---
sourceDocument: Zurich Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/governance-risk-compliance

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Assess risk for a policy exception

# Assess risk for a policy exception {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

After the review of a policy exception request and before deciding to approve or
reject a request, the compliance manager may choose to request a risk assessment by the risk
manager.

## Before you begin

Role required: compliance manager

## About this task

For more information, see [Manage policy exceptions and extensions](https://www.servicenow.com/docs/6Kzwof7zKiyZZflQJUrQuw "Policy exceptions and extensions provide temporary relief for non-compliant controls.").

## Procedure

1. Navigate to AllPolicy and ComplianceMy Policy Exceptions.
2. Select the policy exception.
3. Review the form details, as necessary.
4. Click the Business Impact Analysis tab and update the following fields:  
   {#assess-the-risk-on-policy-exception__table_epy_qrq_f5__entry__2}

   | Field | Value |
   |-|-|
   | Risk description | Description of the risk. |
   | Residual likelihood | Likelihood of the risk occurring. If it is not None, select the likelihood of this risk occurring: * 5 --- Extremely Likely * 4 --- Likely * 3 --- Neutral * 2 --- Unlikely * 1 --- Extremely Unlikely |
   | Residual impact | Residual impact of the risk. If it is not None, select the residual impact of this risk: * 5 --- Very High * 4 --- High * 3 --- Moderate * 2 --- Low * 1 --- Very Low |
   | Residual score | Value calculated after you select a residual likelihood and residual impact rating: * 5 --- Very High * 4 --- High * 3 --- Moderate * 2 --- Low * 1 --- Very Low {#assess-the-risk-on-policy-exception__ul_pkr_xkq_xhb} |
   [Table 1. Policy exception request Business Impact Analysis tab]

   {#assess-the-risk-on-policy-exception__table_epy_qrq_f5}
5. Perform one of the following actions.

   | Option | Action |
   | To view or add impacted controls to the policy exception | 1. Click the Impacted Controls tab. 2. Click Add or Add All. 3. Choose the controls to associate to the policy exception. {#assess-the-risk-on-policy-exception__ol_mbz_zrc_jbb} |
   | To view mitigating controls on the policy exception | Click the Mitigating Controls tab. |
   | To view or add risks to the policy exception | Click the Risks tab. Note: This option is available when Governance, Risk, and Compliance is also activated. |
   | To view or add approvers to the policy exception | Click the Approvers tab. |
   | To view or add task service level agreements to the policy exception | Click the Task SLAs tab. |
   |-|-|

   {#assess-the-risk-on-policy-exception__choicetable_qjq_2vw_x1b}
6. Click Update.
{#assess-the-risk-on-policy-exception__steps_gs2_v5w_x1b}

*[\>]: and then


