ComplianceCustomize Compliance

Set Exceptions on Checks

Add, approve, reject, and remove exceptions on individual checks within a compliance control.

Check exceptions let you exclude one check from your compliance score while keeping the rest of the control active. Use them when a control mostly applies to your organization but one specific check doesn't.

For the four exception types and the space-level settings that affect approval, read Customize Compliance.

A check exception applies to the entire space. Because checks live in policies, excepting a check affects every compliance framework that uses it, not just the one you're viewing.

Set an exception on a check

Only team members with Editor or Owner access can perform this task.
  1. From a space, select Compliance in the side navigation, then select the framework. Scroll to the list of controls.

    Controls in a compliance framework

  2. Select the control containing the check, then check the box beside that check.

    Select a check in a compliance control

  3. Select SET EXCEPTION.

    Set an exception on a compliance check

  4. Choose the exception type and time period, write a justification, then select SAVE EXCEPTION.

Approve or reject an exception

An exception's approval flow depends on your space's exception settings. By default, an exception takes effect when it's created and a different team member approves or rejects it as an audit step. Approving keeps the exception. Rejecting removes it and re-enables the check.

Only team members with Editor or Owner access can perform this task.
  1. From the framework's controls list, select the control containing the excepted check, then switch to the Exceptions tab.

    Exception on a check in the Mondoo App

  2. Select Approve to keep the exception or Reject to remove it.

Re-enable a check

Only team members with Editor or Owner access can perform this task.
  1. From the framework, select the control containing the check.

    Compliance framework showing checks with an exception

  2. Select the check with the exception.

    Compliance check with an exception

  3. Select REMOVE EXCEPTION AND ENABLE, then confirm with YES, ENABLE THE CHECK.

On this page