ComplianceCustomize Compliance

Customize Compliance

Tailor Mondoo's compliance assessment to your audit by setting scope, defining exceptions, and adjusting the approval workflow.

Every audit is different. Mondoo lets you customize which controls and checks factor into your compliance score, so the data you show your auditor reflects what you've actually agreed to be assessed on.

You have three levers:

LeverWhat it doesWhen to use it
Define scopeRemoves a control from your score and from generated reports.Your auditor has confirmed a control is not applicable to your organization.
Exception on a controlRemoves a control from your score but keeps it in reports with your justification.You want auditor visibility into why a control is excluded.
Exception on a checkExcludes a single check while the rest of the control stays active.Most of a control applies, but one specific check doesn't.

The four exception types

Both control and check exceptions use the same four types as security findings:

Exception typeWhat happensWhen to use it
Risk AcceptedControl or check is excluded from the scoreYou know about the gap and plan to fix it later.
WorkaroundControl or check is excluded from the scoreA compensating control is in place that mitigates the need to address this directly.
False PositiveControl or check is excluded from the scoreThe finding is inaccurate or doesn't apply to your environment.
DisableControl or check is excluded permanentlyThe control or check is causing stability or performance impact and you want to skip it.

Space-level exception settings

Each space has three settings that shape how exceptions behave. By default, new exceptions need a reviewer's approval before they apply.

SettingDefaultWhat changes when toggled
Require exception approvalsOnWhen on, new exceptions start in a pending state and don't apply until a reviewer approves them. When off, exceptions apply as soon as they're created.
Allow non-expiring exceptionsOnWhen off, every exception must have an expiration date.
Allow users to approve their own exceptionsOffWhen on, the user who creates an exception can also approve it, as long as they have a role that can review exceptions. By default, a different team member must approve.

Spaces created before mid-2025 may have Require exception approvals off. Check your space's value in Settings > General.

The approval history gives you a clear audit trail regardless of which settings you choose. These settings apply to both compliance and security exceptions.

Only team members who can review exceptions can approve or reject them: members with the Owner, Exception Reviewer, or Exception Manager role. The Editor role can create exceptions but can't review them. To learn more about these roles, read Manage Team Members.

See also

For how individual findings contribute to risk and how scoring works under the hood, read How Mondoo Scores and Prioritizes Findings.

On this page