Risk And Control

Policy Exception Register

Track policy exceptions by severity, owner, mitigation, approval tier, aging, evidence, linked requirements, and UAT coverage.

Policy Exceptions

5

Portfolio sample

Pending Approval

2

Critical Severity

1

Average Aging

7 days

2 overdue

Exception Governance Filters

Review exceptions by approval status and severity to simulate risk and control oversight.

Exception Register

Each row is linked to BA requirements, UAT coverage, mitigation, approval authority, and evidence.

5 shown
ExceptionSeverityStatusOwnerAgingApproval TierEvidence
EXC001: Missing latest audited financial statement
Term Loan / Management accounts, bank statements, and tax return required as alternate evidence.
MajorPending ApprovalCredit Analyst6 daysCountry Credit CommitteeWaiver form, exception memo, approver decision, and audit timestamp.
EXC002: Unsecured exposure above standard threshold
Overdraft / Additional repayment capacity analysis and monthly conduct monitoring.
CriticalPending ApprovalApprover9 daysGroup Credit CommitteeException register, committee approval note, and route override history.
EXC003: High risk customer EDD pending
Trade Line / EDD checklist to be completed before submission to Credit Review.
MajorDraftRM3 daysCountry Credit CommitteeEDD checklist, screening result, and compliance review note.
EXC004: Corporate guarantee authority evidence incomplete
Bank Guarantee / Board resolution obtained with authorized signatory verification.
MinorApprovedCredit Admin2 daysRegional Credit ManagerBoard resolution, signatory evidence, and guarantee agreement.
EXC005: Trade facility product document mapping pending
Trade Line / Product owner to confirm final document mapping before next UAT cycle.
MinorExpiredSystem Admin14 daysRegional Credit ManagerProduct owner sign-off and updated checklist rule mapping.

Control Lens

Exceptions are not just notes. A strong banking workflow records severity, mitigation, approval authority, aging, evidence, and UAT coverage.

Release Gate

Critical or expired exceptions should be reviewed before production sign-off.
Pending approval exceptions should remain visible in dashboard and approval memo.
Each exception should map to at least one requirement and UAT test case.