assess.one – AI-powered business operations platform

Workflow Template

Policy Exception Request Workflow

Enables a requester to submit a policy exception request. A risk reviewer assesses the exception and compensating controls, then routes the request based on risk level: low-risk exceptions go to the policy owner for approval, high-risk exceptions require risk/compliance approval. Approved exceptions are recorded with an expiry date for review; rejected requests are returned to the requester with a reason. The requester is notified of the final decision.

Policy exceptions often get approved in email threads with no record of who signed off, what controls were checked, or when the exception expires. This workflow gives requesters a structured way to submit exceptions, routes them to the right approver based on risk level, and records the decision with an expiry date for future review. Risk reviewers, policy owners, and compliance teams each get their part of the process without chasing status updates.

Business Outcomes

  • Supports faster turnaround on exception requests with clear routing rules
  • Helps reduce exceptions that get approved without proper risk review
  • Makes it easier to track expiry dates and flag exceptions for renewal or closure
  • Improves visibility into who approved what and why, for audit purposes
  • Reduces back-and-forth by capturing rejection reasons in one place

Workflow Steps

Steps

  1. 1
    Create Exception Request Recordcreate record

    Registers the submitted policy exception request as a record.

  2. 2
    Set Status: Submittedupdate record

    Marks the request as submitted before risk review begins.

  3. 3
    Risk Review Assessmentcreate task

    A risk reviewer assesses the exception, compensating controls, and assigns a risk level.

  4. 4
    Set Status: Under Risk Review Completeupdate record

    Persists the risk assessment outcome and marks the request pending approval.

  5. 5
    Route Approval by Risk Level

    Routes low-risk exceptions to the policy owner and high-risk exceptions to risk/compliance for approval.

    risk_level: "Low"Policy Owner Approval
    risk_level: "High"Risk / Compliance Approval
    DefaultRisk / Compliance Approval
  6. 6
    Policy Owner Approvalrequest approval

    The policy owner reviews and approves or rejects the low-risk exception.

  7. 7
    Route Policy Owner Outcome

    Branches based on the policy owner's approval decision.

    approval_status: "approved"Record Approved Exception & Set Review Expiry
    approval_status: "rejected"Record Rejected Exception
    DefaultEnd
  8. 8
    Risk / Compliance Approvalrequest approval

    Risk or compliance team reviews and approves or rejects the high-risk exception.

  9. 9
    Route Risk/Compliance Outcome

    Branches based on the risk/compliance team's approval decision.

    approval_status: "approved"Record Approved Exception & Set Review Expiry
    approval_status: "rejected"Record Rejected Exception
    DefaultEnd
  10. 10
    Record Approved Exception & Set Review Expiryupdate record

    Marks the exception as approved and sets an expiry date based on the requested duration for future review.

  11. 11
    Set Exception Expiry Dateset due date

    Sets the record's due date to the requested duration for scheduled review.

  12. 12
    Notify Requester: Approvedsend email

    Emails the requester confirming the exception was approved, including its expiry review date.

  13. 13
    Record Rejected Exceptionupdate record

    Marks the exception as rejected on the record.

  14. 14
    Notify Requester: Rejectedsend email

    Emails the requester informing them the exception was rejected, with the reason, returning the request to them.

Fields

  • Requester Name*
  • Requester Email*
  • Policy to Deviate From*
  • Exception Requested*
  • Business Justification*
  • Scope of Exception*
  • +5 more fields

Forms

Policy Exception Request Form

7 fields

Data Views

All Policy Exception Requests

policy_name, risk_level, exception_status, requested_duration_days +1 more

Dashboard Widgets

Exceptions by StatusException Request PipelineException Request Summary

Recommended integrations

Setup the following integrations to extend workflow capability.

  • Send email in the workflow

    AWS SES logoAWS SES
policy exceptionpolicy waiverexception requestrisk acceptancecompliance exception

Similar Workflows

Similar Categories

FAQs

How do I set up this workflow for my team?

Publish the template in assess.one and it's live immediately, no separate implementation project needed. You can then assign roles like requester, risk reviewer, policy owner, and compliance approver to the right people. The routing logic for low-risk versus high-risk exceptions is already built in, so you just need to confirm who sits in each approval role.

How long does it take to get this running?

Minutes. Once you publish the template, your team can start submitting exception requests straight away. There's no software to install or IT project to schedule, the workflow runs inside assess.one from the moment it's published.

Who needs access to this workflow?

At minimum you need requesters who submit exceptions, a risk reviewer who assesses compensating controls, and approvers for both policy owner and risk/compliance decisions. You can add or adjust these roles inside assess.one depending on how your organisation structures approvals.

Can I change the risk-level routing logic?

Yes. The routing between policy owner approval and risk/compliance approval is based on risk level, and you can adjust the thresholds or criteria directly in assess.one. You can also add extra approval steps if your organisation needs more than two tiers.

What happens if an exception is rejected?

The rejection is recorded along with a reason, and the requester is automatically notified. This keeps a clear record of why an exception didn't get approved, which is useful if the same request comes back later or if it's reviewed during an audit.

How does the expiry date work for approved exceptions?

When an exception is approved, the workflow records it and sets a review expiry date so it doesn't stay open indefinitely. This helps teams revisit exceptions periodically instead of letting them become permanent by default.

Can I customise the notifications sent to requesters?

Yes, notification content and timing can be configured inside assess.one for both approved and rejected outcomes. You can also add notifications to other stakeholders, like the policy owner or compliance team, at any step.

Does this workflow support compliance or audit requirements?

It's designed to help by keeping a record of the request, risk assessment, approver decisions, and expiry dates in one place. This supports audit readiness, though your organisation should still confirm the workflow aligns with your specific compliance obligations.

What if a high-risk exception needs additional scrutiny beyond the standard approvers?

You can add extra review steps or additional approvers to the risk/compliance approval stage directly in assess.one. This is useful if certain exception types need sign-off from a second compliance reviewer or a committee.

Ready to use this workflow?

Create a free account and customise this workflow for your business.

Policy Exception Request Workflow | assess.one