Exception Governance.
Not every finding gets remediated on the original timeline. Navigator treats an accepted risk as a governed decision in its own right, not a gap in the data.
Exceptions are raised against a specific finding, not a general asset, so each one carries the exact context of what it excuses.
Each entry carries the finding and its severity, the affected asset, the reasoning recorded at approval, and its expiry state.
An accepted risk is a governed decision, not a gap in the data.
Programmes rarely close every finding on schedule. When a finding cannot be remediated in time, Navigator does not leave it as an open item with no owner and no record — it lets the organisation raise an exception against that specific finding.
Because the exception is tied to the finding it excuses, rather than to the asset in general, it carries the exact context of what was accepted, why, and by whom — instead of a broad waiver that quietly covers whatever the asset does next.
Approval is enforced by the platform, not just the interface.
A person whose role is not on the approver list is refused at the API level, not just hidden from a menu. And if the approval policy itself cannot be read, the default is that nobody is approved — not everybody.
Approver roles, maximum duration and evidence requirements are configured per organisation, so the policy reflects how your governance team actually wants exceptions handled.
What closes an exception depends on what it is excusing.
A missing owner, for example, can close with a plain resolution.
A weak cryptography finding needs either validating evidence or a named approver and a written reason.
The same evidence-or-exception mechanism used everywhere else in Navigator applies here too.
A stable address, built to be linked from a report or audit pack.
A dedicated exception register carries three headline counts — active, expiring within thirty days, and lapsed — with each entry showing:
- The finding and its severity
- The asset it applies to
- The reasoning recorded at approval
- Its current expiry state
The register reads live: once the finding underneath an exception is remediated, the entry clears on its own.
“Making it configurable would let an organisation quietly widen its own definition of urgent.”
A lapsed exception is not silently reversed. It stays on record as lapsed, with the original approver and reason still attached, until someone renews it, escalates it, or records that remediation has started.
Navigator records and surfaces these decisions. It does not certify that any of them meets a regulatory threshold — that judgement stays with your governance team.
Govern accepted risk with the same rigour as remediation.
Request a Navigator demo to see how exception governance fits alongside your existing programme.
