Your exception register has grown from 12 to 90 waivers in eighteen months and none have been closed. What does this tell you and what do you do?
Show the full answer Hide the answer
What it tells you
A register that only grows is recording defeat rather than managing deviation. Three things are true and they need separating:
Some standards are wrong. Group the ninety by which standard they deviate from. Where twenty waivers cite one standard, the standard does not fit the estate and fixing it closes twenty exceptions at once. That is the fastest reduction available and it should be done first.
Some waivers have no owner in practice. Named at creation, the owner has moved on, and nothing brings it back to anyone's attention. Expiry dates that pass without consequence are the mechanism failing.
Some are permanent. A legacy system that cannot support modern authentication and will be decommissioned in three years does not need reviewing every quarter. It needs recognising as an accepted risk with a compensating control and a decommissioning date, moved to the risk register rather than the waiver register.
The clean-up
Triage into: standard is wrong (fix the standard), remediable (owner and date, enforced), and permanently accepted (move to the risk register with a compensating control and a review tied to the decommissioning plan).
Expect the ninety to reduce substantially without anyone remediating anything, which is the point.
Then make expiry real
On expiry, the deviation is either remediated or explicitly renewed with fresh justification and a fresh approval. That small friction is what prevents accumulation, and it only works if something enforces it — a scheduled review with the owner's manager copied, rather than a date in a field.
The reporting that keeps it healthy
Count and age, trended, to whoever owns the standards. A register growing faster than it closes is a governance signal, and it is more useful to a risk committee than the individual waivers.
The principle
An exception route is necessary — a standard with no exception path gets ignored rather than debated. What makes it a control rather than a formality is that the exceptions are bounded, owned and visible in aggregate.