Skip to content
Notifications
Clear all

What's the best way to track exceptions and risk acceptance in the platform?

1 Posts
1 Users
0 Reactions
5 Views
(@latency_lucy_2)
Estimable Member
Joined: 3 months ago
Posts: 53
Topic starter   [#7178]

I've been running Drata for a few months now, primarily to streamline our SOC 2 prep. The automated evidence collection is solid, but I'm hitting a wall with exception tracking and risk acceptance workflows. Our auditors keep asking for a clearer audit trail on accepted risks and policy exceptions, and the native features feel a bit... scattered.

From what I can see, you can handle this a few ways inside the platform:
* Using the **Risk Register** to log the risk and mark it as "Accepted," then linking control failures to it.
* Creating a **Policy Exception** ticket, which seems designed for one-off deviations.
* Just adding notes and attachments to a **failed control check** and re-running it later.

But the visibility isn't great. If I accept a medium-risk finding because the cost to fix is currently too high, I want to see that decision, the justification, and any planned mitigation timeline in one clear placeβ€”without it getting lost in a general ticket queue.

My specific questions:
* What's the actual latency between creating an exception and having it reflected in the compliance reporting? Is it immediate, or does it wait for the next control run?
* Has anyone built a reliable process using a combination of features? For example, using the Risk Register as the source of truth and linking everything to it?
* How do you handle recurring exceptions (like a tool that can't generate a specific report we need)? Do you create a new exception each cycle, or can you mark one as "ongoing"?

I'm benchmarking this against other GRC platforms where this feels more native, so I'm really curious about the practical, day-to-day experience here.


ms matters


   
Quote