Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create a policy exception from Employee Center

Use the Employee Center to request exceptions for policies, control objectives, controls, or issues by specifying the reason of exception on a particular list of the systems, applications, networks, or entities for which the exception applies.

Before you begin

Role required: sn_grc.business_user, sn_grc.business_user_lite, sn_grc_emp_user.grc_employee

Procedure

  1. Navigate to Self-Service > Employee Center.

  2. From Help Center, select Risk and compliance.

  3. Select the Policy Exception catalog item.

  4. On the form, fill in the fields.

FieldDescription
What is the exception for?Type of policy exception that you want to create. The options are:- Policy: Create a policy exception based on a policy. - Control objective: Default is a single control objective on which the policy exception is created. - Controls: Option to create a policy exception on multiple controls. - Issue: Option to create a policy exception on an issue.
PolicyPolicy associated with this policy exception.
Control objectiveControl objective associated with this policy exception.When you select a control objective, theImpacted controls field appears.
ControlSelect Control to associate multiple controls from different control objectives. This option supports multiple controls objectives for your policy exception, instead of creating multiple policy exceptions that could be applied on multiple controls.
IssueIssue associated with this policy exception.
Impacted controlsControls associated to the control objective.
Short descriptionBrief description about the policy exception request.
DescriptionDetailed description of the policy exception request.
ReasonReason for the exception
JustificationEvidence or rationale for the policy exception.
Risk descriptionDescription of the risk as performed by the risk manager during risk assessment.
Valid fromDay on which the policy exception begins.
Valid toDay on which the policy exception ends.
PriorityApproval priority of this policy exception.
Watch listUsers that are notified when the request is updated.
  1. Click Submit.

    You are directed to the My Request page where you can view your policy exception number for the submitted policy exception request. This page is read-only and you can view all your requests that you have raised as a business user.

  2. Post a message to support the policy exception in the Activity field.

  3. To attach a document related to the policy exception, select the Attachments tab.

  4. Click My Requests link at the top right corner to view a list of all your requests that includes your issues and policy exceptions.

    The list shows 15 requests at a time. Click Show More Requests for more requests to be listed.

  5. Select Request Approval from the Actions list if the request is in Analyze state.

    If you raise a policy exception from Employee Center and if verification rules are not configured, then the policy exception moves to the Analyze state. However, if verification rules are configured for the policy exception, then the policy exception moves to the New state and the verification approval process is triggered. As verification rules are configured, the approver is required to verify the policy exception and approve it, only then the policy exception moves to Analyze state.

  6. After the policy exception is approved, you can request extension of your policy exception, select Request extension from the Actions list.

    1. Enter the new extension date that is later than the current Valid to date.

      By default, you cannot extend your policy for more than 30 days from the Valid from date. However, the extension can be relaxed based on the maximum exception duration days of the policy.

    2. Select a reason for extension from the list in the Extension reason field.

    3. Enter a justification for the extension.

    4. Click Request.

      The number of remaining extensions that you can avail to request is displayed as Remaining extensions.