Zum Hauptinhalt springen

Deliberately accepting residual risk: documenting exceptions traceably

Requirements that are deliberately not implemented can be documented in the ISMS Cockpit as a justified exception with an accepted residual risk. Such an exception is removed from the degree of fulfilment and counts neither as fulfilled nor as open. Time-limited exceptions automatically trigger a review on their expiry date, so that no exception remains in place unnoticed. For audits, it is advisable to record the approving person as well as compensating measures as conditions.

Last updated:

Some requirements are deliberately not implemented (in full) – for economic or technical reasons. Instead of leaving such a requirement open, you document a justified exception in the ISMS Cockpit and accept the remaining residual risk in a justified and traceable way.

Documenting an exception

  1. Open the risk acceptance: Open the relevant requirement and click "Edit" in the "Risk acceptance / exception" section. The "Risk acceptance (exception)" window opens.
  2. Document the exception: Fill in the fields: "Justification" (why the residual risk is deliberately accepted), "Approved by" (the person who approves the exception), "Valid until" (the expiry date – leave empty for an exception without a time limit) and optional "Conditions" or compensating measures. Click "Accept the risk".

Effect on the degree of fulfilment

A documented exception removes the requirement from the degree of fulfilment – it counts neither as fulfilled nor as open, but as "accepted". This way a deliberate decision does not distort your key figures.

Automatic follow-up

If you limit the exception in time, a review is created automatically on the expiry date. This is how the platform ensures that no exception remains in place permanently and unnoticed.

Tip: Under "Approved by", always record the person who is actually authorized to decide, and store compensating measures as conditions – both are typical audit checkpoints.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.

Related glossary terms