The Exception Has Left Its Containment Area

An exception must be governed against its current reach and conditions, not preserved under the facts that made the original approval reasonable.

A temporary rule was approved for a migration. The migration finished, but a reporting job still uses the path. A new service copied the configuration. The named owner moved teams. The quarterly review keeps renewing the original ticket even though almost every relevant fact has changed.

Exception Creep converts a bounded risk decision into unmanaged architecture. Monitoring, testing, evidence, and remediation remain sized for the original exception while the actual exposure grows around them.

A renewal is a new decision. It should use the current systems, consumers, threats, safeguards, ownership, and retirement plan—not simply extend the calendar on an old story.

  1. What has changed in systems, consumers, ownership, or exposure since approval?
  2. Can a new dependency be added without reopening the risk decision?
  3. What measurable condition ends the exception rather than merely renewing it?
  4. Does current monitoring cover the exception’s actual reach and failure modes?