---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Exception Management in Application Vulnerability Response

# Exception Management in Application Vulnerability Response {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exception Management in Application Vulnerability Response

Exception management allows organizations to request, review, approve, or reject exceptions for application vulnerable items (AVIs) when compliance with security policies is not feasible.
This process acknowledges the associated risks when vulnerabilities cannot be remediated due to a lack of available patches or solutions.
Show full answer Show less  

## Key Features

* **Exception Requests:** Developers can request exceptions through the Vulnerability Manager Workspace or IT Remediation Workspace, moving AVIs to a Deferred state upon approval.
* **Exception Rules:** Starting from version 20, you can create rules to automate the deferral of AVIs, reducing manual intervention and ensuring compliance with service level agreements.
* **Extension Requests:** You may request an extension on exception rules if remediation is not achieved by the Deferred until date, requiring two-level approval.
* **Tracking and Management:** The status of exception requests can be monitored via the State Change Approvals tab, and actions can be taken post-approval, such as reopening requests.
* **Configuration Options:** Customize duration limits and add questionnaires for exception requests using the ServiceNow Application Vulnerability Response module.

## Key Outcomes

By effectively managing exceptions, organizations can maintain compliance while acknowledging the risks associated with not remediating certain vulnerabilities. The structured approval process and automated features help streamline vulnerability management, ensuring that exceptions are well-documented and monitored, ultimately enhancing the security posture of the organization.  
When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or
rejecting exceptions to an application vulnerable item (AVIT) that cannot be remediated according to the policy.  
Some vulnerabilities might not have an existing patch, fix, or solution. When an exception is approved, it also means that you're accepting a risk because you're acknowledging and agreeing to the consequences of not remediating the vulnerability.  
Note:  
Starting from v21.0 of Application Vulnerability Response, you can configure the time frames for approving false positives and exceptions, along with email notifications for both the approver and requester after a set number of days. When a request is raised, the application vulnerable item changes to In-Review status and a state change record is created. If the approver doesn't respond within the configured time frame, the application vulnerable item or remediation task reverts to Open status. The previous state is stored in the backup_state field. For more information, see [Configure approval rules for Exception Management](https://servicenow-prod.fluidtopics.net/6wErapFqZ8hq2HLk9FBLNA "Starting with Application Vulnerability Response v15.0, use the flow designer to approve exception requests for exception management, exception rules, and false positive management. If you are deploying Application Vulnerability Response (AVR) for the first time, the flow designer is enabled by default.").

## Life cycle of an exception {#avr-exception-management__section_ems_dy3_flb}

Definition of an exception
:   An exception is a request to defer the remediation of an AVI for a specified period. For example, as a developer, you can request an exception if a patch is not available for a machine.

Requesting an exception
:   As the developer, you can ask for an exemption for an AVI using the exception management process. After the application security analyst approves this request, the AVI moves to Deferred state.  
    Important:  
    You can request exceptions for AVTIs and RTs from the Vulnerability Manager Workspace and IT Remediation Workspace respectively. For more information, see [Request exceptions for remediation tasks and records in the Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/bWo4zdNcYMgNqM8grmyNNw "From the Vulnerability Manager Workspace, vulnerability managers and analysts can request exceptions and false positives for a remediation task (VUL, AVUL, CVUL or CRG) and record (VIT, CVIT, AVIT or CTR). You can also split a remediation task and create change requests.") and [Request an exception in the IT Remediation Workspace](https://servicenow-prod.fluidtopics.net/u8048LRMppDaxV9c9jKGkg "Request an exception for the host vulnerable item (VIT), application vulnerable item (AVIT), container vulnerable item (CVIT) and remediation task (VUL, AVUL, CVUL, or CRG) from the IT Remediation Workspace.").

Exception rules
:   Starting with v20, you can create exception rules to automatically defer existing and new application vulnerable items (AVI)s for a specific period if they match the conditions of the rule. Using exception rules to
    automatically defer AVIs minimizes the risk of missing service level agreements. The rules can help you manage multiple items, because you are eliminating manual intervention. See Create an Exception rule.

Requesting an extension for an exception rule
:   Starting with v20, you can submit a request for an extension to the Deferred until date of an exception rule. You might request an extension to a rule if you find that a large number of records
    created by the rule are not being resolved by its Deferred until date, the date when the remediation task stops accepting new AVIs. The extension updates the exception rule so it automatically
    extends the deferral date on your existing rule. You can enter dates up to one year from the current date, and you must include a reason for the extension. An extension request requires two-level approval from separate
    approval groups.

Approving an exception request
:   AVITs that can't be remediated immediately are reviewed by application security analysts, assessed for risk, and approved for deferral until they can be remediated. Approving an exception request can be a two-level
    flow. If only the first-level approver is present, the exception can be requested and approved. However, if there's no first-level approver, an exception can't be requested. See [Add an exception approver for Application Vulnerability Response](https://servicenow-prod.fluidtopics.net/VVr3mNrhkQGj6sWzMhtfrw "Add users to the approver groups so that you can request an exception.") for more information.  
    Important:  
You can approve or reject exception requests in the Vulnerability Manager Workspace. For more information, see [Approve or reject requests in the Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/JmHZsK9cXU4wNJPCJNMXvg "Approve or reject requests that are submitted by remediation owners.").  
Note:  
After an exception request for an AVIT is approved, you can perform the following actions:

* Reopen
* Get more details
{#avr-exception-management__ul_h32_y22_4lb}

Tracking an exception request
:   After raising the exception, you can track its status by using the State Change Approvals tab of the AVIT.

Expiry of an exception request and requesting an extension to an exception rule
:   When an exception request for a particular AVI expires, the impacted AVI reverts to its Open state.

    However, starting with v20, you can submit a request to extend the Deferred until date on the exception rule.
* **[Configure Exception Management for Application Vulnerability Response](https://servicenow-prod.fluidtopics.net/hUbQRfWpg0t_QP1QguWQmg)**   
  Limit the duration of an exception requested and add a questionnaire to the exception or false positive request using the module. By default, an exception is requested using the ServiceNow® Application Vulnerability Response module. You can also request an exception using the GRC: Policy and Compliance Management integration.
* **[Configure approval rules for Exception Management](https://servicenow-prod.fluidtopics.net/6wErapFqZ8hq2HLk9FBLNA)**   
  Starting with Application Vulnerability Response v15.0, use the flow designer to approve exception requests for exception management, exception rules, and false positive management. If you are deploying Application Vulnerability Response (AVR) for the first time, the flow designer is enabled by default.
* **[Deferring remediation in Application Vulnerability Response](https://servicenow-prod.fluidtopics.net/E3_BOvUWyRzSt1e_9Zsmvg)**   
  Starting with v20.0, you can defer remediation with the Awaiting Implementation state that is available for application vulnerable items (AVI)s and remediation tasks as they move through their life cycles. You can only transition records to this state manually by selecting Awaiting Implementation from AVI and remediation task records in the Under Investigation state.
* **[Add an exception approver for Application Vulnerability Response](https://servicenow-prod.fluidtopics.net/VVr3mNrhkQGj6sWzMhtfrw)**   
  Add users to the approver groups so that you can request an exception.
* **[Requesting and approving an exception in Application Vulnerability Response](https://servicenow-prod.fluidtopics.net/0DUpNa08dQh9G6tok5GGzw)**   
  You can request to defer the remediation of an application vulnerable item and a remediation task for a specified period.
* **[Create, delete, and cancel an exception rule for Application Vulnerability Response](https://servicenow-prod.fluidtopics.net/GRrCZFlR~GzOsbfoudOkNA)**   
  Create a rule to request an exception automatically for application vulnerable items (AVI)s that meet specific conditions.

