Skip to main content
Category: Policy Management

Policy Deviation

Also known as: Compliance Deviation, SOP Deviation
Simply put

A policy deviation is any instance where an activity, transaction, control, or operational practice departs from what an organization's established policies, procedures, or standards require. It represents a gap between how something was actually done and how the governing rules say it should be done. Organizations typically document such deviations so they can be reviewed, justified where appropriate, and addressed.

Formal definition

A policy deviation is a departure of an activity, transaction, control, or operational practice from established internal policies, procedures, standards, or defined protocols. It is commonly distinguished from broader compliance deviation, which may also encompass divergence from external regulatory requirements; a policy deviation refers specifically to a departure from internally established rules, though the two overlap where internal policy operationalizes external obligations. Deviations are typically identified, documented (for example via a policy deviation form), and subjected to a management or review process that may assess justification, risk, and corrective action. This entry addresses the concept generally and does not cover jurisdiction- or sector-specific handling requirements, tooling, or implementation specifics, which vary by organization and regulatory context.

Why it matters

Policy deviations matter because they represent the practical gap between an organization's stated rules and its actual conduct. Where internal policies operationalize external regulatory obligations, an unaddressed deviation can expose the organization to compliance failures, control breakdowns, and heightened risk against its objectives. Documenting deviations allows management to distinguish between one-off exceptions that carry acceptable risk and recurring patterns that may signal a policy is unworkable, poorly communicated, or being systematically circumvented.

Beyond the immediate compliance question, the way an organization handles deviations reflects the maturity of its governance and control environment. A structured process for capturing, reviewing, and justifying deviations provides an evidence trail that assurance functions can examine, and it supports informed decisions about whether to accept, remediate, or escalate a given departure. Conversely, deviations that go unrecorded deprive the organization of visibility into where its actual practice diverges from its intended controls.

It is worth noting that a documented deviation is not inherently a violation; in many settings a deviation may be justified after review, while in others it may require corrective action. The distinction, and the handling requirements that follow, depend on the applicable policy, jurisdiction, and sector, which vary considerably.

Who it's relevant to

Compliance officers
Compliance officers rely on deviation records to monitor where actual practice departs from internal policy, particularly where that policy operationalizes external regulatory obligations. Recurring or unjustified deviations may indicate compliance exposure or a need to revise policy, communication, or training.
Risk managers
Risk managers use deviation information to assess the risk associated with departures from established controls and procedures, informing decisions about whether a given deviation should be accepted, remediated, or escalated in line with the organization's risk appetite.
Internal auditors
As an assurance function, internal audit examines whether deviations are being identified, documented, and handled in accordance with the organization's own processes. Auditors evaluate the deviation process itself rather than managing the deviations, preserving their independence from the activities under review.
Governance and policy owners
Those responsible for setting and maintaining policies and standards use patterns in deviations to judge whether a rule is workable, clearly understood, and consistently applied, and to determine when a policy warrants revision.
Operational and process managers
First-line managers who own the activities and controls are commonly responsible for identifying deviations, documenting them, and providing justification or corrective action, since their operations are where departures from policy occur in practice.

Inside Policy Deviation

Deviation Description
A clear statement of the specific policy provision, standard, or procedure that was not followed, identifying the affected requirement and the nature of the departure from it.
Scope and Duration
The boundaries of the deviation, including the processes, systems, business units, or activities affected and whether the departure is a one-time exception or applies for a defined period.
Justification or Rationale
The documented business or operational reasoning for the deviation, which supports the assessment of whether the departure is acceptable within the organization's risk appetite and tolerance.
Risk Assessment
An evaluation of the risk introduced or increased by not adhering to the policy, distinguishing the inherent risk of the deviation from any residual risk after compensating measures are applied.
Compensating Controls
Alternative measures put in place to mitigate the risk arising from the deviation when the standard control is not applied. These are management activities and are distinct from the assurance functions that later review them.
Approval and Authorization
The record of who reviewed and authorized the deviation, reflecting the governance decision rights that determine who may accept the associated risk on behalf of the organization.
Expiry and Review Conditions
The date or conditions under which the deviation is reassessed, renewed, or closed, so that departures are not treated as permanent without periodic reconsideration.

Common questions

Answers to the questions practitioners most commonly ask about Policy Deviation.

Is a policy deviation the same as a compliance violation?
Not necessarily. A policy deviation is a departure from an organization's internally defined policy, standard, or procedure. A compliance violation typically refers to a breach of an external law or regulation. While some deviations may also constitute compliance violations where the internal policy implements a legal obligation, many deviations concern internal requirements that exceed or are independent of external mandates. The two concepts should be distinguished because they can carry different escalation, reporting, and remediation implications, and treating every deviation as a regulatory breach can distort risk reporting.
Does an approved exception mean the deviation no longer represents risk?
No. Formally granting an exception or waiver documents and authorizes a departure from policy, but it does not eliminate the underlying risk that the policy was designed to address. An approved exception typically means the organization has accepted, and in many cases compensated for through additional controls, the residual risk associated with the deviation. The distinction matters because exceptions should generally be time-bound, subject to review, and reflected in risk reporting rather than treated as closing the matter.
How should a policy deviation typically be documented?
Practices vary by organization, but documentation commonly captures the specific policy or provision departed from, the business reason, the scope and duration, the residual risk assessed, any compensating controls, and the approving authority. Maintaining this record supports auditability and allows assurance functions to evaluate whether deviations are being managed consistently. This entry does not prescribe specific tooling or templates, which depend on organizational context.
Who typically has authority to approve a policy deviation?
Approval authority generally depends on the significance of the deviation and the organization's delegation-of-authority structure. Lower-risk deviations may be approved at management level within the first line, while deviations affecting material risks or regulated requirements are often escalated to the second line, senior management, or a governance committee. The appropriate approver commonly corresponds to the level accountable for accepting the associated residual risk. Specific authority levels are organization-defined.
How do deviations relate to the three lines model?
In many organizations applying the IIA's three lines model, the first line identifies, requests, and operates under deviations as part of managing its activities; the second line, such as risk or compliance functions, may set the deviation process, advise on risk acceptance, and monitor aggregate deviations; and the third line, internal audit, independently evaluates whether the deviation process is designed and operating effectively. Assurance functions assess the process rather than authorizing deviations, preserving their independence and objectivity.
How can recurring policy deviations be monitored over time?
Organizations commonly track deviations in aggregate to identify patterns, such as a provision that is frequently waived, which may indicate that a policy is impractical, outdated, or in need of revision. Periodic review of open exceptions against their expiry dates helps prevent temporary deviations from becoming permanent by default. Trend analysis of deviations can also inform risk reporting and governance oversight. Specific metrics and review cadence are determined by the organization.

Common misconceptions

A policy deviation is the same as a policy violation.
The two are commonly distinguished. A deviation typically refers to a departure from policy that is documented, justified, and formally approved through an exception or waiver process, whereas a violation generally refers to an unauthorized failure to comply. The defining difference is the presence of prior authorization through defined governance channels; where these processes differ by organization, the terminology may vary.
Once a deviation is approved, the associated risk is resolved.
Approval does not eliminate the underlying risk. It records that an authorized party has accepted the residual risk, typically supported by compensating controls, for a defined scope and period. The risk commonly remains subject to monitoring and reassessment, and approval does not guarantee that adverse outcomes will not occur.
Granting and reviewing deviations can be handled by the same function.
Authorizing a deviation is a management activity carried out within the first or second line, while independent evaluation of whether the deviation process operates effectively is an assurance activity commonly associated with internal audit. Keeping these responsibilities separate preserves the independence and objectivity of assurance functions.

Best practices

Establish a documented exception or waiver process that defines who may request a deviation, who holds the decision rights to approve it, and the criteria for acceptance relative to the organization's risk appetite and tolerance.
Require each deviation to record its scope, duration, justification, risk assessment, and any compensating controls so that the basis for the decision is transparent and auditable.
Assign approval authority to a level appropriate to the risk being accepted, escalating higher-risk deviations to those with the authority to accept risk on the organization's behalf.
Set explicit expiry dates or review conditions so that deviations are periodically reassessed rather than treated as permanent departures from policy.
Maintain a central register of active deviations to support monitoring, trend analysis, and reporting to governance and oversight bodies.
Keep the granting of deviations separate from their independent review, allowing assurance functions to evaluate the effectiveness of the deviation process without compromising their objectivity.
Promotional banner for the Pentest Readiness checklist download