
Setup the following integrations to extend workflow capability.
Send email in the workflow
AWS SES
Similar Workflows
Similar Categories
FAQs
How do I set up this workflow for my team?
Publish the template in assess.one and it's live immediately, no separate implementation project needed. You can then assign roles like requester, risk reviewer, policy owner, and compliance approver to the right people. The routing logic for low-risk versus high-risk exceptions is already built in, so you just need to confirm who sits in each approval role.
How long does it take to get this running?
Minutes. Once you publish the template, your team can start submitting exception requests straight away. There's no software to install or IT project to schedule, the workflow runs inside assess.one from the moment it's published.
Who needs access to this workflow?
At minimum you need requesters who submit exceptions, a risk reviewer who assesses compensating controls, and approvers for both policy owner and risk/compliance decisions. You can add or adjust these roles inside assess.one depending on how your organisation structures approvals.
Can I change the risk-level routing logic?
Yes. The routing between policy owner approval and risk/compliance approval is based on risk level, and you can adjust the thresholds or criteria directly in assess.one. You can also add extra approval steps if your organisation needs more than two tiers.
What happens if an exception is rejected?
The rejection is recorded along with a reason, and the requester is automatically notified. This keeps a clear record of why an exception didn't get approved, which is useful if the same request comes back later or if it's reviewed during an audit.
How does the expiry date work for approved exceptions?
When an exception is approved, the workflow records it and sets a review expiry date so it doesn't stay open indefinitely. This helps teams revisit exceptions periodically instead of letting them become permanent by default.
Can I customise the notifications sent to requesters?
Yes, notification content and timing can be configured inside assess.one for both approved and rejected outcomes. You can also add notifications to other stakeholders, like the policy owner or compliance team, at any step.
Does this workflow support compliance or audit requirements?
It's designed to help by keeping a record of the request, risk assessment, approver decisions, and expiry dates in one place. This supports audit readiness, though your organisation should still confirm the workflow aligns with your specific compliance obligations.
What if a high-risk exception needs additional scrutiny beyond the standard approvers?
You can add extra review steps or additional approvers to the risk/compliance approval stage directly in assess.one. This is useful if certain exception types need sign-off from a second compliance reviewer or a committee.
Ready to use this workflow?
Create a free account and customise this workflow for your business.
