Time-Boxed Waiver
An approved deviation from a standard that carries an owner, a justification, a compensating control and an expiry date after which it is reconsidered.
Standards meet reality and lose sometimes: a legacy system cannot support the required authentication, a vendor product does not permit the logging, a deadline does not allow the migration. Refusing to grant exceptions produces either a stalled delivery or an undocumented deviation, and the second is worse because nobody knows about it.
A waiver makes the deviation visible and bounded. It records what standard is not being met, why, what compensating control reduces the residual risk, who owns remediation, and when it expires.
The expiry is what distinguishes a waiver from a silent permanent exception. On expiry the deviation is either remediated or explicitly renewed with a fresh justification — which is a small friction that reliably prevents the accumulation of forgotten exceptions.
Two properties keep the register healthy. It is reviewed in aggregate, because twenty waivers of the same standard means the standard is wrong rather than that twenty teams are non-compliant. And the count and age are reported, since a register that only grows is evidence that the process has become a way of recording defeat rather than managing it.