Exceptions Register

The read-only list of every risk your organisation has formally chosen to accept, with the justification, the person who accepted it, and the date the acceptance falls due for review.

Sometimes the right answer to a risk is to accept it: the cost of treating it outweighs the harm, or no practical control exists yet. An assessor will then ask who decided, why, and until when. The exceptions register (the formal list of consciously accepted risks) is where those answers live. You do not accept a risk here — the register reads back every risk whose status is Accepted and lays the acceptance evidence out in one table.

Who uses it

Nothing on this page changes data: there is no New button, no inline editing and no export — only the two filters and the links out to each risk. The screenshot below was captured as a Contributor, and a Viewer sees the same screen.

What's on this screen

The register sits under the RISKS group in the left sidebar. The page opens with the heading Exceptions Register, a short description of what the register is for, and a two-control filter bar: a Search risks... box and an All Categories dropdown. Below that is the table, with nine columns — Title, Category, Owner, Treatment, Inherent Score / Residual, Accepted By, Accepted On, Review By and Justification. It is wide, so on a narrow window it scrolls sideways with a soft shadow at whichever edge has more content off-screen.

In the captured screen the register holds a full page of accepted risks — Talent Shortage - System B, M&A Integration Failure - System A, Political Instability - Division 1 and so on — each with its category, owner and scores. Only one row in view carries a treatment badge (Mitigate, in blue); the rest show an em-dash there. Every row shows an em-dash under Accepted By, Accepted On and Review By, and No justification recorded in italics under Justification. That combination is worth recognising; the note below the figure explains what it means.

  1. Select RISKS in the left sidebar and choose Exceptions Register. The page loads with its heading, the filter bar, and a table of every risk currently marked Accepted.
  2. Type into Search risks... to narrow the register. The search matches the risk title and its description, ignoring case. Aegis waits a moment after you stop typing, then reloads the table with the matching rows and returns you to page one.
  3. Choose a category from the All Categories dropdown to see only the accepted risks in that category. The table reloads against that filter; set it back to All Categories to bring the whole register back.
  4. Read a row from left to right: title, category, owner, treatment badge, then the inherent and residual scores. Select the title to open the full risk record, where the acceptance can be edited.
  5. Check Accepted By. It names the person who recorded the acceptance in Aegis; here it shows an em-dash on every row, as do Accepted On and Review By.
  6. Read Justification last. A recorded reason appears as one truncated line — hover it for the full text — while No justification recorded in grey italics means the acceptance has no reason attached.
The Exceptions Register: search box, category filter and the nine-column table of accepted risks — /risks/exceptions-register.
The Exceptions Register: search box, category filter and the nine-column table of accepted risks — /risks/exceptions-register.
Acceptance evidence is only captured from the moment you accept in Aegis

Aegis stamps Accepted By and Accepted On when a risk moves into Accepted through the app. Risks that arrived already marked as accepted — from an import or a migration off a spreadsheet — appear with those columns empty, exactly as in the screenshot above. They are real accepted risks carrying no governance record. Their risk pages say so: the Acceptance panel reports that no acceptance details were recorded and asks you to re-accept the risk. Editing that panel adds a justification and a review date but does not stamp an acceptor or a date — only a fresh acceptance does. To record those too, move the risk to Open or In Progress and then accept it again.

How a risk reaches the register

Membership is decided by one rule: the risk's status is Accepted. Treatment is a separate field — a risk whose treatment reads Accept is not on the register unless its status says so too, which is why the screenshot shows an accepted risk badged Mitigate.

  1. Open the risk from Risks. Its detail page shows the status buttons near the top for anyone who may edit risks; a Viewer sees no buttons at all.
  2. Select the Accepted status button. Rather than switching the status straight away, Aegis opens the Accept Risk dialogue, which explains that formal acceptance places the risk on the exceptions register.
  3. Fill in Justification. The form will not submit without it, and it holds up to 2,000 characters. The placeholder suggests reasoning that stands up later: residual risk within appetite, compensating controls in place, insured.
  4. Optionally set Review by (optional) — the date the acceptance must be looked at again. Leave it empty and the register shows an em-dash there, meaning nothing ever falls due.
  5. Select Accept Risk to confirm. Aegis sets the status to Accepted, records you as the acceptor with today's date, writes an entry to the Audit Log, and confirms with Risk accepted and added to the exceptions register. The risk now appears on the register with its evidence complete.

The risk's detail page then carries an Acceptance panel showing Accepted by, Accepted on, Review by and the justification. Anyone who may edit risks can use the small edit control there to correct the justification or move the review date; that edit touches only those two fields, so it does not re-stamp the acceptor or the date.

Accepting in bulk records less

Setting several risks to Accepted at once records the acceptor and the date, but that flow has no justification field — those rows land on the register reading No justification recorded. Accept one at a time when the reasoning matters.

Reading a register row

Column What it shows
Title The risk name, as a link to the full risk record.
Category The risk category — for example Legal Risk — or an em-dash if none.
Owner The person accountable for the risk.
Treatment Accept, Mitigate, Transfer, Insure or Avoid; an em-dash means no treatment has been decided. Separate from the acceptance.
Inherent Score / Residual The score before controls and the rest-risk after them. Where no residual score has been recorded, the inherent score is repeated.
Accepted By The person who accepted the risk in Aegis, or an em-dash if none.
Accepted On The date the acceptance was recorded, in your locale's date format.
Review By The review date. A red Review overdue badge marks a date already past; an amber Review due soon badge marks one due within 30 days. Neither appears in the capture, because none of these rows has a review date.
Justification The recorded reasoning, truncated to one line with the full text on hover, or No justification recorded.

Rows are sorted by review date, so overdue acceptances come first; acceptances with no review date fall to the end, most recently updated first. In the capture no row has a review date at all, so the whole page falls into that last group. The table shows 20 rows to a page. Beneath it — below the part of the screen captured above — sit a Page 1 of 2 style counter with Previous and Next buttons, greyed out when there is nowhere to move to.

When the register shows nothing

There are two different kinds of empty here, and they mean different things:

If the register fails to load, Aegis shows Failed to load the exceptions register. with a Retry button rather than an empty table — so an outage never reads as "we have no accepted risks". The filter bar stays on screen in that state too.

The AI assist

The register has no AI of its own, but each accepted risk does. The Acceptance panel on the risk's detail page carries a Review (AI) button, which opens AI Exception Review — Justification, renewal & governance check. It reads the record and the signals Aegis has already calculated — severity, how overdue or stale the acceptance is, whether a justification exists — and reviews three things:

The dialogue states its own limits: the review is read-only — it narrates your record and the computed signals, and never changes the exception or invents data. It cannot renew an acceptance, move a review date, or take a risk off the register; a person reads it and decides. Save as record keeps a review with the risk's acceptance section for the next reviewer. Each run counts as one AI action against your organisation's AI credits and is audit-logged.

Tips and limits

Where this connects