---
sourceDocument: Zurich Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/security-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Exception Management overview

# Exception Management overview {#ariaid-title1}

Release version: Zurich  
Updated July 31, 2025  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exception Management overview

Exception Management in ServiceNow Vulnerability Response allows organizations to formally request, review, approve, or reject exceptions when they cannot comply with a vulnerability management or security policy, standard, or guideline.
This applies to vulnerable items (VIs) or remediation tasks (RTs) that cannot be remediated as required.
Exception approval signifies acceptance of the associated risk due to deferral of remediation.
Show full answer Show less  
Starting with Vulnerability Response v30.0, the Exception Management UI is enhanced to provide approvers with better insights directly within Change Approval records and a new Approver landing page in the Security Exposure Management workspace. These improvements streamline the approval process by offering richer context and reducing manual effort.

## Life cycle and process

* **Definition:** An exception is a request to defer remediation of a VI or RT for a specified time, for example, when no patch is available.
* **Requesting an exception:** Remediation owners submit exception requests via the exception management process.
* **Approving exceptions:** Vulnerability analysts review requests and approve deferrals after assessing risk. There may be a two-level approval workflow; if no first-level approver exists, exceptions cannot be requested.
* **Post-approval actions:** Once approved, exceptions move the VI or RT to a Deferred state. Users can reopen, delete, or update assignment fields.
* **Tracking:** Exception request status is tracked via the State Change Approvals tab on VIs or RTs. Note that actions on RTs do not track individual VIs separately.
* **Expiry:** When an exception expires, the VI or RT reverts to Open state and must be remediated.

## Key features and changes

* Exception Rule State Approval workflow deprecated in favor of flow designer Exception Rule Approval starting v23.0.
* Flow designer enabled by default for new deployments starting v15.0; existing users can upgrade but cannot revert.
* Scheduled job tracks multiple deferrals, logging counts when VIs or RTs are deferred more than once.

## Practical implications for ServiceNow customers

This capability helps your organization manage unavoidable remediation delays while maintaining visibility and control over security risks. The enhanced UI and approval workflows provide approvers with the context needed to make timely, informed decisions. Tracking deferrals and expiries ensures exceptions are monitored and addressed appropriately to reduce long-term exposure.

To implement effectively, configure approval rules, add exception approvers as needed, and use the provided workspace modules to request and manage exceptions for both vulnerable items and remediation tasks.  
When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or
rejecting exceptions to a vulnerable item (VI) or remediation task (RT) that cannot be remediated according to the policy.  
Note:  
Starting with v30.0 of Vulnerability Response, the Exception Management UI has been enhanced to provide improved insights directly within the Change Approval record, enabling approvers to quickly make informed decisions without navigating to related records. Additionally, an Approver landing page has been introduced within the Security Exposure Management workspace for all findings that introduces an improved table view with additional columns, offering better visibility and context. Together, these enhancements streamline the approval workflow, reduce manual effort, and accelerate decision-making for exception requests. For more information, see [Exception Management Overview](https://www.servicenow.com/docs/KEjCgxBBhqiiGO7OrtdKoQ "When your organization can't comply with a published finding or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions to a finding or remediation task (RT) that can’t be remediated.") , [Unified Approvals View](https://www.servicenow.com/docs/bD7U5eCDgA5RAQfdy4Ia1w "The approval process in Security Exposure Management for vulnerability and compliance exceptions is unified to simplify workflows, improve visibility, and streamline actions for Approvers.")Some vulnerabilities might not have an existing patch, fix, or solution. When an exception is approved, it also means that you're accepting a risk because you're acknowledging and agreeing to the consequences of not remediating the vulnerability.

## Life cycle of an exception {#vr-exception-management__section_ems_dy3_flb}

Definition of an exception
:   An exception is a request to defer the remediation of a VI or RT for a specified period. For example, as a remediation owner, you can request an exception if a patch is not available for a machine.

Requesting an exception
:   As the remediation owner, you can ask for an exemption for a VI or RT using the exception management process. After the exception approver approves this request, the VI or RT moves to a Deferred
    state.

Approving an exception request
:   VIs or RTs that can't be remediated immediately are reviewed by vulnerability analysts, assessed for risk, and approved for deferral until they can be remediated. Approving an exception request can be a two-level
workflow. If only the first-level approver is present, the exception can be requested and approved. However, if there's no first-level approver, an exception can't be requested. See [Add an exception approver](https://www.servicenow.com/docs/Wado0iZ99aASC4vcQSfqcw "Add users to the approver groups so that you can request an exception.") for more information.  
Note:  
* Starting from Vulnerability Response v15.0, if you are deploying the VR application for the first time, the flow designer for exception management is enabled by default. If you are already using the workflow, you can update
  to the flow designer. In both cases, you cannot change it back to workflow. To configure approval rules for exception management and false positive, see [Configure approval rules for Exception Management](https://www.servicenow.com/docs/vE8_540YbrjJlaXAW8XmSQ "Starting with Vulnerability Response v15.0, use the flow designer to approve exception requests for exception management, exception rules, and false positive management. If you are deploying Vulnerability Response (VR) for the first time, the flow designer is enabled by default.").

  Once an exception request for a VI or RT is approved, you can perform the following actions:
  * Reopen
  * Delete
  * Update the Assignment to or Assignment groups fields
  {#vr-exception-management__ul_h32_y22_4lb}
* Starting with v23.0 of Vulnerability Response, the Exception Rule State Approval workflow is deprecated and replaced by the flow Exception Rule Approval in the flow designer.
{#vr-exception-management__ul_sff_qhl_dcc}

Tracking an exception request
:   After raising the exception, you can track its status by using the State Change Approvals tab of the VI or RT. If an action is taken on an RT, you can't track the status of the individual VIs in
    that RT.

Expiry of an exception request
:   When an exception request for a particular VI or RT expires, the impacted VI or RT reverts to its Open state.
Figure 1. Exception management approval process prior to VR v15.0

If a single VI or all the VIs in a RT pass in the next scan, then the VIs and, where applicable, the RT State field changes to Closed with the substate
Fixed.

## Multiple deferrals {#vr-exception-management__section_kgk_vkw_h5b}

Track the number of times a record or a remediation task is deferred. A scheduled job, set deferral counts, runs daily to post counts for the records that are deferred more than once in the Deferral count column in the Multiple deferrals module for VR. All counts for records associated with a remediation task are collected and posted if a remediation task is deferred more than one time.
**Related concepts**   

* [Request exceptions for remediation tasks and records in the Vulnerability Manager Workspace](https://www.servicenow.com/docs/RWADeXpJ2MQIM5_P5dl2Ww "From the Vulnerability Manager Workspace, vulnerability managers and analysts can request exceptions and false positives for a remediation task (VUL, AVUL, CVUL or CRG) and record (VIT, CVIT, AVIT or CTR). You can also split a remediation task and create change requests.")  
**Related tasks**   

* [Request an exception in the IT Remediation Workspace](https://www.servicenow.com/docs/Bq~M4ujrH9jPsjST2wozyw "Request an exception for the host vulnerable item (VIT), application vulnerable item (AVIT), container vulnerable item (CVIT) and remediation task (VUL, AVUL, CVUL, or CRG) from the IT Remediation Workspace.")
* [Request an exception using GRC: Policy and Compliance Management in the IT Remediation Workspace](https://www.servicenow.com/docs/6ghm8TRRB1TbG3o5bE~RdQ "Request a policy exception for the host vulnerable item (VIT), application vulnerable item (AVIT), container vulnerable item (CVIT) or remediation task (VUL, AVUL, CVUL, or CRG) from the IT Remediation Workspace.")

