---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Request risk reduction for a vulnerable item or remediation task

# Request risk reduction for a vulnerable item or remediation task {#ariaid-title1}

* Release version: Australia
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Request a reduction in risk for a host vulnerable item or a remediation task in the IT Remediation Workspace.

## Before you begin

Role required: sn_vul.remediation_owner

## About this task

Starting from v21.0 of Vulnerability Response, you can request risk reduction only for the following items:

* A remediation task only if all its vulnerable items are associated to the same Common Vulnerability Entry (CVE) regardless of whether its risk reduction is enabled for CVEs.
* A third-party (TPE) for which risk reduction is enabled.

{#request-risk-reduction__ul_zlw_1p4_21c}  
Note:  
The compensating controls feature is available for host vulnerabilities only.

## Procedure

1. Navigate to WorkspacesIT Remediation Workspace.
2. Select the List icon (![List icon]()).
3. On the List page, open a host vulnerable item or a remediation task.
4. Select the More options icon and select Request Exception.
5. On the Request Exception form, fill in the fields.  
   For a description of the field values, see[Request exception form for risk reduction](https://servicenow-prod.fluidtopics.net/NwbB~7eEgCUv7AzZ5mK1_g "The following table shows the fields that you must fill on the Request exception form for risk reduction requests.").
6. Select Request Exception.
7. If a Take Questionnaire modal is displayed, answer the questions to provide additional information about your request and select Submit.  
   Note:  
   The Take Questionnaire modal appears only when the questionnaire is enabled for exception management. For more information, see [Configure Exception Management for Vulnerability Response](https://servicenow-prod.fluidtopics.net/nvJv1NSej6qBu9mMzQWItg "When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions to a vulnerable item (VI) or remediation task (RT) that cannot be remediated according to the policy.").

## Result

A message appears stating that your request is successfully submitted for approval. A notification is sent to the approver about your request.

* If your request is for a deferral and risk reduction:
  * Two state change approvals (VCA#) are created for deferral and risk reduction.
  * The state of the record changes to In Review.
  {#request-risk-reduction__ul_ip2_msk_zyb}
* If your request is for risk reduction only:
  * A state change approval (VCA#) is created.
  * The state doesn't change.
  {#request-risk-reduction__ul_x2s_n5k_zyb}

{#request-risk-reduction__ul_uhr_fqk_zyb}

On approval or rejection of your request, you'll receive a notification. For more information on the approval process, see [Approve or reject requests in the Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/JmHZsK9cXU4wNJPCJNMXvg "Approve or reject requests that are submitted by remediation owners.").

For more information on how the Until date for risk reduction is updated for a remediation task and vulnerable item when a risk reduction request is approved, see [Impact of the compensating controls on risk score and expiration date](https://servicenow-prod.fluidtopics.net/bTr0bwJDUG1RCOsW1oW0zA "As a Remediation Owner, you can request risk reduction for a host vulnerable item or remediation task. And the Vulnerability Manager or Analyst can approve these risk reduction requests.").
**Related concepts**   

* [Understanding compensating controls for risk reduction](https://servicenow-prod.fluidtopics.net/lfL1ilZ~cS~h1vU8BMI49g "Compensating controls are the measures taken to reduce the risk posed by vulnerabilities that can't be patched immediately. They can be used to mitigate the likelihood or impact of a successful exploit.")
* [Impact of the compensating controls on risk score and expiration date](https://servicenow-prod.fluidtopics.net/bTr0bwJDUG1RCOsW1oW0zA "As a Remediation Owner, you can request risk reduction for a host vulnerable item or remediation task. And the Vulnerability Manager or Analyst can approve these risk reduction requests.")  
**Related tasks**   

* [Disable or enable risk reduction for a CVE or TPE](https://servicenow-prod.fluidtopics.net/PkBpor8ePECeKOr89863KA "As a Vulnerability Manager and Analyst, you can disable or enable the risk reduction requests for the host vulnerabilities associated with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Vulnerability Manager Workspace.")
* [Add a compensating control to the library](https://servicenow-prod.fluidtopics.net/CnRYfdkCzjQjmVMVX77y8A "As a Vulnerability Manager or Analyst, add a list of compensatory controls to the Compensating Controls library in the Vulnerability Manager Workspace, which can be applied for the risk reduction of host vulnerable items and remediation tasks.")

*[\>]: and then


