Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Request exception form for risk reduction

The following table shows the fields that you must fill on the Request exception form for risk reduction requests.

FieldDescription
ReasonReason for your exception request. Select Mitigating Control in Place for risk reduction request.To see how to add new reason choices, see Define policy reason mapping.
Request for DeferralDeffer the record. This field is selected by default.Note: This field appears only when the Mitigating Control in Place option is selected in the Reason field.
Request for Risk ReductionEnables you to request for the risk score reduction.Note: This check box appears only when the Mitigating Control in Place option is selected in the Reason field.
Current Risk RatingCurrent severity of the risk.Note: This field appears only when the Request for Risk Reduction check box is selected.
Desired Risk Rating

New risk rating that you want to assign to the record.The highest risk score in this risk rating range is applied to the record when your request is approved.

Note: This field appears only when the Request for Risk Reduction check box is selected.

Select Compensating ControlsReason for your request to reduce the risk rating.
UntilDate on which the deferral or risk reduction request expires.When the exception request expires: - The record reverts to the Open state. - The compensating controls expire. - The calculated score will be in place of a reduced score.
Justification notesDetails that are related to the reason why this request is being made.

Related topics

Request risk reduction for a vulnerable item or remediation task