Skip to main content
The state of ai impact assessment
Should Second Line Own Exception Approval?Policy Management
5 min readFor Compliance Officers

Should Second Line Own Exception Approval?

The Question at Hand

Most GRC teams agree that policy exceptions need formal approval. The debate begins when you ask who should grant it.

On one side: let business units approve their own exceptions, with second-line oversight after the fact. This keeps decisions close to operations and prevents bottlenecks. On the other: route all exceptions through the second line for upfront approval, ensuring independent review before the risk is taken.

This choice matters because it affects whether your exception process produces audit evidence or audit findings. A Approved Exception is a documented decision to allow a specific activity to proceed outside a Policy Standard, for a defined period, with a named owner and an assessed level of residual risk. The approval structure you choose shapes whether that documentation holds up under examination.

The Case for First-Line Approval

Business units understand the operational context better than anyone in the second line. They know why the vendor contract signed in 2019 predates the information security standard written in 2024, and they can assess whether the gap creates material exposure or administrative friction.

Speed is another argument. Route every exception through a centralized approval queue and you'll watch urgent business decisions pile up behind administrative reviews. Credit officers need to move on loan policy exceptions. Information security teams need to document risk acceptances without waiting weeks for committee review. Vendor management needs to handle contractual deviations from standard terms within the negotiation window.

First-line approval also creates accountability. When the business unit head signs off on the exception, they own the residual risk. That ownership drives better compensating controls and more realistic expiry dates than a second-line reviewer working from a form submission.

A practical version of this model puts guardrails around self-approval: business units can approve low-risk administrative departures, with escalation thresholds that route moderate and high-residual-risk exceptions upward. A department head approving a low-risk exception, the second line approving moderate exceptions, and an executive risk committee approving high-residual-risk exceptions creates a defensible ladder without creating a single point of bottleneck.

The Case for Second-Line Approval

Self-approval is the weak point internal audit designs tests around. Any process where the requester can approve their own exception hands auditors an obvious finding, and adding a reporting relationship between the requester and the approver doesn't fix the independence problem.

The second line exists to challenge business justifications before risk is taken, not to document what happened after the fact. Upfront approval forces the requesting unit to articulate the compensating control, assess the residual risk, and set a realistic expiry date while the decision is still reversible. Post-approval oversight catches problems after they're already embedded in operations.

Regulatory expectations point toward independent review. The OCC Comptroller's Handbook on corporate and risk governance states that the board should approve risk limits for specific policies and monitor those limits periodically. When exceptions to a particular policy are approaching or breaching risk limits, the handbook directs the board to take appropriate action. That monitoring requirement assumes someone other than the business unit is tracking the aggregate exposure.

Consistency is another argument. Business units operating under different approval standards create institution-wide blind spots. Credit has loan policy exceptions tracked in one system, information security has risk acceptances in another, vendor management has contractual deviations in a spreadsheet. Centralized approval through the second line creates a single register that can answer the examiner question about how many open exceptions the institution carries.

The residual risk rating drives the approval level, which means an unrated exception can't be routed correctly. Second-line review ensures that rating happens before approval, not as a box-checking exercise afterward.

Where Practitioners Actually Land

Most institutions run a hybrid model. Low-risk administrative exceptions stay with the first line, subject to notification and periodic sampling by the second line. Anything above that threshold routes through formal second-line approval.

The dividing line usually sits at the residual risk rating. If the compensating control brings residual risk below the threshold that triggers escalation, the business unit can approve. If residual risk remains moderate or high, the second line assesses the justification and either approves, requires additional mitigation, or escalates to the risk committee.

The three-lines model maps cleanly onto this structure: the first line requests and owns the compensating control, the second line assesses the risk and challenges the justification, and the third line tests whether the process operated as designed and samples individual records for adequacy.

Technology makes the hybrid work. A complete exception record carries the requesting business unit and named requester, the exact policy clause being departed from, the business reason, the assessed inherent risk, the compensating control and its owner, the residual risk rating after that control, the approver and the authority under which they approved, the effective date, the expiry date, and the monitoring evidence collected during the exception period. Workflow automation routes that record to the right approver based on the risk rating, without requiring manual triage.

Our Take

Second-line approval should be the default for anything beyond administrative housekeeping. The independence argument outweighs the speed argument, and the regulatory expectation is clear enough that designing around it creates more risk than it removes.

That said, the approval authority should follow residual risk, not policy category. A low-risk departure from a high-profile policy still carries low residual risk. A high-risk departure from an administrative standard still needs executive review. Build the routing logic around the risk rating, and you'll avoid both bottlenecks and independence gaps.

The harder discipline is what happens after approval. A compensating control described in a request and never tested is an assertion. Build a test schedule into the exception record, automate escalation when expiry dates pass, and report aggregate exception counts to the board quarterly. That's where most institutions fail, not in the initial approval decision.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like