Policy exceptions

  • Release version: Zurich
  • Updated July 16, 2026
  • 1 minute to read
  • Request an approved, time-bound deviation from a policy or control objective that applies to an AI asset.

    A policy exception documents why an AI asset can't currently meet a control objective and requests approval to operate outside that control for a defined period. Each exception includes a justification and a risk assessment that an approver reviews before the exception takes effect.

    Policy exception lifecycle

    An AI steward or asset owner creates a policy exception, identifies the policy or control objective it applies to, and documents the justification and risk assessment. The exception is valid only for the period defined by its Valid from and Valid to dates; a valid-to date is required to raise an exception.

    The exception moves into review, and the request routes to an approval group or approver. The approver approves or rejects the exception based on the documented justification and risk assessment, and an approved exception closes once its valid-to date passes.

    Where policy exceptions appear

    Policy exceptions appear on the Policy exceptions sub-tab of the Team, Assigned to you, Unassigned, and Submitted by you tabs in Activity Center, depending on assignment.